Information Security Engineer (CISO track)

Tangible

United States

Remote

GBP 90,000 - 150,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Ownership of security program
Fully remote
Learning budget
Direct access to leadership

Job summary

Tangible is seeking its first dedicated information security hire to lead security across AWS, IaC, and audits while working fully remotely. The role will evolve toward CISO as the company scales, interacting with engineering, product, and leadership.

You will own security controls, incident response, and vendor risk in a fast-growing fintech-adjacent environment. You will build robust detection, automation, and governance, collaborating with auditors and financial-institution clients to provide

Qualifications

  • 5+ years in security engineering or security-heavy infrastructure.
  • Depth in AWS security (IAM, SCPs, logging, detection, encryption).
  • Python and Terraform, or close equivalents; automate evidence collection.
  • SOC 2 experience, ideally owning a Type II audit; privacy legislation knowledge.
  • Exposure to financial-services customer scrutiny or the drive to specialize.
  • LLM security awareness and ability to discuss risk with engineers and auditors.
  • Judgment on which risks matter; ability to justify controls to auditors.
  • Clear writing for async remote communication and policy memos.
  • Ambition to grow into an executive role and people skills to sustain it.

Responsibilities

  • Own security in our AWS environment: IAM, least privilege, network segmentation, encryption, logging and detection.
  • Build security into the development pipeline: secrets management, scanning, threat modelling.
  • Automate detection rules, alerting, evidence collection, and IaC guardrails.
  • Run vulnerability management, incident response, and runbooks.
  • Define rules for AI/LLM usage: data handling, model approvals, prompts logging.
  • Own SOC 2: control design, automated evidence collection, auditor liaison.
  • Handle regulatory duties for financial‑institution customers: GDPR, CCPA, DORA, etc.
  • Lead customer security reviews: due diligence, RFPs, contract security terms.
  • Run vendor reviews and third-party risk; build security awareness training.
  • Over time: set security strategy, report risks, budget, hire.

Skills

AWS security
Python
Terraform
SOC 2
Privacy laws
LLM security
Auditing
Risk communication
Writing skills
Leadership potential

Tools

GuardDuty
Security Hub
CloudTrail

Job description

Fully remote · CET timezone or close - Full-time · Reports to the CTO

About the role

You'll be our first dedicated information security hire. Right now security is a part‑time job for engineering leadership and external vendor; we want it to be your full‑time one. The work is hands‑on: AWS, infrastructure as code, detection and response, auditors. As the company grows, the role grows into CISO.

We sell to financial institutions, and their security teams question everything we do, so you'll be the person with good answers.

Tasks
  • Own security in our AWS environment: IAM and least privilege, network segmentation, encryption, logging and detection (GuardDuty, Security Hub, CloudTrail), fixing what you find.
  • Build security into the development pipeline: secrets management, dependency and container scanning, code review for risky changes, threat modeling with the engineers.
  • Automate. Detection rules, alerting, compliance evidence, IaC guardrails. If a control can be code instead of a meeting, make it code.
  • Run vulnerability management and incident response. Write the runbooks, run the drills.
  • Set the rules for our AI and LLM use: which data goes to which vendors, which models are approved, how prompts and outputs are handled and logged. Assess risks like prompt injection and data leakage, design controls that let people keep working.
  • Own SOC 2: control design, automated evidence collection, the auditor relationship.
  • Handle regulatory side for our financial‑institution customers: GDPR and CCPA for privacy, DORA and EBA outsourcing guidelines in the EU, GLBA and SEC/FINRA expectations in the US.
  • Lead customer security reviews: due diligence questionnaires, RFPs, contract security terms, calls with bank security teams.
  • Run vendor reviews and third‑party risk.
  • Secure the human half by building awareness training, phishing resilience, and device and identity hygiene that work for deals and sales people, not only engineers.
  • Over time: set the security strategy, report risk to leadership in business terms, choose tooling, build a budget, hire.
Requirements
  • 5+ years in security engineering or security‑heavy infrastructure work, with depth in AWS security (IAM, SCPs, logging, detection, encryption). Certifications are fine, but shipped work is better.
  • Python and Terraform, or close equivalents. You automate evidence collection instead of maintaining spreadsheets.
  • SOC 2 experience, ideally owning a Type II audit. Working knowledge of privacy legislation.
  • Exposure to financial‑services customer scrutiny, or the appetite to make it your specialty.
  • A working view on LLM security risks, or strong fundamentals and the curiosity to build one.
  • Judgment about which risks matter. You can tell an auditor why a control exists and an engineer why it isn’t theater.
  • Clear writing. Remote means async, and async means your policies and risk memos do the talking.
  • The ambition to grow into an executive role and the people skills to survive it.
Nice to have
  • Fintech or another regulated B2B environment with large financial‑institution customers.
  • DORA, EBA/ESMA outsourcing guidelines, or NYDFS 500.
  • Experience securing enterprise integrations: SSO/SCIM, SFTP feeds, APIs.
  • You’ve been the first security hire somewhere before.
Benefits
  • A blank slate with real ownership
  • A committed path to CISO.
  • Fully remote, flexible hours.
  • Direct access to leadership and to customer security teams at major financial institutions.
  • Competitive pay, equity, learning budget.

We're an equal opportunity employer. If you don't tick every box, apply anyway.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote InfoSec Engineer: Path to CISO
Remote InfoSec Engineer: Path to CISO

Tangible • United Kingdom

On-site
GBP 90,000 - 150,000
Ownership of security program
Fully remote
Learning budget
+1
Staff Security Engineer
Staff Security Engineer

CFC • City Of London

On-site
GBP 120,000 - 180,000
Staff Security Engineer
Staff Security Engineer

CFC • Greater London

On-site
GBP 90,000 - 140,000
Security Lead
Security Lead

Taktile • Greater London

On-site
GBP 110,000 - 190,000
Equity
Self-development budget
Home office setup
+1
Lead Security Engineer
Lead Security Engineer

Winston Fox • Greater London

On-site
GBP 70,000 - 95,000
Senior Security Engineer
Senior Security Engineer

Spendesk • Greater London

On-site
GBP 90,000 - 120,000
Staff Security Engineer
Staff Security Engineer

CFC Underwriting • Greater London

On-site
GBP 90,000 - 130,000
Head of Security Engineering (DevSecOps & CISO)
Head of Security Engineering (DevSecOps & CISO)

United States Digital Space LLC • Greater London

Hybrid
GBP 140,000 - 230,000
Private health insurance
Pension (up to 6%)
£1,000 annual education budget
+5
Information Security Manager
Information Security Manager

United States Digital Space LLC • Greater London

Hybrid
GBP 80,000 - 110,000
Unlimited Annual Leave Policy
Private healthcare and dental
Enhanced parental leave
+3
Engineering Manager, Security
Engineering Manager, Security

Insignis • Greater London

Hybrid
GBP 120,000 - 180,000
25 days holiday (exc. Bank holidays)
5% Pension contributions
Private medical insurance with Vitaliy
+4