DriveWealth

Head of Security Engineering

DriveWealth • $220K — $250K *
US-AnywhereRemote in United States
Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in security, software, or infrastructure engineering, with 4+ years in team management.
  • Proven track record in owning a security engineering roadmap and delivering improvements.
  • Expertise in AWS and Kubernetes security, particularly in API and software delivery pipeline security.
  • Strong knowledge of identity and access management, endpoint security, and SaaS security.
  • Experience in building security platforms and automation for security operations teams.
  • Ability to review code and infrastructure changes, contributing solutions in Python, Java, or similar languages.
  • Experience in regulated financial services, particularly in brokerage or trading infrastructure.

Responsibilities

  • Define and deliver a multiyear security engineering strategy and quarterly roadmap.
  • Hire, coach, and develop a high-performing security engineering team.
  • Manage backlogs, budgets, and vendor relationships while communicating risks to leadership.
  • Embed security practices into development processes, enhancing API security and data protection.
  • Secure AWS and trading infrastructure through best practices in access control and encryption.
  • Partner with IT to enhance corporate security measures, including identity governance and data protection.
  • Build and maintain security monitoring and response infrastructure, ensuring effective incident management.

Benefits

  • Competitive compensation and equity options.
  • 401(k) match and generous Paid Time Off (PTO).
  • Comprehensive medical, dental, and vision insurance.
  • Disability insurance and paid parental leave.
  • Wellness reimbursement and personal development allowance.
  • Company-provided phone and support for in-office collaboration.
Full Job Description
About the Role

DriveWealth LLC is seeking a highly motivated and seasoned Head of Security Engineering to own the
security engineering strategy, roadmap, and delivery across our product platform and corporate environment.
Reporting to the Chief Information Security Officer, you will build and lead the Security Engineering team,
define its strategy and roadmap, and deliver improvements that support the security of customer data, the
firm's growth, and regulatory obligations.
In this leadership role, you will provide both expert guidance on security and security capability
implementation across our AWS platform, Kubernetes services, low-latency trading infrastructure, and
corporate technology. This role is focused on building and maturing the Security Engineering function and we
are seeking a leader who combines strategic thinking with hands-on engineering experience to establish
scalable controls and enable product innovation. You will also lead the development and maintenance of
infrastructure, services, and automation for Security Operations, partnering with Engineering, IT, Risk, and
Compliance within an innovative and entrepreneurial culture.

What You'll Do
What You'll Do
Strategy & Team Leadership
  • Roadmap Ownership: Define and deliver a multiyear security engineering strategy and quarterly roadmap across product and corporate environments, aligning architecture standards and investments with business priorities and risk appetite.
  • Team Leadership: Hire, coach, and develop a team of high-performing security engineers, manage performance, and build technical depth as the team scales.
  • Delivery & Risk Management: Manage backlogs, budgets, vendors, and dependencies. Work with Security GRC to measure control effectiveness and delivery. Communicate progress, tradeoffs, and residual risks to the CISO and technology leaders.
Product & Corporate Security
  • Product Security: Embed threat modeling, architecture reviews, security testing, and secure design into development and CI/CD, strengthening API authentication, authorization, data isolation, and secrets management.
  • Infrastructure Security: Secure AWS, including services such as EKS, EC2, DynamoDB, as well as co-located trading infrastructure through least privilege, segmentation, encryption, hardening, and automated guardrails, accounting for availability, recovery, and latency requirements.
  • Corporate Security: Partner with IT to mature identity, access governance, endpoint, remote access, DLP, communications, and SaaS security across the corporate service estate, including phishing-resistant authentication, device compliance, and data protection.
  • Exposure Management: Build scanning and remediation capabilities across cloud and on-premises environments, code, dependencies, containers, and infrastructure. Partner with Engineering and IT to prioritize fixes and prevent recurring vulnerabilities and other types of exposures.
Security Operations Enablement
  • Security Platforms: Build, integrate, and maintain the infrastructure and services used for monitoring, investigation, exposure management, and response, including SIEM, SOAR, and endpoint security platforms.
  • Telemetry Engineering: Own security data pipelines across product and corporate systems, ensuring coverage, quality, enrichment, availability, appropriate retention, and documented maintenance and support procedures.
  • Operational Partnership: Deliver detection and response automation with Security Operations, provide incident engineering support, and implement lasting improvements. Security Operations retains day-to-day ownership of monitoring, triage, and response.
  • Investigation & Response Support: Provide Security Operations with necessary expertise and support during security investigations and incident response activities.
Compliance & Assurance
  • Regulatory Controls: Partner with Legal, Compliance, and GRC to implement SEC and FINRA requirements, including SEC Rule 17a-4 controls supporting record capture, preservation, integrity, access, and retrieval. Partner with Security GRC to align the Security Engineering roadmap to regulatory requirements and other necessary compliance controls and activities, such as SOC 2 Type 2 auditing.
  • Data Security & Privacy: Build and maintain capabilities for data discovery, classification, access control, encryption, retention, and secure deletion to support GDPR and other applicable privacy and data protection requirements.
  • Control Assurance: Automate control validation and evidence collection. Support audits and regulatory examinations, and drive remediation of technical findings.


