Salary
$0–0/yr
TrueML is a mission-driven financial software company that aims to create better customer experiences for distressed borrowers. Consumers today want personal, digital-first experiences that align with their lifestyles, especially when it comes to managing finances. TrueMLâs approach uses machine learning to engage each customer digitally and adjust strategies in real time in response to their interactions.
The TrueML team includes inspired data scientists, financial services industry experts and customer experience fanatics building technology to serve people in a way that recognizes their unique needs and preferences as human beings and endeavoring toward ensuring nobody gets locked out of the financial system.
\n
What you will do
Position Summary
We are seeking a Sr. Security Engineer to lead the integration of security across the software
development lifecycle (SDLC). This role sits at the intersection of engineering, cloud infrastructure, and
application security, driving automation, scalability, and secure-by-default development practices.
You will design and implement security-first CI/CD pipelines, embed automated security testing, and
partner with engineering teams to ensure applications are built, deployed, and operated securelyâat
scale
Key Responsibilities
Security Automation & CI/CD Integration (Core Focus)
⢠Embed security controls and scanners (SAST, SCA, DAST, IaC, Container Security) into CI/CD
pipelines
(GitHub Actions, Jenkins, GitLab CI, Azure DevOps)
⢠Design and maintain automated security workflows across build, test, and deploy stages
⢠Implement security gates, policy enforcement, and compliance checks within pipelines
Cloud Security (AWS Focus)
⢠Secure cloud-native architectures across AWS (IAM, VPC, ECS/EKS, Lambda, S3, API Gateway)
⢠Integrate and operationalize CNAPP/CSPM tools (e.g., Wiz, Prisma Cloud)
⢠Enforce least privilege access, secrets management, and runtime protections
Define and maintain security policies for our AWS environment, specifically focusing on containerized workloads (EKS/ECS) and serverless architectures (Lambda).
Automate Compliance: Move beyond manual checks by building real-time monitoring and automated remediation for AWS resources, ensuring we stay "audit-ready" for frameworks like PCI and ISO 27001.
Lead Threat Modeling: Perform deep-dive threat modeling exercises on applications and designs, turning theoretical risks into actionable engineering plans.
Innovate with AI: Stay at the forefront of the industry by developing security standards for Generative AI. Youâll leverage AI-powered tools to explore our attack surface while defending against AI-driven threats.
Guard the Infrastructure: Secure our Infrastructure as Code (IaC) templates (Terraform/CloudFormation) and manage cloud primitives like IAM, KMS, and WAF to ensure a "least privilege" environment.
What you bring
Pro unlocks apply links & auto-apply
Spam, scam, fake employer, broken apply link — let us know and we’ll review within 24h.
Report this listing