SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tuum is a next-generation banking platform enabling fintech and banks to rapidly offer seamless financial services. The platform is API-based with flexible modules covering retail and business banking capabilities, launched in 2019 and backed by major investors including Citibank, BlackFin Capital Partners, and Portage Ventures.
You will work directly with the Head of Security on a hands-on, build-oriented role focused on code, automation, and root-cause fixes rather than ticket management. Your responsibilities include:
• Threat modeling new services with product engineers, conducting code and infrastructure-as-code reviews, and building tooling to catch recurring problems automatically
• Hardening the cloud environment (primarily AWS, some GCP) across IAM, network boundaries, secrets/key management, logging, Kubernetes workloads, and Okta identity engineering
• Owning the vulnerability cycle end-to-end: CI/CD gates (SAST, SCA, ECR image scanning), quarterly internal/external scanning, remediation to policy timeframes, and penetration testing programs
• Building and maintaining detections on native cloud services and custom code; acting as a first responder on incidents
• Supporting compliance efforts for PCI DSS, SOC 2, and ISO 27001 through testing and recurring calendar management
• Supporting the IT Lead on corporate environment automation and complex investigations
• Helping other engineers make secure decisions through reusable patterns, secure defaults, and standing security consultation slots
The platform is primarily built in Java and TypeScript. You will review both languages and write maintainable code.
REQUIREMENTS:
• Security engineering experience, or software/infrastructure engineering with substantial security ownership; deep working knowledge matters more than job titles
• Strong cloud security experience with AWS focus: IAM, networking, key management, logging
• Ability to read and write Terraform independently
• Strong skills in at least one general-purpose language, plus confidence reading others
• Practical experience securing containerized workloads
• Identity and access fundamentals: OAuth/OIDC, SAML, least privilege
• Working knowledge of common vulnerability classes (OWASP Top 10 and beyond) and structural prevention approaches
• Experience operating an inherited security control
• Clear written English and judgment to prioritize real risk over checklist findings
• Collaborative approach with ability to say no when it matters and offer workable alternatives
BONUS:
• University degree in cybersecurity or related field
• Detection engineering or incident response experience (log pipelines, EDR, cloud audit trails)
• Experience in regulated or high-trust environments (fintech, payments, banking)
• Payments or card-issuing domain knowledge (PAN flows, scheme/issuer integration)
• Vulnerability disclosure program experience
• Certifications: AWS Certified Security Specialty, CKS, OSCP, or hands-on GIAC tracks (GCSA, GCIH)