The mission of Yieldstreet's Security Team is to protect our investor and company data by monitoring the data we generate from the services we use and create, implementing thoughtful controls that enhance enterprise security with minimal impact to team productivity, and raising awareness of the persistent threats to our organization. We are enablers. We make it easier for stakeholders in infrastructure and core engineering to create secure products, while preempting security vulnerabilities in our platform.As the Security Engineering Lead, you will build and lead a team to drive the design, implementation, and maintenance of Yieldstreet's security solutions while also ensuring a seamless developer experience across our software development life cycle. You will collaborate with Yieldstreet's core and infrastructure engineering teams to deliver shared outcomes that measurably improve our efficacy and efficiency in detecting, responding to, and recovering from vulnerabilities and threats, and acquiring and maintaining industry certifications.This role reports to the Chief Technology Officer.What you will do:Monitor, investigate and respond to security threats across Yieldstreet systems and networks.Conduct regular security assessments and audits of both application and infrastructure components to identify vulnerabilities and areas for improvement.Develop and enforce security best practices for infrastructure automation and orchestration.Monitor bug bounty submissions and coordinate response to legitimate submissions.Analyze event logs and network activity to detect and respond to security incidents.Assist in maintaining SOC 2 Type II, GDPR, and related compliance standards.Drive a culture of security through security training and awareness efforts.Participate in incident response and recovery efforts as needed.Focus Areas:Threat Modeling and Attack Surface Reduction.Vulnerability Management.Security Operations Monitoring.Cloud Security Architecture.Application Security Architecture.What you will need:Minimum 5 years experience building software.Minimum 3 years of experience building in AWS (with Terraform).Fluent in English and ability to document solutions and specifications.Experience improving the developer experience and security properties of a multi-service deployment.Familiarity with the following technologies: Kubernetes, ArgoCD, SonarQube, Crowdstrike Falcon, Cloudflare, Istio, Datadog.Excellent English communication skills, both written and verbal.How To Apply:When sending your application, tell us about yourself, your crown achievements, your failures and your learnings and how you think they can fit here at YieldStreet. Use some of the examples of what you might do in the description of the role and walk us through some of the sample solutions.Apply for this job* indicates a required fieldFirst Name *Last Name *Email *PhoneResume/CV *Enter manuallyAccepted file types: pdf, doc, docx, txt, rtfLinkedIn ProfileYieldstreet employs a hybrid working environment where employees work in office 3 days a week, and remote 2 days a week.
#J-18808-Ljbffr