About the job
You'll own the security of our AWS infrastructure and our client-facing web
and mobile apps. This ishands-on engineering — building controls and breaking
things, not filing findings for someone else to fix.
What you'll do
Cloud security
-
Design and enforce guardrails across multi-account AWS — IAM least
privilege, SCPs, secretsmanagement, network segmentation
-
Build detections on CloudTrail, GuardDuty, and Config, and own the alerts
you create
-
Secure our EKS and CI/CD layer: admission control, image scanning, IaC
scanning, SBOM as a build artifact
-
Integrate SIEM and CSPM platforms, and write the detection rules that run on
them
Mobile security
-
Attack our own Android and iOS builds — reverse engineer, hook with Frida,
bypass detection logic, and report what you find before someone else does
-
Review WebView and native bridge surfaces, deeplinks, and on-device storage
for token and PIIleakage
-
Run pre-release mobile pentests and drive fixes with the mobile teams
-
Working knowledge of app integrity is a plus: root/jailbreak and
hooking-framework resistance,Play Integrity / App Attest, certificate
pinning and rotation
Web and application security
-
Threat model and review new services, with focus on auth and money-movement
flows
-
Own WAF and edge security — rule authoring, bot management, bypass-path
review
-
API security: authorization enforcement, BOLA/IDOR classes, token and
session lifecycle, OAuth/OIDC review
-
Triage our responsible disclosure pipeline end to end
Incident response and assurance
-
Security on-call; lead investigations across cloud, identity, and endpoint
logs through to root cause and closure
-
Run internal VAPT cycles and track remediation to closure
What we're looking for
-
3–5 years in security engineering, with hands-on cloud security at scale
-
Strong scripting in Python or Go; automation is the job, not a bonus
-
OWASP Top 10, MASVS, and API Security Top 10 as working tools
Nice to have
-
Fintech or other regulated-industry experience
-
Kubernetes/EKS security depth
-
CVEs, published research, CTF placements, or bug bounty track record
-
OSCP or equivalent