Run threat modeling and security reviews for major architectural or product changes.
Review and improve WAF rules rate limiting and abuse prevention in a practical measurable way.
Support security and privacy requirements relevant to the business (e.g. GDPR PDPL).
Maintain control mapping and evidence in Drata (or similar tools) with a strong focus on automation.
6 years of experience in security engineering or a closely related role.
Proven experience leading security efforts in startups or high-growth environments.
Strong hands-on background you can identify an issue fix it and ship it to production yourself.
Experience securing CI/CD pipelines build systems and runtime environments.
Experience with incident response vulnerability management and security monitoring.
Practical and execution-driven you focus on reducing real risk not writing security theatre.
Comfortable operating independently and setting priorities without heavy process.
Collaborative by default you partner with engineers and enable them with secure defaults.
High-ownership mindset you take problems from discovery all the way to production.
Experienced in startup environments and comfortable with ambiguity and speed.
Background outside of heavily regulated fintech environments (preferred).
This listing is sourced from a third-party job board. Applying will redirect you to the original posting.
Journeyman Distillery
Addition Management
Wood, Smith, Henning & Berman LLP