You Bring
  • 10+ years of relevant security, software, or infrastructure engineering experience, including 4+ years directly managing technical teams.
  • Demonstrated success owning a security engineering roadmap and delivering measurable improvements across production and corporate environments.
  • Expertise in AWS and Kubernetes security, with practical experience securing APIs and modern software delivery pipelines.
  • Strong working knowledge of identity and access management, macOS and Windows endpoint security, remote access/SASE, network security, and SaaS security. Experience with Okta, JumpCloud, or comparable platforms.
  • Experience building and maintaining security platforms, telemetry pipelines, and automation used by security operations teams.
  • Ability to review code and infrastructure changes and contribute engineering solutions using Python, Java, or a comparable language and infrastructure-as-code tools such as Terraform.
  • Sound judgment balancing security, reliability, developer productivity, and cost.
  • Ability to influence technical decisions and communicate clearly with executives, engineers, and business partners.
  • Experience delivering security capabilities in regulated financial services or another environment with demanding availability, data protection, and audit requirements. Brokerage, trading infrastructure, and SEC/FINRA experience are preferred.
  • Bachelor's degree in a related field or equivalent practical experience. Relevant security, AWS, or Kubernetes certifications are a plus.


Special Knowledge (Nice to Have, But Not Required)

[Ctrl/ -V to paste with formatting/bullets]

Location

This role is open to candidates in the following locations: New York City, Chicago, Austin, Dallas, Denver, Miami, San Francisco Bay Area, or Seattle.
  • If based in New York or Chicago: This role is expected to come into the office on a cadence set by the Hiring Manager/Team.
  • If based in Austin, Dallas, Denver, Miami, San Francisco, or Seattle: This is a fully remote role, though you may need to visit our onsite offices from time to time.
  • If you're not based in one of the locations listed above, this role is not a fit, and we cannot accommodate remote work outside these locations.
  • Applicants must be authorized to work for any employer in the U.S. DriveWealth does not sponsor or take over sponsorship of an employment visa at this time.

Pay Range: $220,000 - $250,000 USD

Working at DriveWealth

We do our best work when we're in the same room. To maintain the speed our partners expect, our New York, Chicago, and Lithuania teams work in office on a hybrid schedule. We've found that being physically side-by-side is the only way to solve complex problems in real-time and stay truly accountable to the products we ship. When you're here, you're working directly with the people making the decisions.

To support that work, we provide competitive compensation, equity, and a 401(k) match. We also offer Medical insurance, Dental insurance, Vision insurance, Disability insurance, and Paid Parental Leave, along with a wellness reimbursement, a company-provided phone, and a personal development allowance. Finally, we value the time you spend away from the office with generous Paid Time Off (PTO) and observed holidays.

How We Think About AI

We leverage AI to work smarter and move faster. We seek AI-curious talent who are proactive about using emerging tools to increase signal quality, reduce friction, and improve outcomes to deliver products faster, provide better service to our partners, and to streamline processes. Your ability to leverage our internal tools and technology to drive results is as important to us as your core domain expertise.

Compensation

Pay is generally based on the level, complexity, responsibility, location, and job duties/requirements of the specific position. We then source candidates with the requisite skills, expertise, education, training, and experience. If you are selected for an interview, please feel welcome to speak to a recruiter about our compensation philosophy and other available benefits. This role is eligible for base, bonus, equity, 401(k) match, and heavily subsidized benefits and perks.

Agency Disclaimer

DriveWealth does not accept agency resumes. Do not forward resumes to our jobs alias, employees, or any other organization location. DriveWealth is not responsible for any fees related to unsolicited resumes.

About DriveWealth

DriveWealth is a financial services company that provides a digital trading platform for retail investors. The company's platform enables investors to buy and sell securities in real-time using fractional shares, making it easier and more affordable for individuals to invest in the stock market. DriveWealth's platform is available in over 150 countries and supports trading in US equities, exchange-traded funds (ETFs), and American depositary receipts (ADRs). The company was founded in 2012 and is headquartered in Chatham, New Jersey.
Learn more about DriveWealth
Size
100 employees
Industry
Founded
2012

Similar Jobs

More Jobs at DriveWealth

More Finance & Insurance Jobs

Find similar Head of Security Engineering jobs: