Security Engineering Lead
Upvest provides regulated, API-first investment infrastructure for fintechs, banks, brokers, and wealth managers across Europe and the UK. Its platform supports brokerage, settlement, custody, fractional investing, portfolios, savings plans, and investment operations.
Funding history
About Upvest GmbH
Upvest is a regulated investment infrastructure company offering a cloud-native Investment API for brokerage, settlement, custody, and real-time investment functionality. It also provides middle- and back-office business process outsourcing, regulatory licences, fractional securities, portfolios, savings plans, and operating models for financial institutions launching or scaling investment and pension products.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
Lead Upvest's Security Engineering function across application security, cloud security, secure development practices, and regulatory implementation. The role combines technical leadership, team growth, security architecture, automation, and cross-functional partnership.
Requirements
- 6–10 years of security engineering experience, including 4+ years in product or cloud security in a regulated environment.
- Hands-on ability to read code, threat model designs, debate architectures, and write tooling.
- Cloud-native security expertise with GCP preferred; AWS or Azure experience is transferable.
- Knowledge of IAM, network segmentation, KMS, Terraform, Kubernetes hardening, RBAC, network policies, and Pod Security Standards.
- Strong application security foundations including OWASP Top 10, ASVS, secure code review, SAST, DAST, SCA, SLSA, and signing.
- Ability to lead through influence and make risk-based decisions with engineering teams.
- Experience hiring and growing a small team.
- Clear communication with engineers, auditors, regulators, and executives.
Responsibilities
- Set multi-quarter application and cloud security strategy aligned with product, tenant, and regulatory requirements.
- Lead, mentor, hire, and grow the Security Engineering team and security culture.
- Build secure paved roads for encryption, authentication, authorization, CI/CD, data, and network surfaces.
- Own threat modeling, secure code review, SAST, DAST, SCA integration, and vulnerability management.
- Drive GCP cloud security posture using IAM, VPC Service Controls, Cloud KMS, Wiz, Binary Authorization, Terraform, GKE, and Linkerd.
- Translate DORA requirements and threat-led penetration testing into engineering programs and audit evidence.
- Embed security into product design through architecture reviews, partnerships, and security champions.
- Address emerging AI, LLM, and agentic identity security threats.
- Represent Upvest's security posture to stakeholders.
- Participate in the security on-call rotation.
Benefits
- €20,000 annual budget for AI tools
- 30 days of annual leave
- Sports benefits
- Confidential professional coaching
- Remote work abroad for up to 183 days per year
- One-month fully paid sabbatical after every four years
- Personal development budget
- Flexible hybrid or remote work across Europe
- Competitive above-market salary and employee equity program
- Company-wide events and Employee Resource Groups
