- Secure and harden cloud infrastructure, applications, APIs, internal systems, and operational workflows
- Implement and maintain security controls across production environments, CI/CD pipelines, cloud infrastructure, and internal tooling
- Remediate vulnerabilities and improve secure development practices with engineering teams
- Maintain encryption, secrets management, logging, monitoring, and access controls
- Design and improve security architecture across cloud-native and distributed systems
- Identify, assess, prioritize, and remediate vulnerabilities across infrastructure, applications, APIs, and operational systems
- Conduct vulnerability scanning, penetration testing, adversarial testing, threat modeling, and manual security reviews
- Coordinate remediation efforts, validate fixes, and implement long‑term mitigation strategies
- Improve detection and prevention capabilities for emerging threats
- Secure AI‑driven systems and automated agents against prompt injection, adversarial inputs, unauthorized actions, unsafe outputs, and data leakage
- Design guardrails and validation layers for AI‑generated actions
- Monitor AI behavior for anomalies, abuse attempts, and unsafe decision‑making
- Ensure AI systems are observable, auditable, bounded, and fail safely
- Improve security monitoring, alerting, logging, and incident response capabilities
- Investigate suspicious activity, anomalies, and potential security incidents
- Lead or support incident response, root cause analysis, and remediation planning
- Recommend preventative measures following incidents or security discoveries
- Collaborate with Compliance and Operations to meet SOC 2, PCI DSS, and financial and consumer data security requirements
- Assist with audit preparation, evidence collection, security documentation, and control validation
- Participate in risk assessments, control reviews, and remediation planning
- Participate in customer and partner due diligence processes
- Answer technical security questions from customers, financial institutions, prospects, partners, auditors, and assessors
- Complete security questionnaires, RFPs, and vendor risk assessments
- Communicate security architecture, operational controls, monitoring capabilities, and security practices
- Collaborate with Engineering, Product, Compliance, Operations, and Leadership
- Contribute to architecture reviews, security planning, engineering roadmaps, and operational processes
- Embed security‑first practices into engineering and operational culture
- Balance security, reliability, scalability, and business velocity
Requirements
- 5+ years of hands‑on experience in security engineering, infrastructure security, application security, DevSecOps, vulnerability management, or offensive security
- Exceptional knowledge of the AWS ecosystem
- Experience identifying and remediating vulnerabilities in production systems
- Working knowledge of SOC 2, PCI, and FinTech security best practices
- Ability to drive projects, make decisions, and prioritize in a fast‑moving environment
- Excellent communication skills for explaining complex systems to engineering and business stakeholders
- Experience securing AI/LLM‑powered systems or automated agents preferred
- Familiarity with prompt injection attacks, adversarial AI techniques, AI guardrails, validation systems, and behavioral anomaly detection preferred
- Experience with cloud security tooling, SIEM, observability platforms, penetration testing tools, endpoint security platforms, and infrastructure‑as‑code security preferred
- Prior experience in high‑growth startups, FinTech, banking, or payments preferred
- CISSP, CISM, AWS Security Specialty, or similar certifications preferred
Core Competencies
Demonstrates expertise in securing cloud infrastructure and applications, with a strong focus on vulnerability management, incident response, and compliance with SOC 2 and PCI standards. Proficient in implementing security controls and improving security architecture for AI-driven systems and operational workflows.
Highest‑signal resume keywords
- Security Engineering
- Vulnerability Management
- AWS Ecosystem
- Incident Response
- DevSecOps
ATS Optimization Keywords
Hard Skills
- Vulnerability Scanning
- Penetration Testing
- Threat Modeling
- Security Architecture Design
- Encryption Management
- Access Control Implementation
- CI/CD Security
- Behavioral Anomaly Detection
- Remediation Planning
- Security Documentation
Soft Skills
- Excellent Communication
- Project Management
- Decision Making
- Collaboration
Certifications & Qualifications
- CISSP
- CISM
- AWS Security Specialty
Industry Keywords
- SOC 2
- PCI DSS
- FinTech
- Adversarial AI Techniques
- AI Guardrails
Tools & Technologies
- Cloud Security Tooling
- SIEM
- Observability Platforms
- Endpoint Security Platforms
- Infrastructure‑as‑Code Security