SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
AiPrise is a global compliance orchestration platform serving fintechs, marketplaces, and payment companies. The platform integrates with 80+ identity and compliance vendors to provide holistic risk assessment and is now building AI-powered compliance agents for KYB, AML, sanctions screening, and risk scoring.
You will own the security architecture of the platform end-to-end, spanning cloud infrastructure, applications, and APIs. This is a hands-on builder's role: you will work directly with engineers to identify, prioritize, and remediate real security issues, establish standards that keep them fixed, and translate regulatory requirements into practical controls the team can ship.
Key responsibilities include:
- Owning security architecture across cloud infrastructure, applications, and APIs as the platform evolves into new products and regions
- Working directly with engineers on threat modeling, security design reviews, and remediation of infrastructure, application, and API security issues
- Embedding security into the development lifecycle through secure coding standards, code review, CI/CD controls, and dependency/container security
- Defining and maintaining security standards, reference architectures, and hardening baselines
- Leading security testing, including penetration tests and vulnerability management, with closure tracking
- Translating industry and regulatory requirements (SOC 2, ISO 27001, GDPR) into concrete technical controls
- Owning the technical side of audits and assessments, including certification audits and enterprise customer security reviews
- Representing security in customer-facing conversations with prospects, customers, and their auditors
- Partnering with privacy and data-protection functions to ensure controls meet GDPR and data protection requirements, particularly for personal and biometric data
- Contributing to incident readiness, detection, investigation, and post-incident improvement
- Mentoring junior security engineers as the team grows, with eventual management responsibility
You will be the technical face of security in critical conversations with auditors, enterprise customers' security teams, and regulators. As the security team expands, you will have a clear path into leadership while continuing to set technical direction.
REQUIREMENTS:
- 7 to 9 years of experience in security engineering, security architecture, or closely related field, with a track record of securing production systems at scale
- Genuine hands-on technical depth: ability to read and reason about application code, cloud infrastructure, and API design; ability to work with engineers to fix issues rather than only flagging them
- Strong command of cloud security, including network segmentation, IAM, secrets and key management, workload and container security, and infrastructure-as-code
- Deep application and API security knowledge, including common vulnerability classes (access-control flaws, injection, SSRF), secure design patterns, authentication and authorization, and secure SDLC practices
- Solid, current understanding of industry and regulatory security and privacy requirements such as SOC 2, ISO/IEC 27001, GDPR, and related frameworks, with judgment to apply them proportionately
- Demonstrated experience handling audits and assessments of multiple kinds (certification, enterprise-client, regulatory), including preparing evidence and driving findings to closure
- Excellent stakeholder and customer-facing communication; ability to explain security clearly to engineers, executives, auditors, and customers
- Sound risk judgment; ability to balance security, business needs, and delivery with incomplete information
NICE TO HAVE:
- Experience in fintech, regtech, identity verification, or other regulated, data-sensitive domains
- Experience handling personal, biometric, and identity data and associated privacy obligations
- Background in penetration testing, red teaming, or vulnerability research
- Familiarity with privacy frameworks beyond GDPR and DevSecOps practices and tooling
- Relevant certifications (CISSP, CCSP, OSCP, CIPP, CIPT), though hands-on capability is prioritized
- Experience mentoring or leading engineers with interest in building and managing a team