This is a remote position.
- Provide architectural guidance on cryptographic key management and secure API design.
- Review, assess, and improve the security of systems related to identity and access control.
- Model all secure end-points and re-engineer access to the end-points targeting security without operational disruption
- Conduct threat modelling and risk assessments for distributed systems and critical business workflows.
- Define and implement security controls for sensitive operations, including privileged access, internal tooling, and system integrations.
- Proactively identify emerging risks and contribute to internal processes for risk tracking and mitigation.
- Lead the response to security incidents, including investigation, containment, and remediation.
- Improve detection, monitoring, and alerting across systems and infrastructure.
- Develop and maintain incident response playbooks for handling security incidents, including abuse and hacking scenarios.
- Help define and maintain security standards and best practices for application development and infrastructure.
- Ensure proper secrets management, access control, and system hardening.
- Work closely with engineering, product, and infrastructure teams to embed security throughout the development lifecycle.
- Provide practical guidance on secure system design, especially for systems handling sensitive data or high-risk operations.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Proven experience in security, ethical hacking, or in a similar security-focused role.
- Strong understanding of security principles, including authentication, authorization, and cryptography.
- Experience securing systems involving digital transactions, sensitive data, or high-privilege access.
- Solid knowledge of operating systems, networking, and secure software development practices.
- Hands-on experience with AWS cloud security.
- Strong analytical, troubleshooting, and problem-solving skills.
