At a Glance
- Tasks: Lead security initiatives and ensure compliance across AWS and Azure environments.
- Company: Join Taxually, a fast-growing SaaS scale-up revolutionising tax management for over 12,000 clients worldwide.
- Benefits: Enjoy remote work flexibility, competitive pay, and generous home office support.
- Why this job: Be part of a dynamic team driving innovation in cloud security and compliance.
- Qualifications: Experience in security governance, risk management, and cloud security is essential.
- Other info: We value diverse backgrounds and encourage all candidates to apply, regardless of qualifications.
The predicted salary is between 43200 - 72000 £ per year.
A little about who we are: Taxually is a global transactions tax SaaS scale-up offering a suite of products to enhance how clients manage their tax processes. Founded in 2018, Taxually has grown nearly 300% year on year, working with over 12,000 customers across more than 60 countries. We have developed, and continue to develop, advanced technology within the tax sector, leading to adoption by Fortune 500 companies and strong Private Equity backing. We have a dedicated, hardworking, and growing team. The ideal person working here is driven, motivated, empowered, and forward-thinking. We encourage challenge, new ideas, and contributions to Taxually's growth.
Role Overview: We are seeking a proactive and experienced Security Engineer to strengthen our global security posture and ensure regulatory compliance across our AWS and Azure cloud environments. This role involves managing security frameworks, maintaining compliance with SOC 2, GDPR, ISO 9001, ISO 27001, and other standards, while implementing best practices to protect our infrastructure, applications, and data. The ideal candidate will have extensive experience in security governance, risk management, cloud security, incident response, vulnerability management, penetration testing, and leading business continuity and disaster recovery tests. You will drive ongoing compliance with various security frameworks and collaborate with internal teams and external auditors to maintain a robust security foundation in a rapidly evolving environment.
Key Responsibilities
- Security & Compliance Management: Lead and maintain compliance with SOC 2, GDPR, ISO 27001, and ISO 9001 by implementing, managing, and improving security controls, policies, and processes, while addressing any compliance gaps to ensure adherence to standards and best practices. Manage all compliance tasks on a daily, monthly, quarterly, and annual basis to ensure regulatory and audit readiness. Oversee internal and external security audits, ensuring continuous adherence to industry standards. Collaborate with third-party auditors and regulatory bodies for assessments and certification renewals. Ensure data protection and privacy controls align with regulatory requirements, continuously updating measures to safeguard sensitive information and maintain compliance.
- Cloud Security, Risk & Vulnerability Management: Implement AWS and Azure security best practices across infrastructure, including IAM, networking, logging, and encryption. Conduct regular security risk assessments and Business Impact Analysis (BIA) to evaluate vulnerabilities. Oversee security patching and vulnerability management to ensure timely remediation of threats. Monitor cloud security posture and recommend remediation strategies to reduce attack surfaces. Enforce CIS benchmarks, OWASP principles, and NIST cybersecurity controls across cloud and application security. Oversee third-party security assessments to ensure vendor compliance and security standards.
- Incident Response, BC/DR & Penetration Testing: Lead Incident Response planning, testing, and execution to ensure swift containment and remediation of threats. Develop and maintain Business Continuity and Disaster Recovery plans for high availability and minimal disruption. Oversee web application penetration testing, collaborating with security teams to identify and remediate vulnerabilities. Drive continuous security improvements based on testing results and incident learnings.
- Policy & Control Enforcement: Define, review, and update security policies, standards, and controls based on industry best practices. Ensure security requirements are integrated into development, operations, and business processes. Conduct security awareness and training programs to foster a security-first culture. Monitor and enforce compliance with security policies across all teams and departments.
Working Environment: Fast-paced environment supporting critical tax and financial services applications. Hybrid role combining hands-on technical work with team leadership. Collaboration with multiple departments and stakeholders. Focus on continuous improvement and service excellence.
What You Can Count On: We aim to offer a mutually beneficial package, including: A competitive compensation package. A fully remote-first company (EU time zones preferred). Our team members are located across Hungary, the UK, Germany, Austria, Romania, China, Argentina, and more. We also have a physical space in Budapest, Hungary. Generous home office setup support and optional co-working space stipends. An exciting, rapidly growing, and highly profitable scale-up environment.
Don’t meet all the role requirements? Don’t worry! We value outcomes over checkboxes, and often the best candidate may have a different CV. Research from Harvard shows that women, in particular, tend to second-guess themselves and not apply—so if you’re hesitant, reach out anyway, and we’ll handle the worries. At Taxually, we are committed to building a diverse company and are especially interested in candidates from underrepresented groups in tech.
Lead Security Engineer (Cloud Security & Compliance) employer: Taxually
Contact Detail:
Taxually Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Lead Security Engineer (Cloud Security & Compliance)
✨Tip Number 1
Familiarise yourself with the specific compliance frameworks mentioned in the job description, such as SOC 2, GDPR, ISO 9001, and ISO 27001. Understanding these standards will not only help you in interviews but also demonstrate your proactive approach to security governance.
✨Tip Number 2
Showcase your experience with AWS and Azure security best practices. Be prepared to discuss specific examples of how you've implemented security measures in cloud environments, as this is a key aspect of the role.
✨Tip Number 3
Highlight any experience you have with incident response and business continuity planning. Being able to articulate your role in past incidents or tests can set you apart from other candidates.
✨Tip Number 4
Network with professionals in the security field, especially those who have experience in SaaS companies. Engaging with industry peers can provide insights into the role and may even lead to referrals, increasing your chances of landing the job.
We think you need these skills to ace Lead Security Engineer (Cloud Security & Compliance)
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Lead Security Engineer position. Familiarise yourself with key terms like SOC 2, GDPR, and cloud security best practices to tailor your application effectively.
Highlight Relevant Experience: In your CV and cover letter, emphasise your experience in security governance, risk management, and cloud security. Use specific examples from your past roles that demonstrate your ability to manage compliance and lead incident response efforts.
Showcase Your Skills: Make sure to highlight any certifications or training related to security frameworks (like ISO 27001) and cloud platforms (AWS and Azure). This will help you stand out as a candidate who is well-prepared for the challenges of the role.
Craft a Compelling Cover Letter: Write a cover letter that not only outlines your qualifications but also conveys your passion for security and compliance. Mention how your proactive approach aligns with Taxually's values and their commitment to continuous improvement.
How to prepare for a job interview at Taxually
✨Understand the Compliance Landscape
Familiarise yourself with SOC 2, GDPR, ISO 9001, and ISO 27001. Be prepared to discuss how you have implemented these standards in previous roles and any challenges you faced.
✨Showcase Your Cloud Security Expertise
Highlight your experience with AWS and Azure security best practices. Be ready to provide examples of how you've managed IAM, networking, and encryption in cloud environments.
✨Demonstrate Incident Response Skills
Prepare to discuss your approach to incident response planning and execution. Share specific instances where you successfully contained and remediated security threats.
✨Emphasise Continuous Improvement
Talk about how you have driven continuous security improvements based on testing results and incident learnings. This shows your proactive mindset and commitment to enhancing security measures.