Define and enforce the security architecture for AWS and Azure: organisation and landing-zone design, service control policies and Azure Policy, network segmentation and private connectivity, encryption and key management (AWS KMS, Azure Key Vault), logging and monitoring baselines.
Own the perimeter and edge: WAF and DDoS protection, VPN and zero-trust access, DNS, certificate, and exposure management for anything internet-facing.
Run vulnerability management end to end: asset discovery, scanning, prioritisation by exploitability and business impact, remediation SLAs tracked with the infrastructure team.
Design security into new infrastructure from the start: threat-model and review architecture changes, define secure patterns other engineers can reuse, and say “no” with a workable alternative when needed.
Own Active Directory: administrative tiering, privileged-group hygiene, Group Policy and Conditional Access baselines
Design and run the group access model: least privilege across AWS IAM, Azure RBAC, Kubernetes RBAC, databases, network devices and SaaS; single sign-on and phishing-resistant MFA everywhere; privileged access management with just-in-time elevation for administrators; tested break-glass procedures.
Own the security telemetry pipeline into the SIEM: AWS CloudTrail, AD and Entra sign-in and audit logs; EDR; Kubernetes audit logs; WAF, VPN, network and application logs. Decide what is collected, for how long and at what cost.
Treat security as code: Terraform modules with secure defaults; policy-as-code (Open Policy Agent, AWS Config rules, Azure Policy) enforced in pipelines and at runtime; drift detection and automatic remediation where safe.
Own API security for internal and client-facing APIs (REST, WebSocket, FIX and streaming market-data interfaces): authentication and authorisation patterns, token and key handling, rate limiting and abuse protection, gateway and WAF rules, schema validation, logging of security-relevant events.
Automate evidence collection and continuous control monitoring so that ISO 27001 and SOC 2 audits become a by-product of normal operations.
Be the technical owner of the ISO/IEC 27001:2022 Annex A technological controls (A.8) and of SOC 2 (Security and Availability criteria) control operation. Support internal audits, surveillance audits and SOC 2 Type II fieldwork.
Map technical controls to DORA: the ICT risk-management framework, the annual digital operational resilience testing programme (vulnerability assessments, penetration tests, scenario tests, readiness for threat-led penetration testing) and the technical inputs to the ICT third-party register.
Run security reviews of ICT third parties and cloud services. Maintain shared-responsibility and data-flow documentation.
Requirements
Experience. 6+ years of hands-on infrastructure, cloud or security engineering, of which 3+ years with security as your primary responsibility, in a regulated financial-services environment — brokerage, trading, payments, banking or crypto services.
AWS and Azure in production. Security of complex, multi-account / multi-subscription, hybrid estates on both platforms: IAM and RBAC, networking and private connectivity, KMS and Key Vault, logging and native detection services, landing zones and policy enforcement. You have designed infrastructure, not only reviewed it.
Active Directory. Deep, practical knowledge of AD — tiering, Group Policy, Conditional Access, hybrid identity, the common attack paths and how to close them — plus enterprise IAM and PAM design and access-rights governance.
Detection and response. You have built and tuned SIEM and EDR detections, owned alerting quality and run security incidents end to end under time pressure. You understand how a Security Operations Center works from the inside — as well as what a SOC 2 report is.
Automation. Terraform (or equivalent IaC), CI/CD security gates, Kubernetes and container security, policy-as-code, and confident scripting in Python, Bash and PowerShell. You understand APIs well enough to secure them and to automate through them.
Crypto-asset infrastructure. Hands-on exposure to securing wallet or key-management systems, exchanges or crypto payment rails — HSM or MPC signing, hot/cold segregation, transaction-flow monitoring.
Conditions
Reliability: official employment from the first day, bonuses, annual employee review (salary review or bonus, feedback on work results)
Stability: our clients are in different countries, therefore we are ready for any changes in work of any country
Development: a lot of projects and products, which means increasing expertise in working with different technologies, or even switching to completely new ones for you within the company
Active corporate life: we participate in thematic conferences and forums in our cool sphere of business, corporate parties in the best restaurants of the city with participation of stars, etc
Comfort: Offices are in different countries. You can work from anywhere in the world