Staff/Principal Security Engineer
Indexed description
Oscar Faye is partnering with a multi-billion-dollar alternative assets and digital finance group in Manhattan to make the founding technical hire of a new Cloud Security function. The first dedicated security engineering seat inside the firm's central platform team — you set the direction of the function, with a second hire to follow behind you
What you will own:
- CI/CD and software supply chain security: pipeline hardening (GitHub Actions, ArgoCD), SLSA, sigstore/cosign, SBOM, artifact signing
- AWS organization security: SCP design, IAM and workload identity, KMS, secrets management (Vault or similar), secure-by-default Terraform
- Kubernetes (EKS) security: admission control (OPA/Gatekeeper, Kyverno), runtime security, workload identity
- The security posture of an emerging AI platform — model access boundaries, agent security, AI supply chain
- A firm-wide security remediation program, driven with tooling engineers actually adopt
What it takes — please read before applying:
- 10+ years of hands-on engineering, 5+ security-focused. The bar is senior: this seat sets direction.
- A track record of building security tooling or platforms that engineering teams adopted. Configuring vendor products, running scanners, or writing policy does not qualify.
- Production Kubernetes security experience. This is a hard requirement.
- Strong Python or Go — you build tooling yourself.
- Long tenure in regulated industries (financial services strongly preferred) and a genuine point of view on AI in security engineering. The team works AI-first.
- Candidates with start up experience preferred
- Relocation not permitted. This requires someone already based in a commutable area of Manhattan.
The role is on-site in Manhattan, five days a week.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search