Talent.com
Tangible
Information Security Engineer (CISO track)Tangible • London, England, United Kingdom
Information Security Engineer (CISO track)

Information Security Engineer (CISO track)

Tangible • London, England, United Kingdom
30+ days ago
Job type
  • Full-time
  • Part-time
  • Remote
  • Quick Apply
Job description

Fully remote · CET timezone or close - Full-time · Reports to the CTO

About the role

You'll be our first dedicated information security hire. Right now security is a part-time job for engineering leadership and external vendor; we want it to be your full-time one. The work is hands-on: AWS, infrastructure as code, detection and response, auditors. As the company grows, the role grows into CISO.

We sell to financial institutions, and their security teams question everything we do, so you'll be the person with good answers.

Tasks

What you'll do

  • Own security in our AWS environment: IAM and least privilege, network segmentation, encryption, logging and detection (GuardDuty, Security Hub, CloudTrail), fixing what you find.
  • Build security into the development pipeline: secrets management, dependency and container scanning, code review for risky changes, threat modeling with the engineers.
  • Automate. Detection rules, alerting, compliance evidence, IaC guardrails. If a control can be code instead of a meeting, make it code.
  • Run vulnerability management and incident response. Write the runbooks, run the drills.
  • Set the rules for our AI and LLM use: which data goes to which vendors, which models are approved, how prompts and outputs are handled and logged. Assess risks like prompt injection and data leakage, design controls that let people keep working.
  • Own SOC 2: control design, automated evidence collection, the auditor relationship.
  • Handle regulatory side for our financial-institution customers: GDPR and CCPA for privacy, DORA and EBA outsourcing guidelines in the EU, GLBA and SEC/FINRA expectations in the US.
  • Lead customer security reviews: due diligence questionnaires, RFPs, contract security terms, calls with bank security teams.
  • Run vendor reviews and third-party risk.
  • Secure the human half by building awareness training, phishing resilience, and device and identity hygiene that work for deals and sales people, not only engineers.
  • Over time: set the security strategy, report risk to leadership in business terms, choose tooling, build a budget, hire.

Requirements

What we're looking for

  • 5+ years in security engineering or security-heavy infrastructure work, with depth in AWS security (IAM, SCPs, logging, detection, encryption). Certifications are fine, but shipped work is better.
  • Python and Terraform, or close equivalents. You automate evidence collection instead of maintaining spreadsheets.
  • SOC 2 experience, ideally owning a Type II audit. Working knowledge of privacy legislation.
  • Exposure to financial-services customer scrutiny, or the appetite to make it your specialty.
  • A working view on LLM security risks, or strong fundamentals and the curiosity to build one.
  • Judgment about which risks matter. You can tell an auditor why a control exists and an engineer why it isn't theater.
  • Clear writing. Remote means async, and async means your policies and risk memos do the talking.
  • The ambition to grow into an executive role and the people skills to survive it.

Nice to have

  • Fintech or another regulated B2B environment with large financial-institution customers.
  • DORA, EBA/ESMA outsourcing guidelines, or NYDFS 500.
  • Experience securing enterprise integrations: SSO/SCIM, SFTP feeds, APIs.
  • You've been the first security hire somewhere before.

Benefits

What we offer

  • A blank slate with real ownership
  • A committed path to CISO.
  • Fully remote, flexible hours.
  • Direct access to leadership and to customer security teams at major financial institutions.
  • Competitive pay, equity, learning budget.

How we hire

  1. Intro call (30 min).
  2. Technical deep dive (60–90 min): AWS security scenarios, plus a walk-through of a program you built.
  3. Practical exercise: review a sanitized architecture or a due diligence questionnaire and tell us what you'd fix first.
  4. Leadership conversation: the CISO path, and working with the non-technical half of the company.
  5. References and offer.

We're an equal opportunity employer. If you don't tick every box, apply anyway.



Tangible is transforming the way secondary markets work for LPs, GPs and wealth managers.

We combine technology and deep private markets expertise to bring transparency, efficiency and simplicity to secondary transactions. Our products enable more LPs to sell on the secondary market and empower GPs and wealth managers to create scalable liquidity solutions for their investors.

Create a job alert for this search

Information Security Engineer (CISO track) • London, England, United Kingdom

Similar jobs

Information Security Engineer

FortegraGreater London, England, GB
Full-time

Responsible for safeguarding the confidentiality, integrity, and availability of data, applications, infrastructure, and AI systems across the organization.The Security Engineer leads day‑to‑day op... Show more

 • Promoted

Remote Information Security Engineer — Path to CISO, AWS & SOC2

TangibleGreater London, England, GB
Remote
Full-time

Tangible is looking for its first dedicated information security hire to manage AWS security and lead the company's security initiatives.This fully remote role involves developing security strategi... Show more

 • Promoted

Senior SOC Engineer: Lead Threat Detection & Incident Response

MTIGreater London, England, GB
Permanent

MTI is seeking a Senior SOC Engineer to play a pivotal role in delivering security operations in their Managed Security Services team.This position requires hands-on experience with SIEM and EDR to... Show more

