Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Security Engineer – Cloud & DevSecOps - Santiago image - Rise Careers
Job details

Senior Security Engineer – Cloud & DevSecOps - Santiago

The Company: 


Capital Markets Gateway (CMG) is a financial technology firm that is modernizing the equity capital markets (ECM).CMG connects investors and underwriters via a neutral platform that delivers integrated ECM data and analytics, transparency, and workflow efficiencies. Providing a digital system of record for firm-wide deal activity, CMG helps clients make more timely, better-informed decisions.


Launched in 2017 by a team of ECM practitioners, the CMG platform is currently relied upon by nearly 100 buy side firms representing $20 trillion in AUM and 15 investment banks. CMG’s goal is to alleviate pain points resulting from disparate solutions, fragmented data, and frenzied communication. CMG’s DataLab product solves for data analytics, while CMG’s XC platform establishes connectivity between buy- and sell-side firms.


Position Overview:

 

CMG is seeking a proactive and highly skilled Senior Security Engineer focused on Cloud & DevSecOps to drive and elevate the security posture across our cloud infrastructure, applications, and DevOps practices. This role merges the responsibilities of securing cloud environments and integrating security into development pipelines, ensuring the safety of both infrastructure and application code. The successful candidate will collaborate closely with various teams, including Security, DevOps, and Engineering, to identify risks, implement security controls, and continuously improve security processes. This is a hands-on role focused on cloud security architecture, application security, and security automation.


Key Responsibilities:


Cloud & Infrastructure Security
  • Design, implement, and evolve cloud security architecture strategies and frameworks across multi-cloud platforms (i.e., Azure and either AWS/GCP).
  • Conduct risk assessments and secure cloud environments using Infrastructure as Code (IaC) tools like Terraform, ensuring compliance with security standards and policies.
  • Partner with DevOps on cloud security initiatives, including network security, data protection, secure configurations, and encryption.
  • Ensure cloud-native services are secured, such as identity management, storage, and compute resources, while ensuring adherence to regulatory and industry standards.


Application Security & DevSecOps
  • Integrate security best practices into the Software Development Life Cycle (SDLC), focusing on secure coding, dependency management, and continuous vulnerability scanning for languages such as .NET, JavaScript, and Python.
  • Collaborate with development teams to establish security standards and enforce secure coding practices.
  • Implement and maintain API security standards, including authentication, encryption, and secrets management.
  • Ensure containerized applications are secured deployed via Kubernetes, managing both image security and runtime security risks.
  • Perform threat modeling and risk assessments for both new and existing applications.
  • Implement and maintain any required security audit trails and/or integrations into security monitoring apparatus


Security Automation & Compliance
  • Develop policy-as-code frameworks and automate security testing in CI/CD pipelines using tools like GitHub Actions, ensuring security is continuously enforced during deployments.
  • Monitor, assess, and mitigate vulnerabilities in cloud infrastructure, application environments, and containers through regular scans and risk assessments.
  • Drive the adoption of security automation tools to streamline secure deployments, enforce security policies, and manage cloud configurations.
  • Support security compliance initiatives, including SOC2, ensuring cloud infrastructure and applications meet regulatory standards.


Security Governance & Leadership
  • Mentor engineers and cross-functional teams, advocating for security best practices across cloud, infrastructure, and applications.
  • Serve as the subject matter expert in security architecture areas such as identity management, encryption, data loss prevention (DLP), and cloud service security.
  • Develop and maintain security documentation, policies, and procedures for cloud, application, and DevOps environments.
  • Stay informed on emerging threats and security technologies, driving continuous improvement and innovation in cloud and application security.


Required Qualifications
  • 7+ years of hands-on experience in information security, with a strong focus on cloud and application security.
  • 4+ years of experience securing cloud platforms (Azure preferred, AWS, GCP), including deep expertise with cloud-native security tools and Infrastructure as Code (Terraform).
  • Proven track record securing application environments and integrating security into DevOps practices.
  • Strong understanding of API security, encryption, and secrets management in distributed cloud environments.
  • Hands-on experience with automation tools like Terraform and Ansible, and security-focused CI/CD pipelines.
  • Expertise in securing containerized environments (Docker, Kubernetes) and addressing vulnerabilities in container images and dependencies.
  • Strong knowledge of cryptography, key management, and data protection best practices.


