About the RoleDriveWealth LLC is seeking a highly motivated and seasoned Head of Security Engineering to own the
security engineering strategy, roadmap, and delivery across our product platform and corporate environment.
Reporting to the Chief Information Security Officer, you will build and lead the Security Engineering team,
define its strategy and roadmap, and deliver improvements that support the security of customer data, the
firm's growth, and regulatory obligations.
In this leadership role, you will provide both expert guidance on security and security capability
implementation across our AWS platform, Kubernetes services, low-latency trading infrastructure, and
corporate technology. This role is focused on building and maturing the Security Engineering function and we
are seeking a leader who combines strategic thinking with hands-on engineering experience to establish
scalable controls and enable product innovation. You will also lead the development and maintenance of
infrastructure, services, and automation for Security Operations, partnering with Engineering, IT, Risk, and
Compliance within an innovative and entrepreneurial culture.
What You'll DoWhat You'll DoStrategy & Team Leadership- Roadmap Ownership: Define and deliver a multiyear security engineering strategy and quarterly roadmap across product and corporate environments, aligning architecture standards and investments with business priorities and risk appetite.
- Team Leadership: Hire, coach, and develop a team of high-performing security engineers, manage performance, and build technical depth as the team scales.
- Delivery & Risk Management: Manage backlogs, budgets, vendors, and dependencies. Work with Security GRC to measure control effectiveness and delivery. Communicate progress, tradeoffs, and residual risks to the CISO and technology leaders.
Product & Corporate Security- Product Security: Embed threat modeling, architecture reviews, security testing, and secure design into development and CI/CD, strengthening API authentication, authorization, data isolation, and secrets management.
- Infrastructure Security: Secure AWS, including services such as EKS, EC2, DynamoDB, as well as co-located trading infrastructure through least privilege, segmentation, encryption, hardening, and automated guardrails, accounting for availability, recovery, and latency requirements.
- Corporate Security: Partner with IT to mature identity, access governance, endpoint, remote access, DLP, communications, and SaaS security across the corporate service estate, including phishing-resistant authentication, device compliance, and data protection.
- Exposure Management: Build scanning and remediation capabilities across cloud and on-premises environments, code, dependencies, containers, and infrastructure. Partner with Engineering and IT to prioritize fixes and prevent recurring vulnerabilities and other types of exposures.
Security Operations Enablement- Security Platforms: Build, integrate, and maintain the infrastructure and services used for monitoring, investigation, exposure management, and response, including SIEM, SOAR, and endpoint security platforms.
- Telemetry Engineering: Own security data pipelines across product and corporate systems, ensuring coverage, quality, enrichment, availability, appropriate retention, and documented maintenance and support procedures.
- Operational Partnership: Deliver detection and response automation with Security Operations, provide incident engineering support, and implement lasting improvements. Security Operations retains day-to-day ownership of monitoring, triage, and response.
- Investigation & Response Support: Provide Security Operations with necessary expertise and support during security investigations and incident response activities.
Compliance & Assurance- Regulatory Controls: Partner with Legal, Compliance, and GRC to implement SEC and FINRA requirements, including SEC Rule 17a-4 controls supporting record capture, preservation, integrity, access, and retrieval. Partner with Security GRC to align the Security Engineering roadmap to regulatory requirements and other necessary compliance controls and activities, such as SOC 2 Type 2 auditing.
- Data Security & Privacy: Build and maintain capabilities for data discovery, classification, access control, encryption, retention, and secure deletion to support GDPR and other applicable privacy and data protection requirements.
- Control Assurance: Automate control validation and evidence collection. Support audits and regulatory examinations, and drive remediation of technical findings.
You Bring- 10+ years of relevant security, software, or infrastructure engineering experience, including 4+ years directly managing technical teams.
- Demonstrated success owning a security engineering roadmap and delivering measurable improvements across production and corporate environments.
- Expertise in AWS and Kubernetes security, with practical experience securing APIs and modern software delivery pipelines.
- Strong working knowledge of identity and access management, macOS and Windows endpoint security, remote access/SASE, network security, and SaaS security. Experience with Okta, JumpCloud, or comparable platforms.
- Experience building and maintaining security platforms, telemetry pipelines, and automation used by security operations teams.
- Ability to review code and infrastructure changes and contribute engineering solutions using Python, Java, or a comparable language and infrastructure-as-code tools such as Terraform.
- Sound judgment balancing security, reliability, developer productivity, and cost.
- Ability to influence technical decisions and communicate clearly with executives, engineers, and business partners.
- Experience delivering security capabilities in regulated financial services or another environment with demanding availability, data protection, and audit requirements. Brokerage, trading infrastructure, and SEC/FINRA experience are preferred.
- Bachelor's degree in a related field or equivalent practical experience. Relevant security, AWS, or Kubernetes certifications are a plus.
Special Knowledge (Nice to Have, But Not Required)[Ctrl/-V to paste with formatting/bullets]
LocationThis role is open to candidates in the following locations:
New York City, Chicago, Austin, Dallas, Denver, Miami, San Francisco Bay Area, or Seattle.
- If based in New York or Chicago: This role is expected to come into the office on a cadence set by the Hiring Manager/Team.
- If based in Austin, Dallas, Denver, Miami, San Francisco, or Seattle: This is a fully remote role, though you may need to visit our onsite offices from time to time.
- If you're not based in one of the locations listed above, this role is not a fit, and we cannot accommodate remote work outside these locations.
- Applicants must be authorized to work for any employer in the U.S. DriveWealth does not sponsor or take over sponsorship of an employment visa at this time.
Pay Range: $220,000 - $250,000 USD
Working at DriveWealthWe do our best work when we're in the same room. To maintain the speed our partners expect, our New York, Chicago, and Lithuania teams work in office on a hybrid schedule. We've found that being physically side-by-side is the only way to solve complex problems in real-time and stay truly accountable to the products we ship. When you're here, you're working directly with the people making the decisions.
To support that work, we provide competitive compensation, equity, and a 401(k) match. We also offer Medical insurance, Dental insurance, Vision insurance, Disability insurance, and Paid Parental Leave, along with a wellness reimbursement, a company-provided phone, and a personal development allowance. Finally, we value the time you spend away from the office with generous Paid Time Off (PTO) and observed holidays.
How We Think About AIWe leverage AI to work smarter and move faster. We seek AI-curious talent who are proactive about using emerging tools to increase signal quality, reduce friction, and improve outcomes to deliver products faster, provide better service to our partners, and to streamline processes. Your ability to leverage our internal tools and technology to drive results is as important to us as your core domain expertise.
CompensationPay is generally based on the level, complexity, responsibility, location, and job duties/requirements of the specific position. We then source candidates with the requisite skills, expertise, education, training, and experience. If you are selected for an interview, please feel welcome to speak to a recruiter about our compensation philosophy and other available benefits. This role is eligible for base, bonus, equity, 401(k) match, and heavily subsidized benefits and perks.
Agency DisclaimerDriveWealth does not accept agency resumes. Do not forward resumes to our jobs alias, employees, or any other organization location. DriveWealth is not responsible for any fees related to unsolicited resumes.