Security Automation Engineer
Job Description
Flourish was founded in 2017 with the goal of helping financial advisors to better secure the financial futures of their clients. We focus on independent Registered Investment Advisers (RIAs), delivering financial products that advisors can’t easily access today through beautiful, scalable, and easy-to-use technology.
Today, we work with over 400 RIAs that collectively represent more than $1 trillion in assets under management across two products: Flourish Cash,1 a cash management solution with more than $1B in deposits, and Flourish Crypto,2 a turnkey cryptocurrency offering built for financial advisors and their clients. In February of 2021, we joined MassMutual3 to continue our journey in partnering with the independent RIA community to help more people reach their financial goals.
Read on if you are interested in joining a small, highly collaborative, rapidly growing startup—backed by the support and stability of a Fortune 500 company.
You love automation and want to have your hands on a keyboard securing a high-velocity environment with demanding security posture requirements. You appreciate that in a heavily federated security environment, your infrastructure and application partners are contributing to security in a timebox. You understand how automation reduces their toil and how providing clean, well-summarized data supports their security responsibilities.
With an eye for assessing data quality, you understand how it creates automation opportunities and supports decision-making. Communication with internal partners is important - you understand the change impact of your work, when to seek feedback about production and workflow impact, and how to budget change so that partners can keep pace. Juggling a large range of opportunities for automation is exciting and you can work under self-imposed timebox constraints. You are thrilled at never having to do GRC but appreciate the need to meet security standards, show basis for judgment, and enable machine-readable auditability and metrics as primary automation features and design considerations, treating this as an aspect of SRE for modern operations.
While deep technical skills across a wide range of domains are critical to success with us, we're also looking for fast learners who are passionate about security and are constantly researching to stay ahead of the newest threats. We want to support your growth as an ambitious and motivated generalist. You are analytical, love to problem solve and understand the importance of collaboration. You constantly look for ways to improve operations and are able to manage projects independently.
Qualifications- Bachelor’s degree in Computer Science, Math, Physics or Engineering
- 5+ years of related technical experience in Cybersecurity, preferably in a Cloud Environment
- 5+ years of experience with Programming and Scripting Languages (Python strongly preferred).
- Experience automating operational processes, preferably in a Cloud Environment
- Conceptual familiarity with vulnerability and posture management for infrastructure and/or applications
- 2+ years of experience working with infrastructure and application stakeholders on the deployment portion of product life cycles, preferably including security considerations such as vulnerability and posture assessment and remediation for internet-facing products
We don’t expect experience in a large number of these areas, what we are looking for is someone hungry enough as a generalist to sustain this breadth.
- Python for automation and data analysis
- AWS, particularly SecurityHub, GuardDuty, Lambda, IAM/SCPs, and Inspector
- Modern identity, particularly Okta
- Application Security in an agile environment
- Developing for data pipelines and analytics
- Cloud networking (IaaS networking primitives, LBs, CDN, WAF, DNS, service mesh)
- Infrastructure as Code, preferably Terraform
- Development in Golang as a programming language additional to Python
- MITRE ATT&CK framework, particularly data sources
- Log analysis (Splunk, Athena, CloudTrail) and reporting
- Security and systems administration in Windows-, Linux-, and MacOS-based operating system environments
- Containers and container orchestration, preferably Kubernetes
- SaaS security, particularly Google Workspaces and Slack
- VDI or Cloud VDI, particularly AWS Workspaces and Workspaces Application Manager
- Endpoint management (UEM/MDM, particularly Jamf and EDR)
- CIS hardening all of the above
- Incident response automation
- Hands-on experience with delivery via DevOps processes (git with pull requests, code reviews, automated code hygiene checks, e.g.,git hooks or CI/CD actions)
- Familiarity with SRE methodology
- Verifiability problems of work experience domain (e.g. data quality measurement for data engineering, code coverage for software engineering, reachability for network security, least privilege for IAM, SLOs for reliability characteristics)
- Experience developing in a non-dynamic language, preferably Golang
- Familiarity with security and privacy frameworks, particularly CIS, NIST CSF/PF, and Cloud Security Alliance
Disclosures:
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.
1 A Flourish Cash account is a brokerage account offered by Flourish Financial LLC. Flourish Financial LLC is not a bank. The cash balance in a Flourish Cash account will be swept from the brokerage account to deposit account(s) at one or more third-party banks that have agreed to accept deposits from customers of Flourish Financial LLC (Program Banks). The accounts at Program Banks will pay a variable rate of interest. If you were introduced or invited to Flourish Cash by a third-party investment adviser or other third party, whose name or logo may be shown above, please be aware that, unless otherwise disclosed to you, they are not affiliated with Flourish Financial LLC and will not provide any advisory or brokerage services for your Flourish Cash account or have the authority to provide instructions on your account.
2 Flourish Crypto is a cryptocurrency investment account through which investors can trade cryptocurrencies and maintain custody of cryptocurrencies and U.S. dollars. Custody of Flourish Crypto accounts, including all assets in the accounts, and cryptocurrency trading services are provided by Paxos Trust Company, LLC (Paxos) in accordance with the Paxos Terms. Paxos is a New York limited purpose trust company regulated by the New York Department of Financial Services. Website and other technology services and support for Flourish Crypto accounts are provided by Flourish Digital Assets LLC (Flourish Digital Assets) in accordance with the Flourish Crypto Terms. Flourish Digital Assets is registered in New York as a commodity broker-dealer. Investment options in Flourish Crypto accounts are currently limited to bitcoin. Cryptocurrencies held in Flourish Crypto accounts are not currently eligible for in-kind transfer to other custodians or cryptocurrency wallets. If a Flourish Crypto account is closed, the customer’s cryptocurrency positions will be liquidated and the customer will receive the U.S. dollar proceeds. Investing in cryptocurrencies involves a high degree of risk, as further described in the risk disclosures section of the Paxos Terms and the Flourish Crypto Terms. Flourish Crypto accounts are separate from Flourish Cash accounts and assets in Flourish Crypto accounts are not eligible for protection by the Securities Investor Protection Corporation (SIPC).
3 The Flourish business is owned by Massachusetts Mutual Life Insurance Company ("MassMutual"). Flourish Financial LLC and Flourish Digital Assets LLC are indirect, wholly-owned subsidiaries of MassMutual.
Date Posted
08/25/2022
Views
5
Similar Jobs
Software Engineer - Python - Vatic Investments
Views in the last 30 days - 7
Vatic Investments is looking for a Python Software Engineer to work on algorithmic trading systems The role requires expertise in C Python and Linux a...
View DetailsSenior DevOps Engineer - 3Red Partners
Views in the last 30 days - 0
3Red Partners LLC is seeking a Senior DevOps Engineer to join their team The company offers competitive benefits excellent worklife balance and opport...
View DetailsSenior Mobile Engineer - Viam
Views in the last 30 days - 13
Viam is a robotics platform that makes it easy to turn great ideas into productionready robots The company is looking for a Mobile Engineer to build c...
View DetailsSoftware Engineer - Viam
Views in the last 30 days - 14
Viam is a robotics platform that makes it easy to turn great ideas into productionready robots It offers a modern architecture easy developer APIs clo...
View DetailsSoftware Engineer, SDK/NetCode - Viam
Views in the last 30 days - 11
Viam is a robotics platform that makes it easy to turn great ideas into productionready robots The company is looking for engineers to build software ...
View DetailsSr. Manager/Associate Director, Program Management - Volastra Therapeutics
Views in the last 30 days - 11
Volastra Therapeutics is a biotechnology company dedicated to discovering and developing treatments for patients with cancer They have raised funding ...
View Details