Lead the cloud security initiatives at TRM Labs to enhance security for financial systems globally.
Posted by employer 3 days ago
First seen on Joblaze 1 day ago
Last verified on the company career page 1 day ago
Skills & Technologies
What you'll build
Must have
Not disclosed in this posting: compensation, years of experience, visa sponsorship.
Joblaze summary
In the role of Senior Cloud Security Engineer at TRM Labs, the individual will focus on enhancing the security of the company's cloud infrastructure and systems, ensuring robust protection against vulnerabilities. Key skills include expertise in cloud security, particularly with Google Cloud Platform, and proficiency in automation tools and infrastructure-as-code solutions. This position is suited for experienced professionals with a strong background in managing cloud security programs and a proactive approach to risk assessment. The security team emphasizes collaboration and transparency, fostering an environment where innovative solutions to complex security challenges are prioritized.
Joblaze insights
Quick facts
From the original posting
About the Team
The Security team is responsible for and committed to securing all things at TRM. From our customers to our code, and everything in between, the security team is involved in all aspects of the business. As a Senior Cloud Security Engineer, you will lead the charter for maturing TRM’s cloud infrastructure and security systems at scale. From designing the strategy to implementing best practices, your work will accelerate our mission of building a safer financial system for billions of people.
The impact you will have here:
Provide technical guidance and leadership as a cybersecurity expert on topics such as architecture, configuration management, and environment design
Leverage automation tools, configuration management, and infrastructure-as-code (IaC) solutions to standardize security across all environments
Guide relevant stakeholders such as engineering, product, and leadership and ensure alignment with security strategies
Identify and communicate cloud platform vulnerabilities and mitigation options to stakeholders that balance business agility with security
Serves as a Cloud Security Subject Matter Expert (SME) by maintaining knowledge of industry-recognized cloud security technologies and concepts; actively engages and assists lines of business to understand their needs and develop secure business solutions
Drive security improvements in the GCP environment and perform Identity and Access Management (IAM) in GCP to ensure that principles of least privilege and roles-based access control are maintained
Participate in audits of the cloud environment by working with external auditors and internal resources to ensure we are meeting expectations
What we’re looking for:
Relevant industry experience in managing cloud security programs, Identity Access Management (IAM), and cloud-native security solutions (e.g., firewalls)
Expert-level knowledge of cloud infrastructure components, preferably with GCP
Strong bias for action; ability to juggle multiple priorities and create a sense of urgency in a fast-paced, dynamic environment.
Ability to audit and provide audit support for security controls within the cloud environment
Experience with infrastructure vulnerability testing tools, Cloud Application Platforms (Heroku), and Infrastructure as code tools (Terraform)
About the Team:
The culture of our team is built on mutual respect, where everyone's opinion is valued and heard.
We prioritize flexibility and efficiency, always seeking smarter ways to work without compromising quality.
Transparency is at the heart of how we operate, both within the team and with the business, as we focus on clearly communicating and addressing cyber risks.
Our collaborative approach ensures that we not only mitigate these risks but also align our efforts with business goals to protect and drive success.
Team’s Time Zones:
Eastern Standard Time (EST - GMT-4)
Pacific Standard Time (PST - GMT-7)
Central European Summer Time (CET - GMT+2)
Learn about TRM Speed in this position:
Prioritize Rapid Threat Assessments: Efficiently perform security risk assessments and triage vulnerabilities based on immediate risk to the business, focusing on the most critical issues with minimal delays.
Integrate Security Early in Development: Embed security testing and reviews within our Product Shipping Framework and CI/CD pipelines to ensure that security is automated and runs parallel to the fast-paced development cycle, preventing bottlenecks.
Proactively Educate Developers: Conduct just-in-time security training for developers and engineers, offering real-time advice and code reviews to help them produce secure code without interrupting their workflow.
Optimize Tools for Speed: Leverage lightweight and efficient security tools that can be quickly integrated into development environments without slowing down deployments, ensuring continuous and secure product iterations.
Recruiter Intro: Explore your experience, motivations, and alignment with the role.
Learn more about interviewing at TRM
At TRM, you should expect:
Priorities and targets to change quickly as we experiment and iterate
Close collaboration across teams and functions
Frequent, high-touch communication
Creative problem solving and out-of-the-box thinking
Accelerate repeatable workflows
Structure and solve problems
Improve output quality
Increase speed and leverage
Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly.
Standard company text repeated across TRM Labs's postings is omitted here.