Security Engineering Lead

Posted:
10/3/2024, 8:36:00 AM

Location(s):
Sofia, Sofia-City, Bulgaria ⋅ Sofia-City, Bulgaria

Experience Level(s):
Senior

Field(s):
IT & Security

Our mission is to enable everyone to build wealth

We reinvent how trading and investing works by creating exceptional products people love. Fostering a culture of excellence and high velocity is the key to our success.

Over the past few years, our client base has grown 20 times to over 3 million, and client assets have grown over 50 times to over €4 billion.

Clearly, with the growing complexity in our tech landscape and the growing capability of the adversary, there is lots to do to keep the environment secure, and as such, we are looking to recruit an experienced, world-class Security Engineering Lead to own and drive this.

What you’ll do

No two days are the same at Trading 212, so you should expect a blend of challenges, and you will use your engineering mindset to complete the tasks ahead of you. You will:

  • Manage a small team of engineers, supporting the delivery of strategic projects such as the AWS migration, ensuring the timely delivery of high-quality solutions while mentoring and cultivating the team to achieve organizational objectives.

  • Take the lead in supporting and maintaining critical solutions, such as L4/L7 Firewalls, SIEM solutions, Vulnerability scanning tools, AWS Cloud Security, E/XDR Solutions, SOAR and Incident Response tools, Offensive tools.

  • Own and drive the vulnerability management programme, ensuring the timely detection and remediation of potential threats and vulnerabilities across our on-premise and cloud infrastructure.

  • Lead our incident response activities to ensure the prompt and effective resolution of security incidents and breaches. You will be the person who can explain what happened and why, who was affected, and what we should do to prevent recurrence.

  • Engaging in collaboration with departmental leaders to assess security requirements.

  • Act as an escalation point for providing deep expertise in event analysis and triage. 

What you need to have

This is an engineering role, so technical capability is key. We don’t expect you to know all of the things, but we do expect you to have an approach which will enable you to get up to speed quickly and apply a reasoned way of working to any technology that you may not have used before. You will hit the ground running if you have experience of the following:

  • Proficiency in incident response, network security, endpoint security and vulnerability management, supported by substantial technical knowledge.

  • Hands-on experience with tools and solutions such as F5, Akamai, CloudFlare, AWS WAF, Splunk, ELK Stack, Tenable, Qualys. AWS, Azure, GCP, CrowdStrike Falcon XDR, Carbon Black, Burp Suite, Metasploit etc.

  • Scripting skills in languages like Bash, Python, PowerShell, or Terraform for automation and tool development.

  • Sysadmin-level knowledge of Linux.

  • Experience of containerisation in a Kubernetes environment.

  • Knowledge of software development tools (such as Git) and application security tools would be a bonus.

  • Ability to set and manage priorities.

  • Exceptional oral and written communication abilities for effective collaboration with team members.

  • Understanding of information security standards and regulations that apply to the financial services sector.

  • Effective leadership qualities, coupled with the skill to mentor and offer direction to the team.

  • Prior experience in a similar role involving people management responsibilities.

  • Proficiency in incident response, network security, endpoint security and vulnerability management, supported by substantial technical knowledge.

  • Business-level English.

What we offer

This is not an isolated role hidden away in a security ivory tower. You will be working on Production platforms using DevOps processes from the outset. You will be exposed to all facets of world-class engineering teams and thrive in that environment. In return, you will receive:

  • Challenges that will help you grow and realise your potential.

  • Opportunity to make a big impact - you’ll be involved in developing cutting-edge services used by millions of investors to build wealth.

  • Work with smart, spirited, helpful, high-performing colleagues toward a common goal.

  • Appreciation for your talent and ideas.

  • Generous remuneration package, including annual bonuses.

  • Excellent social benefits package, including private health insurance, sports card and 25 days of paid vacation per year.

  • Delicious treats and a spacious game room.

Are you ready to accelerate your career with us? We'd love to hear from you!

We thank all applicants, but only candidates selected for an interview will be contacted.

All personal data of applicants is protected by the law and will be treated with strict confidentiality.