 • Promoted

Senior Identity Security Engineer: Cloud IAM & SSO

WPP MediaGreater London, England, GB
Full-time

WPP Media is seeking a Senior Security Engineer based in London to enhance security configurations for identity across various platforms.This role entails designing secure patterns in Azure AD, Okt... Show more

 • Promoted

Infrastructure Lead: Platform, Security & CI/CD

PassFortGreater London, England, GB
Full-time

OLIX in London is seeking an Infrastructure Manager to build and lead the team responsible for the internal platform our entire organization depends on.You will own the compute, storage, networking... Show more

 • Promoted

Information Security Engineer

MedpaceGreater London, England, GB
Full-time

The Information Security team defends the company’s digital infrastructure by designing, implementing, and improving the organization’s cybersecurity architecture.This is a critical role responsibl... Show more

 • Promoted

Strategic Cloud Security Architect

Global RelayGreater London, England, United Kingdom
Full-time

Global Relay seeks a Principal Cyber Security Architect to design and evolve security architecture across cloud, infrastructure, and data domains.You will drive secure-by-design decisions, partner ... Show more

 • Promoted

Cloud Security & AI Strategy Leader

Bridewell Consulting LimitedGreater London, England, United Kingdom
Full-time

Bridewell Consulting Limited is seeking a strategic Head of Cloud Engineering to lead and grow the Cloud Security practice.You will define the vision, capability, and commercial success of our clou... Show more

 • Promoted

Lead Security Incident Response Engineer: Cloud & Forensics

Checkout.comGreater London, England, United Kingdom
Full-time

London is seeking a senior security incident response lead to own the technical direction of incident response across the company.You will guide investigations, containment, eradication, and recove... Show more

 • Promoted

Information Security Engineer

Medpace, Inc.Greater London, England, GB
Full-time

The Information Security team defends the company's digital infrastructure by designing, implementing, and improving the company's cybersecurity architecture.This is a critical role responsible for... Show more

 • Promoted

Information Security Engineer - Vulnerability Management

Starling BankGreater London, England, GB
Full-time

Starling is the UK's first and leading digital bank on a mission to fix banking! Our vision is fast technology, fair service, and honest values.All at the tap of a phone, all the time.We are about ... Show more

 • Promoted

Information Security Engineer

AlgoliaGreater London, England, GB
Full-time

As Algolia continues to expand globally, we are growing our Information Security team to match that scale.We are seeking a pragmatic, technically strong, and collaborative information security engi... Show more

 • Promoted

Information Security Engineer - Vulnerability Management

Starling Bank LimitedGreater London, England, GB
Full-time

Starling is the UK's first and leading digital bank on a mission to fix banking! Our vision is fast technology, fair service, and honest values.All at the tap of a phone, all the time.We are about ... Show more

 • Promoted

Security Engineer — SOC & Threat Detection (Remote)

TechnologyOneGreater London, England, GB
Remote
Full-time

A leading technology firm in the UK is seeking a Security Engineer to safeguard digital platforms from security threats.The successful candidate will conduct audits, implement monitoring systems, a... Show more

 • Promoted

Chief Cloud Security & AI Transformation Lead

PVH (Tommy Hilfiger/Calvin Klein)Greater London, England, United Kingdom
Full-time

Bridewell is seeking a Head of Cloud Engineering to lead and grow our Cloud Security practice.You will define the vision, build the team, and drive delivery excellence across client engagements and... Show more

 • Promoted

Information Security and Compliance Engineer

Engineered ArtsGreater London, England, GB
Full-time

Engineered Arts is seeking an Information Security and Compliance Engineer to own the technical and operational execution of information security and cybersecurity compliance across products, cloud... Show more

 • Promoted

Hybrid Senior Security Engineer | SC-Cleared XSIAM Expert

LHHGreater London, England, GB
Full-time

LHH in the United Kingdom is seeking a Senior Security Engineer to strengthen security monitoring, threat detection and incident response.You will design and optimize security operations across a c... Show more

 • Promoted

CSOC Engineer: Security Escalations & Mentoring

FastlyGreater London, England, GB
Full-time

A leading edge cloud provider is seeking a CSOC Engineer to join their team in London.This role involves monitoring customer activities to identify security threats and designing tools to enhance s... Show more

 • Promoted

Strategic Information Security Leader (Hybrid)

Langley James HR & IT RecruitmentCity Of London, England, GB
Full-time

Langley James HR & IT Recruitment is seeking a Cyber Security Engineer for a Financial firm near Bank station.The role is hybrid (3 days in office, 2 days remote) with a salary up to £95k plus bonu... Show more

 • Promoted

Deputy CISO: Global Information Security Leader

GXO Logistics, IncGreater London, England, GB
Full-time

GXO Logistics, Inc is seeking a Deputy CISO to lead day-to-day execution of its global cybersecurity program, ensuring strategic alignment and robust operations within a complex logistics environme... Show more