We are looking for a highly skilled Security Engineer with strong expertise in audits, compliance, and penetration testing to strengthen the security posture of our high-frequency trading (HFT) infrastructure. The ideal candidate will have a blend of technical proficiency and regulatory understanding, with hands-on experience in security assessments, vulnerability management, and compliance frameworks.
Key Responsibilities
- Conduct and manage System Audits, Exchange IT Compliance Audits, Vulnerability Assessments, and Compliance Audits in line with regulatory and internal requirements.
- Plan, execute, and document penetration testing to identify and mitigate security risks.
- Collaborate with cross-functional teams (IT, Legal, Compliance) to prepare, review, and submit compliance documentation for regulatory bodies and exchange audits.
- Drive security controls within the CI / CD pipelines ensuring robust DevSecOps practices.
- Ensure timely remediation of vulnerabilities, deviations, and audit findings across infrastructure and applications.
- Maintain up-to-date knowledge of exchange regulations, IT security standards, and compliance requirements applicable to HFT environments.
- Provide technical expertise and support during external and internal audits.
- Act as a bridge between engineering, compliance, and business leadership to strengthen system reliability, security, and adherence to policies.
Key Skills & Competencies
Strong understanding of IT compliance frameworks, exchange audit requirements, and vulnerability management.Hands-on experience in penetration testing, system hardening, and security tooling.Expertise in CI / CD pipelines, DevOps practices, and secure deployment strategies.Excellent documentation, reporting, and cross-team collaboration skills.Analytical mindset with problem-solving ability to balance regulatory compliance and system performance in a high-speed trading environment.Qualifications
Bachelor's degree in Engineering (BE) with MBA preferred.Professional certifications : CISA (Certified Information Systems Auditor) and CISM (Certified Information Security Manager).Additional certifications in penetration testing, cloud security, or DevSecOps will be an advantage.Show more
Show less
Skills Required
Vulnerability Management, Penetration Testing