At a Glance
- Tasks: Join our team to enhance product security and tackle emerging threats in a dynamic environment.
- Company: ION is a leading provider of trading software and analytics, trusted by top global corporations.
- Benefits: Enjoy a diverse workplace, career growth opportunities, and the chance to work with cutting-edge technology.
- Why this job: Be a key player in securing innovative products while collaborating with talented professionals worldwide.
- Qualifications: Knowledge of cybersecurity principles and experience in regulated industries are essential; scripting skills preferred.
- Other info: This role may require occasional overnight and weekend work.
The predicted salary is between 36000 - 60000 £ per year.
This is an amazing opportunity to work with the Information Security and Compliance Team at ION. As a Product Security Engineer, you would be the key enabler of secure and compliant products. You should have knowledge of attack paths across the technology stack, including tactics, techniques and procedures (TTPs) used by adversaries to exploit vulnerabilities. You will be a trusted advisor throughout the product development lifecycle, incorporating knowledge of emerging threats, business goals and system design to improve platform security posture. You will be responsible for aligning the Markets security strategy, security design and controls engineering to the product roadmap. You will also be responsible for providing transparency to leadership on product control performance and associated risk.
Key Responsibilities:
- Monitor and identify security events and emerging threats associated with the product line you are managing and any dependencies;
- Act as the interface between CSIRT and Product teams as part of security incident activities;
- Deliver threat modelling and hunting to identify vulnerabilities in product design and provide control recommendations to mitigate those risks;
- Engage in architecture and design reviews to ensure product alignment with Security strategy and industry best practices;
- Stay up to date with industry trends, best practices and regulatory standards that may impact product implementations;
- Support the engineering of control solutions where existing offerings are not available;
- Provide security expertise during incident and problem management;
- Produce threat intelligence briefings and other work products to share information across the organisation;
- Respond to ad-hoc requests for platform security related guidance.
This role may require some overnight, weekend and on-call activities.
Required Skills, Qualifications and Experience:
- Knowledge of working within the financial services industry, or other highly regulated industries in a technical role.
- Information security management, governance, and compliance principles, practices, laws, rules and regulations, e.g. NIST, ISO, NIS, DORA and GDPR;
- Information technology systems and processes, network infrastructure, data architecture, data processes and protocols;
- Cyber and cloud security standard frameworks, architecture, design, operations, controls, technology, solutions, and service orchestration, e.g. CIS, CSF;
Skills in:
- Security Tooling: Proficiency in common security tools, such as SIEMs, vulnerability scanners, firewalls and EDR products;
- Scripting: Proficiency in scripting languages like Python, BASH, or PowerShell;
- Security Incident Management: Ability to assist with the detection, response, and recovery of escalated security incidents and manage backlog/lessons learned actions;
- Risk Assessment: Proficiency in conducting security risk assessments and providing thorough post-event analyses;
- Security Expertise: Providing security expertise during incident and problem management;
- Communication: Strong communication skills to explain complex security issues to both technical and non-technical audiences.
Ability to:
- Effectively communicate technical issues to diverse audiences, both in writing and verbally;
- Handle sensitive and confidential matters, situations, and data;
- Understand and follow broad and complex instructions;
- Comprehend technical language and to confer, analyse and write in an objective, lucid manner;
- Work independently and prioritise multiple tasks and adapt to needed changes;
- Remain calm under high pressure/difficult situations.
Preferred Certifications: GCIH; CSEC; CSSLP; CISSP; CASP+
About us: We’re a diverse group of visionary innovators who provide trading and workflow automation software, high-value analytics, and strategic consulting to corporations, central banks, financial institutions, and governments. Founded in 1999, we’ve achieved tremendous growth by bringing together some of the best and most successful financial technology companies in the world. Over 2,000 of the world’s leading corporations, including 50% of the Fortune 500 and 30% of the world’s central banks, trust ION solutions to manage their cash, in-house banking, commodity supply chain, trading and risk. Over 800 of the world’s leading banks and broker-dealers use our electronic trading platforms to operate the world’s financial market infrastructure. ION is a rapidly expanding and dynamic group with 13,000 employees and offices in more than 40 cities around the globe. Our ever-expanding global footprint, cutting edge products, and over 40,000 customers worldwide provide an unparalleled career experience for those who share our vision. ION is committed to maintaining a supportive and inclusive environment for people with diverse backgrounds and experiences. We respect the varied identities, abilities, cultures, and traditions of the individuals who comprise our organization and recognize the value that different backgrounds and points of view bring to our business. ION adheres to an equal employment opportunity policy that prohibits discriminatory practices or harassment against applicants or employees based on any legally impermissible factor.
Markets Product Security Engineer employer: ION Group
Contact Detail:
ION Group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Markets Product Security Engineer
✨Tip Number 1
Familiarise yourself with the latest trends in cybersecurity, especially those relevant to the financial services industry. This will not only help you understand the challenges we face but also demonstrate your proactive approach to staying informed during interviews.
✨Tip Number 2
Engage with online communities and forums related to product security and compliance. Networking with professionals in the field can provide insights into the role and may even lead to referrals or recommendations.
✨Tip Number 3
Prepare to discuss specific security tools and frameworks you have experience with, such as SIEMs or vulnerability scanners. Being able to articulate your hands-on experience will set you apart from other candidates.
✨Tip Number 4
Showcase your problem-solving skills by preparing examples of how you've handled security incidents in the past. Highlighting your ability to remain calm under pressure will resonate well with our team.
We think you need these skills to ace Markets Product Security Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in information security, particularly within the financial services industry. Emphasise your knowledge of security frameworks like NIST and GDPR, as well as any specific tools or scripting languages mentioned in the job description.
Craft a Compelling Cover Letter: In your cover letter, explain why you are passionate about product security and how your skills align with the responsibilities outlined in the job description. Mention specific experiences where you've successfully identified vulnerabilities or improved security posture.
Showcase Relevant Skills: Clearly list your proficiency in security tooling, incident management, and risk assessment. Use examples from your past work to demonstrate your ability to communicate complex security issues effectively to both technical and non-technical audiences.
Highlight Certifications: If you have any relevant certifications such as GCIH, CISSP, or CASP+, make sure to include them prominently in your application. This will help establish your credibility and expertise in the field of information security.
How to prepare for a job interview at ION Group
✨Understand the Security Landscape
Familiarise yourself with the latest trends in information security, especially those relevant to the financial services industry. Be prepared to discuss specific attack paths and TTPs that adversaries might use, as this knowledge will demonstrate your expertise and readiness for the role.
✨Showcase Your Technical Skills
Be ready to talk about your proficiency with security tools like SIEMs and vulnerability scanners, as well as your scripting skills in languages such as Python or PowerShell. Providing examples of how you've used these tools in past roles can help illustrate your capabilities.
✨Communicate Clearly
Since you'll need to explain complex security issues to both technical and non-technical audiences, practice articulating your thoughts clearly and concisely. Use relatable examples to convey your points effectively during the interview.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving abilities in high-pressure situations. Think of past experiences where you managed security incidents or conducted risk assessments, and be ready to discuss the outcomes and lessons learned from those scenarios.