About the role
You will work directly with the Head of Security to secure cloud infrastructure, CI/CD pipelines, and product code while building automated guardrails. Additionally, you will manage the vulnerability lifecycle, handle incident response, and support compliance efforts for standards like PCI DSS and SOC 2.
What they look for
Requirements
The role requires strong cloud security experience, particularly with AWS, and proficiency in infrastructure-as-code tools like Terraform. Candidates should be skilled in at least one general-purpose programming language and possess a deep understanding of container security and common vulnerability classes.
Benefits
Full description
Tuum is a next-generation banking platform. We enable fintech and banks to rapidly offer seamless and tailored financial services to their customers. Our core banking platform is revolutionising the financial services industry. The platform is API-based, consisting of flexible and independent modules covering all retail and business banking capabilities for quick and easy integration.
Launched in 2019, Tuum is headquartered in Tallinn and is backed by investors including Citibank, BlackFin Capital Partners, Karma Ventures, Portage Ventures, SpeedInvest, and CommerzVentures.
We're looking for a Security Engineer to help keep that platform safe, along with the money and data our customers trust us with. This role works well whether you're early in your security career or have years of experience — what matters most is how you think. Working directly with the Head of Security, you’ll dig into our cloud infrastructure, CI/CD pipeline, and product code to find weaknesses before attackers do and build guardrails that stop whole classes of bugs. This is a hands-on, build-oriented role: more code, automation, and root-cause fixes than tickets.
\n
What you'll be doing
- Threat model new services with product engineers, review code and infrastructure-as-code, and build tooling that catches recurring problems automatically.
- Harden our cloud environment (mainly AWS, some GCP): IAM, network boundaries, secrets/key management, logging, Kubernetes workloads, and Okta identity engineering.
- Own the vulnerability cycle end to end: the CI/CD gates (SAST, SCA, ECR image scanning), quarterly internal/external scanning, remediation to policy timeframes, and our penetration testing programme.
- Build and maintain detections on native cloud services and our own code, not a SIEM appliance - each one a query, a function and a runbook you own - and act as a first responder on incidents.
- Support the Head of Security on PCI DSS, SOC 2 and ISO 27001: you'd own the testing and much of the recurring calendar.
- Support the IT Lead on the corporate environment — automation, complex investigations, absence cover — while end-user support and device management stay with them.
- Help other engineers decide well without asking: reusable patterns, secure defaults, and a standing slot for security questions.
Our expectations
- Security engineering experience, or software/infrastructure engineering with substantial security ownership — deep working knowledge matters more to us than job titles.
- Strong cloud security experience with a focus on AWS: IAM, networking, key management, logging. You can read and write Terraform without help.
- Strong skills in at least one general-purpose language, plus confidence in reading others. Our platform is mostly Java and TypeScript, so you'd review both and write code a colleague can maintain.
- Practical experience securing containerised workloads, plus identity and access fundamentals: OAuth/OIDC, SAML, least privilege.
- Working knowledge of common vulnerability classes (OWASP Top 10 and beyond) and how to prevent them structurally, plus experience operating a security control you inherited rather than designed.
- Clear written English and the judgment to prioritise real risk over checklist findings - auditors and our customers' banks read what you write.
- A collaborative approach: you can say no when it matters, and offer a workable alternative when it doesn't.
Bonus points for
- University degree in cybersecurity or a related field.
- Detection engineering or incident response experience: log pipelines, EDR, cloud audit trails.
- Experience in a regulated or high-trust environment: fintech, payments, banking.
- Payments or card-issuing domain knowledge: PAN flows, scheme or issuer integration.
- Having stood up or run a vulnerability disclosure programme.
- Certifications such as AWS Certified Security Specialty, CKS, OSCP, or a hands-on GIAC track like GCSA or GCIH.
What we offer
- Competitive salary
- Tuum stock options
- Hybrid working (3 days a week in the office)
- 4-day work week during the summer months (June, July, August)
- Private health insurance or generous wellness compensation
- Career opportunities to grow both professionally and personally as we scale
- Bright and warm-hearted team of professionals delivering great things together
- All-hands-on-deck approach (meaning that everyone delivers value regardless of responsibilities)
\nWe are an equal opportunity employer and value diversity at our company. We actively hire for cultural growth and welcome people of all ages, backgrounds and value people who take a journey unique to them. Equality, diversity and inclusion are our priority and we are committed to ensuring all job applicants are treated equally. All applicants will be treated fairly and will be considered for employment without discrimination because of ethnicity, race, religion or belief, gender, sexual orientation, gender identity or gender reassignment, family or parental status, pregnancy or maternity, marital or civil partner status, national origin, age, veteran, neurodiversity status or disability status.
Similar roles
-
Cloud Security Engineer
Gifthealth Inc Columbus, Ohio, United States · $115K–$150K/yr
-
Senior Cybersecurity Engineer (Identity and Access Management)
Open Dealer Exchange Southfield, Michigan, United States
-
Cybersecurity Engineer
Open Dealer Exchange Southfield, Michigan, United States
-
Senior Information Security Engineer
Zscaler United States · $134K–$168K/yr
-
Cybersecurity Analyst
Smiths Group Pune, Maharashtra, India
-
Staff Product Security Engineer
Affirm Canada · CA$181K–CA$241K/yr