Career Opportunities
Senior Cybersecurity Engineer
What you will do:Compliance and Regulatory Programs:-
• Own the operational execution of FGI Tech's NYDFS Cybersecurity Regulation 500 compliance program, including policy documentation, annual risk assessments, and regulatory filings.
• Maintain and continuously improve FGI Tech's ISO 27001 compliance posture; support audit preparation and evidence collection.
• Respond to client and prospect security questionnaires, due diligence requests, and information security reviews in support of the sales and CS teams.
• Maintain security policy documentation, control libraries, and audit evidence in an organized, audit-ready state at all times.
Vulnerability Management and Penetration Testing:-
• Conduct ongoing vulnerability assessments across the TRUST platform, cloud infrastructure, and internal systems; prioritize and track remediation.
• Coordinate external penetration testing engagements, manage vendor relationships, and translate findings into actionable remediation plans.
• Monitor threat intelligence feeds and apply findings to the TRUST environment; communicate relevant risks to engineering leadership. Security Operations and Incident Response• Manage security monitoring and visibility across the environment using Vanta, AWS services (GuardDuty, Security Hub, CloudTrail) and existing tooling: tune alerting, analyze logs, investigate anomalies, and maintain operational visibility across the environment.
• Implement a future SIEM capability
• Develop and maintain incident response runbooks; lead tabletop exercises and manage security incidents from detection through resolution and post-mortem.
• Design, implement, and monitor security controls across application, network, and cloud layers (AWS).
• Manage identity and access management (IAM) controls, including privileged access, MFA enforcement, and third-party vendor access policies. Secure Development and Engineering Partnership
• Partner with engineering leadership to embed security into the SDLC -- code reviews, threat modeling, and secure development guidelines.
• Review and assess the security posture of new features, integrations, and infrastructure changes prior to deployment.
• Support vendor and third-party risk assessments, particularly for offshore development partners and SaaS integrations.
• Serve as the internal subject matter expert on application security, API security, and OWASP Top 10 for the development teams.
What we're looking for:
• 7+ years of experience in cybersecurity engineering or information security roles, ideally within a SaaS or fintech environment.
• Demonstrated experience owning or leading compliance programs or audits NYDFS, ISO 27001, SOC2, PCI, or equivalent financial services..
• Strong hands-on experience with cloud security (AWS, Azure, or GCP), including identity, logging, monitoring, and access control
• Ability to quickly adapt and operate in an AWS-based environment is expected
• Experience securing SaaS platforms or applications, including API security and working with engineering teams in an SDLC environment
• Hands-on experience with SIEM platforms, vulnerability scanning tools, and endpoint security solutions.
• Strong understanding of OWASP Top 10, secure coding practices, and API security.
• Experience conducting or coordinating penetration tests and translating findings into remediation roadmaps.
• Excellent written communication skills -- ability to produce policy documentation, audit evidence, and clear security reports for non-technical audiences.
• Experience working in environments with offshore development teams and managing third party vendor security risk (preferred).
• Financial services, insurance, or lending industry background (preferred).
• CISSP, CISM, CEH, or equivalent security certification (preferred).
If this opportunity aligns with your career goals, kindly share your updated resume with us at hr@simelabs.com