SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tangible Markets is seeking their first dedicated Information Security Engineer to build and own a comprehensive security program from the ground up. This is a hands-on role with a clear path to CISO as the company scales.
You will own security across the AWS environment, including IAM and least privilege, network segmentation, encryption, logging, and detection using GuardDuty, Security Hub, and CloudTrail. You'll integrate security into the development pipeline through secrets management, dependency scanning, container scanning, and threat modeling with engineers. A core focus is automation—converting manual controls and compliance evidence collection into code-based solutions.
Key responsibilities include vulnerability management and incident response, with ownership of runbooks and security drills. You'll establish governance for AI and LLM use, assessing risks like prompt injection and data leakage while enabling productive workflows. SOC 2 Type II compliance is a major deliverable, including control design, automated evidence collection, and auditor relationships.
Regulatory expertise is essential: you'll handle GDPR, CCPA, DORA, EBA outsourcing guidelines, GLBA, and SEC/FINRA expectations for financial-institution customers. You'll lead customer security reviews, due diligence questionnaires, RFPs, and contract negotiations with bank security teams. Vendor risk management and third-party assessments are ongoing responsibilities.
You'll also build a security-aware culture through training, phishing resilience programs, and device/identity hygiene initiatives. As the company grows, you'll develop security strategy, communicate risk to leadership in business terms, manage tooling and budgets, and eventually hire and lead a security team.
Requirements: 5+ years in security engineering or security-heavy infrastructure, with deep AWS security expertise (IAM, SCPs, logging, detection, encryption). Proficiency in Python and Terraform for automation. SOC 2 Type II audit experience preferred. Working knowledge of privacy legislation and financial-services customer requirements. Familiarity with LLM security risks or strong fundamentals to develop expertise. Excellent written communication for async remote work. Ambition to grow into an executive security role with strong people skills.