Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Tangible

Information Security Engineer – CISO Track

Tangible

Information Security Engineer focusing on AWS security for a fintech startup. Managing incident response, security audits, and leading customer security reviews for financial institutions.

Posted 7/22/2026contractRemote • 🇬🇧 United KingdomMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in AWS security, including IAM, encryption, and logging, while automating security processes and managing compliance with regulations such as SOC 2, GDPR, and CCPA. Capable of leading security strategy and risk assessments in a financial services context, with strong communication and people skills.

Highest-signal resume keywords
AWS SecuritySOC 2 ExperiencePython ProgrammingTerraformRisk Assessment

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
IAMEncryptionLoggingVulnerability ManagementIncident ResponseThreat ModelingAutomationEvidence CollectionSecurity ReviewsRegulatory Compliance
Soft Skills
Clear WritingJudgmentPeople SkillsAmbition
Tools & Technologies
GuardDutySecurity HubCloudTrailSSOSCIMSFTPAPIs
Industry Keywords
GDPRCCPADORAEBAFINRAGLBAFinancial ServicesB2B EnvironmentVendor RiskPhishing Resilience

Tech Stack

Tools & technologies
AWSPythonTerraform

About the role

Key responsibilities & impact
  • Own security in our AWS environment: IAM and least privilege, network segmentation, encryption, logging and detection (GuardDuty, Security Hub, CloudTrail), fixing what you find.
  • Build security into the development pipeline: secrets management, dependency and container scanning, code review for risky changes, threat modeling with the engineers.
  • Automate. Detection rules, alerting, compliance evidence, IaC guardrails. If a control can be code instead of a meeting, make it code.
  • Run vulnerability management and incident response.
  • Write the runbooks, run the drills.
  • Set the rules for our AI and LLM use: which data goes to which vendors, which models are approved, how prompts and outputs are handled and logged.
  • Assess risks like prompt injection and data leakage, design controls that let people keep working.
  • Own SOC 2: control design, automated evidence collection, the auditor relationship.
  • Handle regulatory side for our financial-institution customers: GDPR and CCPA for privacy, DORA and EBA outsourcing guidelines in the EU, GLBA and SEC/FINRA expectations in the US.
  • Lead customer security reviews: due diligence questionnaires, RFPs, contract security terms, calls with bank security teams.
  • Run vendor reviews and third-party risk.
  • Secure the human half by building awareness training, phishing resilience, and device and identity hygiene that work for deals and sales people, not only engineers.
  • Over time: set the security strategy, report risk to leadership in business terms, choose tooling, build a budget, hire.

Requirements

What you’ll need
  • 5+ years in security engineering or security-heavy infrastructure work, with depth in AWS security (IAM, SCPs, logging, detection, encryption).
  • Certifications are fine, but shipped work is better.
  • Python and Terraform, or close equivalents.
  • You automate evidence collection instead of maintaining spreadsheets.
  • SOC 2 experience, ideally owning a Type II audit.
  • Working knowledge of privacy legislation.
  • Exposure to financial-services customer scrutiny, or the appetite to make it your specialty.
  • A working view on LLM security risks, or strong fundamentals and the curiosity to build one.
  • Judgment about which risks matter.
  • Clear writing.
  • The ambition to grow into an executive role and the people skills to survive it.
  • Nice to have Fintech or another regulated B2B environment with large financial-institution customers.
  • DORA, EBA/ESMA outsourcing guidelines, or NYDFS 500.
  • Experience securing enterprise integrations: SSO/SCIM, SFTP feeds, APIs.
  • You've been the first security hire somewhere before.

Benefits

Comp & perks
  • A blank slate with real ownership
  • A committed path to CISO.
  • Fully remote, flexible hours.
  • Direct access to leadership and to customer security teams at major financial institutions.
  • Competitive pay, equity, learning budget.