About the Company
My client is a fast-growing fintech company, building secure and scalable infrastructure to support digital payments and next-generation financial services. The team operates in a highly regulated and security-critical environment, with strong emphasis on system reliability, compliance, and end-to-end platform protection. They are now expanding their cybersecurity function to further strengthen the security posture across engineering and infrastructure.
Responsibilities
- Design and implement security controls across identity (SSO, MFA, access policies) and reduce account takeover risks
- Establish endpoint and mobile security baselines (MDM, device compliance, posture checks)
- Embed security into CI/CD pipelines (SAST, DAST, SCA, IaC security, policy‑as‑code)
- Build and manage centralized secrets management and prevent credential leakage
- Develop detection rules aligned with MITRE ATT&CK and support threat hunting activities
- Participate in purple team exercises and continuously improve security controls
- Build automation for incident response (SOAR, playbooks, scripting) to improve response efficiency
- Support compliance frameworks (MAS TRM, CIS benchmarks, SOC2 / PCI‑DSS readiness)
Qualifications
- 5–10 years of experience in Security Engineering / DevSecOps / Application Security
- Hands‑on experience with identity security (SSO, SAML/OIDC, MFA)
- Experience implementing DevSecOps practices in CI/CD pipelines
- Familiar with detection engineering, SIEM/EDR, or security monitoring
- Experience with automation (scripting, APIs, or security tooling)
- Exposure to cloud environments and modern infrastructure
- Strong collaboration skills with engineering teams
Benefits
- High‑impact role in a security‑critical fintech environment
- Opportunity to work across end-to-end security domains
#J-18808-Ljbffr…
