Staff Security Engineer, InfraSec
Role details
Job location
Tech stack
Job description
-
Designing, implementing, and maintaining security controls across multi-cloud environments (AWS, GCP, etc.), Kubernetes clusters, and containerized workloads (Docker).
-
Developing secure-by-default patterns for infrastructure-as-code (Terraform) and container orchestration platforms.
-
Writing code in Go to automate security processes, enforce guardrails, and integrate security solutions.
-
Conducting security reviews of cloud architecture, data platforms (e.g., Snowflake, Databricks), and routing configurations to identify vulnerabilities and recommend improvements.
-
Partnering with engineering teams to embed security into the design and deployment of platform services.
-
Collaborating with cross-functional teams to align security initiatives with business goals, balancing security, risk, and enablement.
-
Evaluating security needs during mergers and acquisitions (M&A) and ensuring acquired companies are integrated into secure paved road frameworks.
-
Influencing senior leaders and stakeholders on technical decisions, risk management strategies, and tradeoffs to drive secure and scalable outcomes.
-
Driving continuous improvement of security policies, threat detection mechanisms, and incident response automations.
Requirements
-
At least 7 years of experience in infrastructure security, with strong expertise in both AWS and Kubernetes, and deep SME-level knowledge in at least one.
-
Proficiency in writing Go for automation and guardrails, and deploying infrastructure with Terraform.
-
Expertise across modern cloud and containerized platform technologies, including securing data platforms (e.g., Snowflake, Databricks) and cloud edge security.
-
Proven ability to partner with engineering, product, and business teams to align security initiatives with broader company goals.
-
Experience influencing senior leaders and stakeholders on technical decisions, risk tradeoffs, and enablement strategies.
-
An execution-focused approach, capable of navigating ambiguity and delivering impactful results.
-
A commitment to advancing an open financial system that connects the world.
Nice to haves:
-
Experience with hybrid cloud and on-prem environments, including platforms like GCP and Vercel, to secure infrastructure in a multi-cloud company alongside AWS and on-prem systems.
-
Proficiency in crafting Rego rules for Open Policy Agent (OPA) or similar tools to enforce security policies at scale.
-
Physical networking and datacenter experience, including securing physical infrastructure and managing network hardware in datacenter environments.