Senior Security Engineer
Job description
About the role
As a , you will play a role in safeguarding our digital infrastructure and ensuring the security of our financial technology solutions. You will be responsible for designing, implementing, and maintaining security measures that protect sensitive data and systems from potential threats. This position requires a deep understanding of security protocols, risk assessment, and incident response, as well as the ability to collaborate with cross-functional teams to enhance our security posture. Your expertise will contribute to fostering a culture of security awareness and compliance within the organization.
Key facts
What you'll do
- Develop and implement security policies, procedures, and standards to protect Fispan's assets and data.
- Conduct thorough security assessments and audits to identify vulnerabilities and recommend appropriate remediation strategies.
- Collaborate with software development teams to integrate security best practices into the software development lifecycle.
- Monitor security incidents and respond to breaches or threats in a timely manner, ensuring minimal impact on operations.
- Design and maintain security architecture, including firewalls, intrusion detection systems, and encryption protocols.
- Lead incident response efforts, including forensic analysis, to investigate security breaches and mitigate future risks.
- Stay up-to-date with the latest security trends, threats, and technologies to proactively enhance Fispan's security measures.
- Provide training and guidance to employees on security awareness and best practices to foster a security-conscious culture.
- Work closely with compliance teams to ensure adherence to relevant regulations and standards, such as PCI DSS and GDPR.
- Participate in the development and execution of disaster recovery and business continuity plans.
- Collaborate with external security vendors and partners to enhance security capabilities and threat intelligence.
- Prepare detailed reports and presentations for management regarding security status, incidents, and improvement recommendations.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A minimum of 5 years of experience in information security, with a focus on security engineering and architecture.
- Strong knowledge of security frameworks and standards, such as NIST, ISO 27001, and CIS Controls.
- Proficiency in security tools and technologies, including SIEM, firewalls, IDS/IPS, and vulnerability management solutions.
- Experience with cloud security, particularly in environments such as AWS, Azure, or Google Cloud Platform.
- Familiarity with programming and scripting languages, such as Python, Java, or Bash, to automate security tasks.
- Excellent analytical and problem-solving skills, with the ability to think critically under pressure.
- Strong communication skills, both verbal and written, to effectively convey security concepts to technical and non-technical audiences.
- Proven ability to work independently and collaboratively in a fast-paced environment.
Nice to have
- Relevant security certifications, such as CISSP, CISM, or CEH, are highly desirable.
- Experience with DevSecOps practices and tools to integrate security into CI/CD pipelines.
- Knowledge of threat modeling and risk assessment methodologies.
- Familiarity with data protection regulations and compliance requirements specific to the financial industry.
- Experience in security incident response planning and execution.
- Understanding of emerging technologies, such as blockchain and machine learning, and their security implications.
Skills & tools
- Security Information and Event Management (SIEM) tools
- Intrusion Detection and Prevention Systems (IDPS)
- Firewalls and VPN technologies
- Vulnerability assessment and penetration testing tools
- Cloud security solutions (AWS, Azure, GCP)
- Incident response and forensic analysis tools
- Programming and scripting languages (Python, Java, Bash)
- Risk management frameworks and compliance standards
Practical notes
- This role is based in Vancouver, British Columbia, and requires the ability to work on-site as well as remotely as needed.
- Candidates must be eligible to work in Canada and may require visa sponsorship.
- The position may involve occasional on-call duties to respond to security incidents outside of regular working hours.
- Fispan is committed to fostering a diverse and inclusive workplace, and we encourage applications from individuals of all backgrounds.
Join Fispan as a Senior Security Engineer and contribute to the security of innovative financial solutions in a dynamic and collaborative environment. If you are about cybersecurity and eager to make a significant impact, we invite you to apply through our career portal.