FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in cloud security, particularly with AWS, including IAM, networking, and logging, while effectively managing the vulnerability lifecycle and incident response. Proficient in security engineering practices, including threat modeling, code review, and detection engineering.
Highest-signal resume keywords
Cloud Security ExperienceAWS IAM ManagementTerraform ProficiencyJava and TypeScript CodingIncident Response Experience
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security EngineeringInfrastructure-as-Code ReviewVulnerability ManagementContainer SecurityDetection EngineeringPenetration TestingCompliance TestingOAuth/OIDC KnowledgeOWASP Top 10 FamiliarityCI/CD Security Gates
Soft Skills
Collaborative ApproachClear Written CommunicationJudgment in Risk Prioritization
Tools & Technologies
AWSGCPKubernetesOktaTerraform
Certifications & Qualifications
AWS Certified Security SpecialtyCKSOSCPGCSAGCIH
Industry Keywords
FintechPaymentsBankingPCI DSSSOC 2ISO 27001
Tech Stack
Tools & technologiesAWSCloudCyber SecurityGoogle Cloud PlatformJavaKubernetesTerraformTypeScript
About the role
Key responsibilities & impact- Threat model new services with product engineers
- Review code and infrastructure-as-code
- Build tooling that automatically catches recurring security problems
- Harden the cloud environment, mainly AWS and some GCP, including IAM, network boundaries, secrets/key management, logging, Kubernetes workloads, and Okta identity engineering
- Own the vulnerability cycle end to end, including CI/CD security gates, scanning, remediation, and penetration testing
- Build and maintain detections on native cloud services and company code
- Own detection queries, functions, and runbooks
- Act as a first responder on security incidents
- Support the Head of Security on PCI DSS, SOC 2, and ISO 27001, including testing and recurring compliance activities
- Support the IT Lead with corporate-environment automation, complex investigations, and absence cover
- Help engineers adopt reusable security patterns and secure defaults
- Provide a standing slot for security questions
- Work directly with the Head of Security to secure Tuum’s banking platform, cloud infrastructure, CI/CD pipeline, and product code
Requirements
What you’ll need- Security engineering experience, or software/infrastructure engineering with substantial security ownership
- Strong cloud security experience with a focus on AWS: IAM, networking, key management, and logging
- Ability to read and write Terraform independently
- Strong skills in at least one general-purpose programming language, plus confidence reading others
- Ability to review and write maintainable Java and TypeScript code
- Practical experience securing containerised workloads
- Knowledge of identity and access fundamentals: OAuth/OIDC, SAML, and least privilege
- Working knowledge of common vulnerability classes, including OWASP Top 10 and beyond
- Experience operating an inherited security control
- Clear written English
- Judgment to prioritise real risk over checklist findings
- Collaborative approach and ability to offer workable alternatives
- University degree in cybersecurity or a related field is a bonus, not a requirement
- Detection engineering or incident response experience is a bonus
- Experience in fintech, payments, or banking is a bonus
- Payments or card-issuing domain knowledge is a bonus
- Experience standing up or running a vulnerability disclosure programme is a bonus
- Certifications such as AWS Certified Security Specialty, CKS, OSCP, GCSA, or GCIH are a bonus
Benefits
Comp & perks- Competitive salary
- Tuum stock options
- Hybrid working (3 days a week in the office)
- 4-day work week during the summer months (June, July, August)
- Private health insurance or generous wellness compensation
- Career opportunities to grow both professionally and personally as we scale
- Bright and warm-hearted team of professionals delivering great things together
- All-hands-on-deck approach (meaning that everyone delivers value regardless of responsibilities)
