Overview
In this role you lead product, cloud and security assurance for a confidential, multi-tenant SaaS platform serving financial services. You will partner with engineering and cloud teams to secure AWS environments and own security controls across identity, audit trails and incident response. You’ll drive compliance programs (SOC 2, ISO 27001) and support customer security reviews. This position offers scope to shape security standards and align security with enterprise needs.
Responsibilities
- Lead product and application security across the development lifecycle, including threat modelling, secure code review, vulnerability management and CI/CD security controls
- Collaborate with engineering and cloud teams to secure AWS environments (IAM, network segmentation, encryption, logging and monitoring)
- Own security controls around identity, permissions, tenant isolation, audit trails and incident response
- Lead security assurance activities covering SOC 2, ISO 27001 and broader customer security requirements
- Support enterprise customer security reviews, questionnaires and due diligence, while helping shape security standards across the organisation
Key requirements
- 7+ years’ experience in cyber security or security engineering
- Strong experience securing cloud-native SaaS platforms, ideally within AWS
- Hands-on application security across threat modelling, OWASP and secure software development
- Good understanding of cloud security, identity, access controls, encryption and monitoring
- Experience delivering or implementing SOC 2 and/or ISO 27001 programmes
- Experience supporting enterprise security reviews, questionnaires, audits or customer due diligence
- Strong communication skills with the ability to work effectively with engineers, leadership and external stakeholders
- communication
- stakeholder management
- collaboration
- AWS security (IAM, encryption, logging, monitoring)
- Threat modelling
- OWASP
…
