Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Engineer (remote) image - Rise Careers
Job details

Security Engineer (remote)

Introducing Masabi 

// At Masabi, we’re driving the fare payment revolution, powering the journeys of millions all over the world. We build fare collection platforms that allow riders to seamlessly buy and present tickets for public transport either on their mobile phones, from a ticket machine, or even by tapping their bank card to travel. 

Our Justride platform is used in over 250 locations globally, including some of the largest cities in the world. With our industry-first mobile ticketing SDK, we’ve partnered with large players in the transport space, including Uber, Moovit and Transit. 

Your own journey is important to us too. Choosing a role here means joining a network of innovators from all walks of life; a group of passionate individuals who consistently deliver. Here, you’ll find the tools you need to build the career you want. Whether you’re taking the direct route or trying a new path, we’ll support you no matter what. 

The Role
As we continue to grow, ensuring the security and integrity of our platform is more important than ever. We’re looking for a Security Engineer to help shape the future of security at Masabi, someone who’s excited to build robust controls, reduce risk, and support our global compliance journey.

You’ll work closely with teams across the business to maintain and improve our compliance posture (PCI DSS, ISO27001, SOC2), drive vulnerability management and security tooling, and support audits and client commitments. This is a highly collaborative role that blends technical insight with process improvement, ideal for someone who’s curious, empathetic, detail-oriented, and ready to make a positive impact.

You’ll report directly to the Senior Director of Corporate IT, Compliance, and Customer Success.


Responsibilities
Compliance & Security Controls

  • Own and improve security controls aligned with PCI DSS, SOC 2, and ISO 27001, supporting audits and recertifications

  • Ensure we stay audit-ready with control testing, documentation, and remediation

  • Partner with internal teams and auditors to manage evidence collection and compliance outcomes

  • Manage and track contractual security obligations, flagging any billable work


Risk Management & Policy

  • Lead risk assessments, identify control gaps, and recommend mitigation strategies

  • Manage the lifecycle of security policies and standards, making sure they’re practical, up-to-date, and embedded across teams

  • Stay ahead of regulatory changes and industry trends to proactively adjust our security approach

Vulnerability Management

  • Own our vulnerability scanning and triage process, prioritising risks and working with teams to close gaps within SLAs

  • Coordinate and follow up on bi-annual penetration tests

  • Monitor CVEs and evaluate impact across cloud infrastructure and code dependencies

  • Oversee patching compliance and ensure SSL certificates are up-to-date

  • Automate scanning, reporting, and risk scoring wherever possible


Incident Response & Continuous Improvement

  • Own the lifecycle of security incidents, from detection and response to lessons learned

  • Maintain up-to-date incident response plans aligned with compliance standards

  • Implement and optimise tools to detect, prevent, and mitigate potential threats

  • Lead regular security reviews across cloud environments and code repositories

  • Track key risk indicators (KRIs) and report on security metrics to leadership

  • Support the completion of RFPs and customer security questionnaires

About You

  • Hands-on experience in security engineering, compliance, or risk management

  • Comfortable working with PCI DSS, ISO 27001, SOC 2 and security audits

  • Solid understanding of vulnerability scanning, pen testing, and cloud environments

  • Familiar with risk assessments, mitigation strategies, and patching workflows

  • Able to write clear documentation, reports, and policies

  • Collaborate, curious, proactive, and always looking for ways to improve

  • Comfortable working independently in a remote-first environment

Some of our benefits

  • 25 days holiday per year plus the Christmas Shutdown (another 3-4 days)

  • Premium medical care via Regina Maria

  • Mental health support

  • Menopause support

  • Regular social gatherings with a monthly allowance for each employee

  • Up to €1000 training budget per year

  • €200 to spend on your home office

  • Choice of workstation

  • Ability to work for up to 3 months per year from any country in the world

Careers at Masabi are for people going places - driven by a mission to make transit fair and accessible for all.

We are a network of innovators from all walks of life, passionate about making a difference. At Masabi, we operate with openness and trust, creating an environment where everyone feels empowered to bring their whole, authentic selves to work.

