Jobs and Careers
TR
Senior Security Engineer
TrueAccordUKRemotefull_timeVerifiedPosted 16 Mar 2023
About the role
Why TrueML? TrueML is a mission-driven financial software company that aims to create better customer experiences for distressed borrowers. Consumers today want personal, digital-first experiences that align with their lifestyles, especially when it comes to managing finances. TrueML’s approach uses machine learning to engage each customer digitally and adjust strategies in real time in response to their interactions. The TrueML team includes inspired data scientists, financial services industry experts and customer experience fanatics building technology to serve people in a way that recognizes their unique needs and preferences as human beings and endeavoring toward ensuring nobody gets locked out of the financial system.
The Role:
TrueML’s InfoSec team is responsible for keeping our systems secure and compliant. In this role, you will work across several internal departments across entities (Engineering, Product, Operations, Legal, Audit and Compliance) as well as with our security partners (auditors, security management platform providers) and clients to systematically identify and address information security issues. The work will include security gap analysis, advising product engineers on best practices, and helping implement and validate relevant solutions.
The Role:
TrueML’s InfoSec team is responsible for keeping our systems secure and compliant. In this role, you will work across several internal departments across entities (Engineering, Product, Operations, Legal, Audit and Compliance) as well as with our security partners (auditors, security management platform providers) and clients to systematically identify and address information security issues. The work will include security gap analysis, advising product engineers on best practices, and helping implement and validate relevant solutions.
What You'll Do:
- Evangelizing information security across the company, training employees on new procedures
- Ownership of the PCI-DSS compliance process
- Support and deliver scalable security solutions across our diverse networks
- Consistently assess and communicate security risks associated with practices performed by the company; develop appropriate mitigation countermeasures
- Vulnerability Management program (detection, analysis, reporting, remediation assistance)
- Incident Response: Support the detection, response, and recovery from security incidents
- Provide support for automation and orchestration for 24x7x365 vulnerability management and patch validation
- Build out continuous monitoring and audit for real-time audit and compliance of frameworks
- Perform threat modeling and turn that into actionable plans to reduce risk
- Evaluate security tooling, support the development of new tools, and deploying those tools at scale
- Build out threat intelligence platform using data analytics
- Automate key security-related activities, embed security controls and processes within team workflows
- Static code analysis
- Implement test automation to assure application is tested for security in the backend, UI, and integration before it is moved to the production environment
- Participate in diagnosing and resolving security-related incidents
- Provide audit and certification support
- Implement and execute ongoing programs for proactive testing, patching, and remediation of vulnerabilities align with documented policies
What We're Looking For:
- 5+ years experience in Information Security
- 3+ years of management or lead experience
- Bachelor's degree OR equivalent relevant experience
- Recent success with PCI, SOC, and similar certifications
- Demonstrable expertise in data protection, compliance validation, vulnerability analysis, network security, infrastructure security, identity and access management, logging and monitoring, and incident response
- Strong information security risk-based prioritization abilities
- Familiarity with CASB implementation and Threat Intel feeds to identify and correlate IOCs with user behavior analytics and URL filtering
- Understanding of cloud primitives such as VPC, IAM Policy, KMS, WAF
- Experience in generating automated metrics to measure IT security effectiveness and consistency
- Demonstrated leadership, teamwork, and collaboration skills
- Results-oriented, high energy, self-motivated
- Information security professional certifications (SANS GIAC, CISSP etc.)
- Experience with Chef/Puppet, Terraform, Jenkins, Git, Helm
- Experience with GRC Tools
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s