- Company Name
- ION
- Job Title
- Markets Product Security Engineer
- Job Description
-
**Job Title**
Markets Product Security Engineer
**Role Summary**
Drive security and compliance for product development in a regulated financial services environment. Serve as the primary security advisor throughout the product lifecycle, integrating threat intelligence, risk assessments, and industry standards to strengthen platform security posture.
**Expectations**
- Align security strategy, design, and controls with product road‑map.
- Provide transparent reporting of product control performance and risk to leadership.
- Conduct threat modelling and design reviews to ensure compliance with NIST, ISO, GDPR, DORA, and other applicable regulations.
**Key Responsibilities**
- Monitor security events, emerging threats, and dependencies for assigned product lines.
- Act as liaison between CSIRT and product engineering for incident response.
- Deliver threat modelling, hunting, and vulnerability assessments; recommend control mitigations.
- Participate in architecture and design reviews, ensuring adherence to security strategy and best practices.
- Stay current with industry trends, regulatory updates, and security frameworks (CIS, CSF).
- Engineer control solutions where gaps exist.
- Provide security expertise during incident and problem management.
- Produce threat intelligence briefings and other security documentation.
- Respond to on‑call and ad‑hoc security guidance requests.
**Required Skills**
- **Domain Knowledge**: Experience in financial services or other heavily regulated sectors; familiarity with information security governance, compliance, and regulatory frameworks (NIST, ISO, GDPR, DORA, NIS).
- **Technical Proficiency**: Understanding of IT systems, network infrastructure, data architecture, cloud security, CIS, CSF.
- **Security Tooling**: SIEMs, vulnerability scanners, firewalls, EDR.
- **Scripting**: Python, BASH, PowerShell.
- **Incident Management**: Detection, response, recovery of escalated incidents; backlog and lessons‑learned management.
- **Risk Assessment**: Conduct comprehensive security risk assessments and post‑event analyses.
- **Communication**: Translate complex security issues to technical and non‑technical audiences.
- **Professional Traits**: Independent work, task prioritization, adaptability, composure under pressure, confidentiality handling.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent experience).
- Preferred certifications: GCIH, CSEC, CSSLP, CISSP, CASP+.