Whoever you are, just be yourself.
We welcome applications from underrepresented backgrounds and encourage you to share your pronouns at any stage. Together, we simplify journeys, remove barriers, and improve daily life for millions.

Why Join Masabi?

  • Driven by Purpose – We believe in journeys made simple. The work isn’t always easy, but the best things never are.

  • Encouraged to Accelerate – Masabi is going places and our people are in the driving seat. Whether you’re taking the direct route or exploring new paths, we support your journey.

  • Advancing with Empathy – We put people first and foster a culture of learning, not blame. No matter your cargo, we share the load.

We’re already powering journeys - are you ready to join us?

Masabi Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Masabi DE&I Review
4.5 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Masabi
Masabi CEO photo
Brian Zanghi
Approve of CEO

Average salary estimate

$70000 / YEARLY (est.)
min
max
$60000K
$80000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Engineer (remote), Masabi

At Masabi, we're excited to invite a passionate Security Engineer to join our innovative team in Bucharest! As a key player in the fare payment revolution, you'll help ensure the security and integrity of our cutting-edge Justride platform, which is used across the globe. Your role will be crucial in maintaining compliance with standards like PCI DSS, ISO 27001, and SOC 2. You’ll have the opportunity to shape security controls, manage vulnerability assessment processes, and lead incident response initiatives. Working closely with various teams, you will not only tackle current security challenges but also proactively adapt to industry changes. We value curiosity, collaboration, and a desire for continuous improvement, and here, we’ll support your growth, whether you choose to take the straightforward path or explore new opportunities. With benefits like a generous holiday allowance, premium medical care, and a commitment to mental health support, we are dedicated to empowering you in your career journey while keeping our focus high on securing transit experiences for millions. If you’re detail-oriented and ready to make a positive impact, we’d love to see how you can contribute to our mission at Masabi!

Frequently Asked Questions (FAQs) for Security Engineer (remote) Role at Masabi
What are the main responsibilities of a Security Engineer at Masabi?

As a Security Engineer at Masabi, your key responsibilities will include enhancing security controls compliant with PCI DSS, ISO 27001, and SOC 2, managing audits and evidence collection, leading risk assessments, and conducting vulnerability management. You'll also be responsible for incident response, maintaining documentation, and continually improving our security posture.

Join Rise to see the full answer
What qualifications are needed to apply for the Security Engineer position at Masabi?

To succeed as a Security Engineer at Masabi, candidates typically need hands-on experience in security engineering or compliance management. A solid understanding of vulnerability scanning, pen testing, and familiarity with security audits such as PCI DSS, ISO 27001, and SOC 2 are essential. Excellent documentation skills and a collaborative mindset are also important to thrive in this role.

Join Rise to see the full answer
How does Masabi support the continuous growth of the Security Engineer?

Masabi is dedicated to the continuous growth of its Security Engineers by offering a generous training budget of up to €1000 per year, mentorship from experienced team members, and a culture that encourages learning and self-improvement. This allows you to stay at the forefront of security knowledge and techniques.

Join Rise to see the full answer
What tools do Security Engineers at Masabi use to manage security incidents?

Security Engineers at Masabi leverage a range of advanced tools for managing security incidents, including automated scanning solutions, vulnerability management platforms, and incident response tools. These enable the team to preemptively detect threats, swiftly respond to incidents, and continually improve security strategies.

Join Rise to see the full answer
What is the remote work policy for Security Engineers at Masabi?

Masabi fosters a flexible remote work policy, allowing Security Engineers to work from anywhere in the world for up to three months a year. This flexibility supports a healthy work-life balance, enabling you to manage your work alongside personal commitments while being part of a dynamic team.

Join Rise to see the full answer
Common Interview Questions for Security Engineer (remote)
How do you approach compliance audits in your role as a Security Engineer?

In interviews, emphasize your methodical approach to compliance audits, including preparing documentation, conducting control testing, and collaborating with internal teams. Highlight your experience in managing evidence collection and explain how you ensure the organization meets compliance standards.

Join Rise to see the full answer
Can you describe a time when you identified and resolved a security vulnerability?

Provide a specific example where you discovered a vulnerability in a system, your analysis process, and the steps taken to mitigate the risk. Stress teamwork, documenting the incident, and the impact of your resolution on the overall security posture.