Key Technologies
  • CloudPlatforms: Azure (preferred), GCP, AWS
  • Infrastructure-as-Code (IaC): Terraform
  • Languages: .NET, JavaScript, Python, Bash, Powershell
  • Containers: Docker, Kubernetes
  • CI/CD Tools: GitHub
  • Database: PostgreSQL
  • Secrets Management: Key Vault
  • Operating Systems: Linux, Windows, MacOS


Desired Qualities
  • Strong ownership and initiative, with the ability to work independently in a fast-paced environment.
  • Excellent multitasking and prioritization skills, capable of handling complex, concurrent tasks.
  • Passion for security innovation, staying ahead of emerging threats, and continuously improving security processes.
  • Detail-oriented, ensuring thorough tracking of issues and resolutions.


Our values
  • We innovate with purpose 
  • We focus on outcomes vs. output 
  • We believe diverse and inclusive teams fuel innovation 
  • We are humble yet candid 
  • We do right by the customer 


What we offer
  • 15 days of vacation
  • Gym membership contribution
  • Language courses
  • Tech courses and conferences
  • Top-of-the-line MacBook
  • Potential trips to the USA
  • Company team-building events
  • Flexible working hours and the possibility to work from home


We celebrate diversity and are committed to creating an inclusive work environment. CMG is an equal-opportunity employer.  

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Security Engineer – Cloud & DevSecOps - Santiago, Capital Markets Gateway

Join Capital Markets Gateway (CMG) as a Senior Security Engineer focused on Cloud & DevSecOps in the vibrant city of Santiago! At CMG, we're transforming the equity capital markets by providing a streamlined platform that enhances clarity and efficiency for investors and underwriters alike. As our Senior Security Engineer, you'll play a pivotal role in bolstering our security architecture across cloud environments and development practices. This exciting position isn’t just about locking things down; it’s about building and integrating top-tier security measures into every step of our processes using cutting-edge tools like Terraform and Kubernetes. Collaborating with talented teams across Security, DevOps, and Engineering, you'll design robust security frameworks, conduct thorough risk assessments, and ensure our cloud systems are fortified against any threats. We value innovation and continuous improvement, so your hands-on expertise in securing cloud platforms such as Azure and the use of Infrastructure as Code will help shape a resilient environment. You'll also dive into application security, refining our coding practices and securing our APIs. If you’re passionate about mentoring others and driving security best practices, this role offers you the chance to lead initiatives and craft comprehensive security documentation. By joining CMG, you’ll be part of a mission-driven environment that prioritizes diversity, innovation, and collaboration, and you'll enjoy a range of benefits including flexible work hours and professional development opportunities. Ready to elevate your career with us? Let’s make waves in the fintech world together!

Frequently Asked Questions (FAQs) for Senior Security Engineer – Cloud & DevSecOps - Santiago Role at Capital Markets Gateway
What qualifications do I need for the Senior Security Engineer position at Capital Markets Gateway?

To qualify for the Senior Security Engineer position at Capital Markets Gateway, you should have 7+ years of experience in information security with a significant focus on cloud and application security. This includes at least 4 years of experience securing cloud platforms, especially Azure, and expertise in Infrastructure as Code tools like Terraform. Your background should demonstrate a proven track record in securing applications and integrating security into DevOps practices.

Join Rise to see the full answer
What are the key responsibilities of a Senior Security Engineer at Capital Markets Gateway?

As a Senior Security Engineer at Capital Markets Gateway, your primary responsibilities will include designing and implementing cloud security architectures, conducting risk assessments, ensuring compliance with security standards, and integrating security best practices into the Software Development Life Cycle (SDLC). You'll also be responsible for API security, security automation, and mentoring cross-functional teams while maintaining thorough security documentation.

Join Rise to see the full answer
What tools and technologies should I be familiar with for the Senior Security Engineer role at Capital Markets Gateway?

