About this role
We are looking for a Security Engineer with strong technical acumen who can immediately design, prioritize, and implement risk-reducing technical solutions across complex cloud and enterprise environments. This role emphasizes solution engineering over process engineering — using established information security frameworks, policies, and controls as direct inputs to build practical, automatable, and scalable technical safeguards.
The ideal candidate thinks like an engineer first and a security risk professional second: someone who already understands how systems fail, how controls are enforced through code and architecture, and how risk and compliance intent translate into resilient technical designs — without requiring extended ramp-up time on RAC fundamentals.
Key Responsibilities
• Engineer technical risk solutions that reduce operational, cyber, and resilience risk through architecture, automation, and control design — starting on day one with minimal onboarding.
• Translate risk requirements, policies, and standards into implementable technical patterns, guardrails, and reference architectures.
• Prioritize and influence solution design decisions based on risk impact, blast radius, and recovery dependencies.
• Partner with platform, cloud, security, and SRE teams to embed risk controls directly into infrastructure and pipelines.
• Evaluate control effectiveness using technical signals and evidence, not just procedural compliance checklists.
• Independently support the requirements of internal control, internal audit, and external audit engagements, including evidence gathering, control testing, and remediation tracking.
• Deploy and manage security software, assess and apply required security patches on Security Appliances (servers).
• Support the Security Appliances 24x7 on-call rotation to enable continuous data collection.
• Drive initiatives such as secure cloud architecture, isolated recovery environments, identity and access hardening, and infrastructure resilience.
• Provide informed, immediate guidance on risk tradeoffs and compliance requirements to engineering and business stakeholders.
• Contribute to lightweight process definition where needed, always in service of enabling better technical and audit outcomes.
Required Technical Skills
• Risk, Audit & Compliance Frameworks: Direct working experience with frameworks such as NIST, ISO 27001, SOX, PCI-DSS, or similar, and demonstrated ability to map controls to technical implementations.
• Data Analytics: Proficiency with GCP BigQuery, Power BI (or similar) for visualizing risk posture and audit evidence.
• Configuration Management / Automation: Ansible, REST API, Terraform.
• Programming / Scripting: Python, Linux Bash, Windows PowerShell, SQL.
• Cloud Platforms: Google Cloud Platform (GCP), Azure, AWS.
• Supporting Knowledge (nice to have):
• Cloud IAM, networking, and control planes
• CI/CD pipelines and policy-as-code
• Familiarity with Agentic AI frameworks
• Observability, logging, and evidence automation
• Backup, recovery, and resilience architectures
Required Qualifications
• 7+ years of experience in security engineering, platform engineering, SRE, or technical risk roles, with a significant portion spent directly supporting risk, audit, or compliance functions.
• Demonstrated, ready-to-apply experience with audit lifecycles, control testing, and compliance evidence collection — able to engage with auditors and risk stakeholders immediately without extensive training.
• Proven ability to design and influence technical solutions across teams.
• Strong understanding of how risk manifests in distributed systems, cloud platforms, and automation.
• Comfortable operating at the intersection of engineering teams and risk/compliance stakeholders.
• Ability to explain complex technical risk concepts to non-technical audiences without losing fidelity.
• Experience in production support and troubleshooting.