Join Rise to see the full answer
What strategies do you implement for vulnerability management?

Discuss your strategies for prioritizing vulnerabilities based on severity, employing tools for continuous monitoring, and aligning with development teams to resolve issues within set SLAs. Mention how data-driven decision-making enhances the effectiveness of your vulnerability management approach.

Join Rise to see the full answer
How do you stay current with cybersecurity trends and compliance requirements?

Mention your proactive methods of keeping up-to-date, such as following industry publications, participating in webinars, attending conferences, and being a member of professional associations. Describe how this knowledge informs your daily work and strategic decisions.

Join Rise to see the full answer
Describe your experience with PCI DSS compliance.

Detail your familiarity with the PCI DSS framework, highlighting your experience in implementing necessary controls, conducting risk assessments, and preparing for audits. Discuss any challenges faced and how you overcame them to achieve compliance.

Join Rise to see the full answer
What role does communication play in your work as a Security Engineer?

Explain the importance of communication in your role, particularly in collaborating with other teams during security initiatives, conducting training sessions, and reporting security metrics to leadership. Emphasize how clear communication fosters teamwork and strengthens security posture.

Join Rise to see the full answer
How would you handle a major security incident?

Outline your response process, including initial detection, rapid assessment, and remediation steps. Emphasize the importance of lessons learned through post-incident reviews and how this process contributes to improving security measures and policies.

Join Rise to see the full answer
What experience do you have with automation in security processes?

Discuss your experience implementing automation in vulnerability scanning, reporting, or incident response. Highlight how automation enhances efficiency, accuracy, and allows for a proactive approach to managing security threats.

Join Rise to see the full answer
How do you prioritize security policies within an organization?

Share your method for assessing risk and understanding business needs when prioritizing security policies. Mention consulting with stakeholders to ensure policies are practical and effective, reflecting the organization's operational reality.

Join Rise to see the full answer
What recent security challenge have you encountered and what did you learn from it?

Describe a specific challenge related to security compliance or incidents, explaining your approach to resolving it. Emphasize what you learned from the experience and how it has shaped your approach to future security challenges, highlighting your adaptability.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted yesterday
Dental Insurance
Vision Insurance
Performance Bonus

Lead a passionate design team at Masabi, innovating the future of urban mobility through exceptional user experience design.

Photo of the Rise User
Posted 2 days ago
Dental Insurance
Vision Insurance
Performance Bonus

Join Masabi as a Product Manager to lead the digital experiences of millions of transit users worldwide.

Photo of the Rise User
Multi Media LLC Remote No location specified
Posted 10 days ago

Join Multi Media, LLC as a Security Engineer and play a key role in enhancing their security detection and response capabilities.

Posted 12 days ago

Indiana Wesleyan University is on the lookout for an inspiring VP and CIO to advance their mission through innovative technology leadership.

Photo of the Rise User

Join Compass as a Senior Manager in Incident Response & Forensics, leading vital security practices in a groundbreaking real estate firm.

Posted 13 days ago

As a ServiceNow Integration Developer, you'll leverage your tech expertise to create seamless integrations and enhance system performance.

Photo of the Rise User
ASUCLA Remote US, Los Angeles County, CA; California, Los Angeles, CA
Posted 9 days ago

Join Associated Students UCLA as a NetSuite Administrator/Developer and play a key role in managing their NetSuite ERP and driving innovative solutions.

Photo of the Rise User
Posted 7 days ago

ICF is looking for a Senior Systems Administrator with top-secret clearance to tackle critical IT challenges within an Agile framework.

Photo of the Rise User
Posted 3 hours ago

Join Owner.com as a Senior Site Reliability Engineer to drive our mission of empowering restaurants with robust technology solutions.

Photo of the Rise User
Inclusive & Diverse
Collaboration over Competition
Fast-Paced
Growth & Learning
Empathetic

Join Deel as a Payment Integration Specialist, where you will enhance global payroll operations by integrating diverse payment file formats.

MATCH
Calculating your matching score...
BENEFITS & PERKS
Dental Insurance
Vision Insurance
Performance Bonus
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 5, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!