Hiring.Camp

Information Security Engineer (CISO track)

Tangible Marketscom

·

Jun 10, 2026

Location
United Kingdom
Workplace
Remote
Type
Contract
Department
Professional / Experienced
Source
JOIN

Description

Fully remote · CET timezone or close - Full-time · Reports to the CTO

**About the role**

You'll be our first dedicated information security hire. Right now security is a part-time job for engineering leadership and external vendor; we want it to be your full-time one. The work is hands-on: AWS, infrastructure as code, detection and response, auditors. As the company grows, the role grows into CISO.

We sell to financial institutions, and their security teams question everything we do, so you'll be the person with good answers.

## Tasks

**What you'll do**

  • Own security in our AWS environment: IAM and least privilege, network segmentation, encryption, logging and detection (GuardDuty, Security Hub, CloudTrail), fixing what you find.
  • Build security into the development pipeline: secrets management, dependency and container scanning, code review for risky changes, threat modeling with the engineers.
  • Automate. Detection rules, alerting, compliance evidence, IaC guardrails. If a control can be code instead of a meeting, make it code.
  • Run vulnerability management and incident response. Write the runbooks, run the drills.
  • Set the rules for our AI and LLM use: which data goes to which vendors, which models are approved, how prompts and outputs are handled and logged. Assess risks like prompt injection and data leakage, design controls that let people keep working.
  • Own SOC 2: control design, automated evidence collection, the auditor relationship.
  • Handle regulatory side for our financial-institution customers: GDPR and CCPA for privacy, DORA and EBA outsourcing guidelines in the EU, GLBA and SEC/FINRA expectations in the US.
  • Lead customer security reviews: due diligence questionnaires, RFPs, contract security terms, calls with bank security teams.
  • Run vendor reviews and third-party risk.
  • Secure the human half by building awareness training, phishing resilience, and device and identity hygiene that work for deals and sales people, not only engineers.
  • Over time: set the security strategy, report risk to leadership in business terms, choose tooling, build a budget, hire.

## Requirements

**What we're looking for**

  • 5+ years in security engineering or security-heavy infrastructure work, with depth in AWS security (IAM, SCPs, logging, detection, encryption). Certifications are fine, but shipped work is better.
  • Python and Terraform, or close equivalents. You automate evidence collection instead of maintaining spreadsheets.
  • SOC 2 experience, ideally owning a Type II audit. Working knowledge of privacy legislation.
  • Exposure to financial-services customer scrutiny, or the appetite to make it your specialty.
  • A working view on LLM security risks, or strong fundamentals and the curiosity to build one.
  • Judgment about which risks matter. You can tell an auditor why a control exists and an engineer why it isn't theater.
  • Clear writing. Remote means async, and async means your policies and risk memos do the talking.
  • The ambition to grow into an executive role and the people skills to survive it.

**Nice to have**

  • Fintech or another regulated B2B environment with large financial-institution customers.
  • DORA, EBA/ESMA outsourcing guidelines, or NYDFS 500.
  • Experience securing enterprise integrations: SSO/SCIM, SFTP feeds, APIs.
  • You've been the first security hire somewhere before.

## Benefits

**What we offer**

  • A blank slate with real ownership
  • A committed path to CISO.
  • Fully remote, flexible hours.
  • Direct access to leadership and to customer security teams at major financial institutions.
  • Competitive pay, equity, learning budget.

**How we hire**

1. Intro call (30 min).

2. Technical deep dive (60–90 min): AWS security scenarios, plus a walk-through of a program you built.

3. Practical exercise: review a sanitized architecture or a due diligence questionnaire and tell us what you'd fix first.

4. Leadership conversation: the CISO path, and working with the non-technical half of the company.

5. References and offer.

We're an equal opportunity employer. If you don't tick every box, apply anyway.

Benefits

**What we offer** * A blank slate with real ownership * A committed path to CISO. * Fully remote, flexible hours. * Direct access to leadership and to customer security teams at major financial institutions. * Competitive pay, equity, learning budget.

Similar Jobs

30

Information Security Engineer

Jci · PRT Sao Joao da Madeira, Portugal +3

Yesterday

Information Security Engineer

IEL Careers · Cincinnati, United States of America · Onsite

Yesterday

Information Security Engineer

Default Brand · Neenah, WI

Yesterday

Information Security Engineer

Affinity Plus · St. Paul, MN

4 days ago

Information Security Engineer

Dolby · Atlanta, GA,US, US

5 days ago

Information Security Engineer

Equinix · POL Warsaw, Poland · Hybrid

6 days ago

Information Security Engineer

Appian · McLean, Virginia · Onsite

1 week ago

Information Security Engineer

Keyfactor · USA; Remote (Cleveland or Atlanta preferred) +1 · Remote

1 week ago

Information Security Engineer

Fhlbtopeka · US KS Topeka Main Office, United States of America · Hybrid, Onsite

1 week ago

Information Security Engineer

Scanhealthplan · Long Beach Office 3800, United States of America · Hybrid

2 weeks ago

Information Security Engineer

HSP Group · Spain - Remote · Remote

2 weeks ago

Information Security Engineer

HSP Group · United States - Remote · Remote

2 weeks ago

Information Security Engineer

Amadeus · Makati, Philippines

2 weeks ago

Engineer, Information Security

Lowe's · Lowe's Charlotte Technology Hub 3505, United States of America · Onsite

2 weeks ago

Information Security Engineer

MoonPay · India - Remote · Hybrid, Remote

3 weeks ago

Information Security Engineer

ASRC Federal · Redstone Arsenal, AL, USA

3 weeks ago

Information Security Engineer

Strayer · Campus Surry Hills, Australia · Hybrid

3 weeks ago

Information Security Engineer

Concoracredit · Beaverton, OR, US · Hybrid

3 weeks ago

Information Security Engineer

3655 Freedom Pointe at The Villages · Des Moines, IA, United States, US

4 weeks ago

Information Security Engineer

Hdsupply · GA250 - Atlanta GA, United States of America

1 month ago

Information Security Engineer

Freshfields · London, United Kingdom +1 · Hybrid

1 month ago

Information Security Engineer

Dealertire · OH1 Corporate Office, United States of America +1 · Remote

1 month ago

Information Security Engineer

Farmers and Merchants Bank of Long Beach · Seal Beach, CA

1 month ago

Information Security Engineer

Gulf Coast Automation Group · Chicago

1 month ago

Information Security Engineer

Algolia · Remote - United Kingdom +1 · Remote

1 month ago

Information Security Engineer

Babel Street · Reston, Virginia, United States · Hybrid

1 month ago

Information Security Engineer

Default · Herndon, VA +1

1 month ago

Information Security Engineer

Default · Herndon, VA

1 month ago

Information Security Engineer

CAREER OPPORTUNITIES · Laramie Building, United States of America · Remote, Hybrid, Onsite

1 month ago

Information Security Engineer

Intel · USA - CA - Folsom, United States of America +1

1 month ago
Remote Information Security Engineer (CISO track) at Tangible Marketscom | Hiring.Camp