About the job
Location: Fully Remote - UK/Europe
Reporting Line: Chief Risk Officer
About Auros Global
Auros Global is a leading digital asset liquidity provider operating around the clock across both centralized and decentralized markets. We specialize in high-availability and low-latency systems, where resilience and risk management are paramount. Security is integral to our engineering and risk functions, with robust engagement from senior leadership.
The Role
We are seeking a proactive Principal Security Engineer to establish and manage security controls across our infrastructure. This role focuses on technical execution, requiring you to write code, configure systems, and deliver security enhancements rather than drafting policies or overseeing personnel.
You will collaborate closely with Infrastructure and Engineering teams to fortify our cloud environments, secure our CI/CD pipelines, and safeguard both corporate and production systems. The environment is dynamic, and you will be expected to take ownership of problems from start to finish.
At Auros, we believe that security should empower business operations rather than hinder them. You will design security measures that are effective yet unobtrusive, ensuring seamless integration that does not create friction for engineers or traders.
What You Will Do
- Implement and maintain security controls across multi-cloud environments (primarily AWS and Azure, with some GCP and AliCloud) and on-premises infrastructure.
- Own the Identity and Access Management (IAM) strategy and implementation: design and enforce secure, scalable, and practical identity, access, and permissions models.
- Design and operate key management and custody security controls, including Hardware Security Modules (HSM), secrets management, and secure key handling for trading operations.
- Enhance CI/CD pipelines (GitLab) and secure the software delivery lifecycle.
- Configure and operate corporate security tools (endpoint protection, MDM/Jamf, DLP, identity management).
- Respond to security incidents: triage, investigate, contain, and remediate.
- Conduct security assessments of infrastructure and applications.
- Automate security operations, including detection, alerting, and response.
- Collaborate with Infrastructure teams to embed security into cloud provisioning and system configuration.