For the Senior Security Engineer role at Capital Markets Gateway, familiarity with cloud platforms like Azure and AWS is essential. You should also have hands-on experience with Infrastructure as Code tools (particularly Terraform), containerization tools such as Docker and Kubernetes, and CI/CD practices using tools like GitHub Actions. Knowledge of secure coding practices in languages like .NET, JavaScript, and Python is also important.

Join Rise to see the full answer
How does the Senior Security Engineer role contribute to security governance at Capital Markets Gateway?

The Senior Security Engineer role at Capital Markets Gateway is crucial for security governance as it involves establishing security standards, mentoring team members, and developing security policies and procedures. As a subject matter expert, you’ll monitor emerging threats and ensure that our security practices align with regulatory requirements, driving a culture of security awareness across the organization.

Join Rise to see the full answer
What kind of professional development opportunities does Capital Markets Gateway offer for a Senior Security Engineer?

Capital Markets Gateway offers various professional development opportunities for Senior Security Engineers, including tech courses and conferences, language courses, and participation in team-building events. We believe in fostering growth and innovation, providing a flexible work environment that encourages continuous learning and skill enhancement.

Join Rise to see the full answer
Common Interview Questions for Senior Security Engineer – Cloud & DevSecOps - Santiago
Can you describe your experience with securing cloud environments?

In response to this question, share specific examples of cloud projects you've managed, focusing on the tools and strategies you implemented to enhance security. Discuss your familiarity with platforms like Azure or AWS and detail how you utilized Infrastructure as Code tools to automate security measures.

Join Rise to see the full answer
How do you integrate security best practices into the Software Development Life Cycle?

When addressing this question, mention your approach to incorporating security during each phase of the SDLC, including requirements gathering and design. Provide examples of how you trained development teams in secure coding practices and the tools you utilized for continuous vulnerability scanning.

Join Rise to see the full answer
What methods do you use for threat modeling in applications?

Discuss the threat modeling techniques you've used, such as STRIDE or DREAD, and provide insights into how you assess potential threats. Offer examples of risk assessments you've conducted on both new and existing applications to highlight your proactive approach.

Join Rise to see the full answer
Can you explain your experience with automation in security testing?

Here, you’ll want to elaborate on how you've used automation tools in CI/CD pipelines for security testing. Describe specific tools such as GitHub Actions or other automation frameworks, and share how these tools have impacted your deployment processes.

Join Rise to see the full answer
What do you consider the most critical aspect of API security?

In your response, you should emphasize the importance of authentication and authorization mechanisms in API security. Discuss best practices such as using OAuth tokens, implementing rate limiting, and maintaining secure communication protocols to protect sensitive data.

Join Rise to see the full answer
How do you stay updated with emerging security threats?

Talk about the resources you utilize to stay informed, including security blogs, webinars, and professional networks. Mention your engagement with industry groups or attendance at conferences to continuously enhance your understanding of evolving threats and security technologies.

Join Rise to see the full answer
Describe a challenging security problem you faced and how you solved it.

Here, share a specific story of a security challenge you encountered, including the context, the steps you took to analyze the issue, and the final solution. Highlight your problem-solving skills and the collaboration involved with your team.

Join Rise to see the full answer
What strategies do you utilize for mentoring junior engineers in security best practices?

Discuss your approach to mentoring, such as conducting workshops, providing one-on-one guidance, or creating resources for junior engineers. Emphasize your belief in a collaborative environment and how you encourage open discussions around security concerns.

Join Rise to see the full answer
How would you handle a security breach if it occurred?

Outline your incident response plan, emphasizing the steps you would take to assess the breach, contain it, and conduct a post-incident review. Discuss the importance of communication with stakeholders and the need for continuous improvement following an incident.

Join Rise to see the full answer
What tools do you find most effective for managing cloud security?

In your answer, mention specific tools you’ve used for managing cloud security, such as cloud security posture management (CSPM) tools or identity and access management (IAM) solutions. Explain how these tools have helped you maintain compliance and security across cloud platforms.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
Insight Global Hybrid Strathmoor Manor, KY
Posted 7 days ago
Photo of the Rise User
Posted 9 days ago
Posted 7 hours ago
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Posted 14 days ago
Photo of the Rise User
Posted 2 days ago
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
LOCATION
No info
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 17, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!