CF CloudFrame Job Scanner Open Dashboard →
Verified Active Opening

Senior Cloud Security Engineer

Alloy • New York City

Job Description

<h2>Alloy is where you belong!</h2> <p>Alloy is the AI-powered identity and fraud prevention platform that accelerates onboarding, stops fraud, and scales compliance across the customer lifecycle so financial organizations can grow without limits. More than 900 of the world's leading financial institutions and fintechs trust Alloy for smarter risk management that drives growth.<br><br>Through our values: Be Bold, Go Fast, Collaborate, and Celebrate Our Differences, we are creating a workplace where you can grow, thrive, and belong. See how we’ve been continuously recognized and named one of <a href="https://www.inc.com/profile/alloy_ny" target="_blank">Inc. Magazine’s Best Workplaces</a>, <a href="https://www.forbes.com/companies/alloy/?list=americas-best-startup-employers&sh=55c076453c61" target="_blank">Forbes America’s Best Startup Employers</a>, <a href="https://www.americanbanker.com/list/best-places-to-work-in-fintech-2022" target="_blank">Best Fintech to Work for by American Banker</a>, year after year.<br><br>Check out our investors and read more about us <a href="https://www.alloy.com/about" target="_blank">here</a>.</p> <h2>About the team</h2> <p>Product Security covers application security and cloud security at Alloy. Our customers are banks and fintechs, so the state of our security program is not an internal matter. It shows up in client due diligence, in what we can sell, and in whether deals close. The team is small and the program is still being matured, which means the person in this seat shapes how engineering across the company designs and ships infrastructure rather than inheriting someone else's finished playbook.</p> <p>Alloy operates in a hybrid-work environment. We look to foster collaboration and community by having our local employees onsite three days a week.</p> <p></p> <h2><strong>What you'll be doing</strong></h2> <p>You'll own the security of Alloy's AWS environment and the tooling that keeps it visible. You will work closest with the Infrastructure team, but your reach will extend to every engineering team.</p> <ul> <li>Partner with the Infrastructure team to build security into new cloud infrastructure as it is designed, and act as the security point of contact for new builds</li> <li>Lead initiatives you scope yourself to reduce cloud infrastructure risk in ways that are repeatable and maintainable</li> <li>Build alerts, detections, and dashboards in our CSPM and SIEM, and write the runbooks that make them actionable for the people who get paged</li> <li>Own CSPM findings end to end, from triage through remediation, including the Terraform changes that fix the problem at its source</li> <li>Drive AWS permissions and network design toward least privilege, and debug both without widening the attack surface in the process</li> <li>Join the on-call rotation, investigate security incidents to root cause, and put controls in place so the same incident does not recur</li> </ul> <p></p> <h2><strong>Who we’re looking for</strong></h2> <p>Must-haves:</p> <ul> <li>3+ years in cloud security, or in cloud infrastructure with a security focus, primarily in AWS</li> <li>Hands-on with AWS networking and security services: VPC design, security groups, NACLs, WAF, GuardDuty, Config, Inspector, KMS, and IAM</li> <li>Provisioning infrastructure as code with Terraform and working knowledge of Kubernetes or EKS</li> <li>Working experience with a SIEM and a CSPM, including tuning alerts and building detections that engineers act on</li> <li>Scripting or programming in Python or TypeScript, with an eye for where the code itself creates risk</li&

Job Reference ID: CF-148236 • Posted on CloudFrame Job Scanner