ARQ logo

Security Engineer, Senior

ARQ

London, England, United KingdomHybridFull-time$110–175K/yrPosted 1mo agoVerified open 5 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$110–175K/yr
Location
London, England, United KingdomHybrid
Schedule
Full-time
Work Authorization
Not specified

Job overview

ARQ is hiring a Security Engineer, Senior. ARQ seeks its first Security Engineer in Brazil to establish and shape the security function across application security, operations, and governance, working closely with the global team while having autonomy to define local security standards from day one.

Key focus areas include Drive application security initiatives including threat modelling, secure code review, API testing, and security pipeline improvements, Assess and secure AI/agentic workflows by reviewing prompts, preventing destructive actions, and controlling data exposure, and Build and improve SIEM detection rules, alert pipelines, and automated response playbooks using Datadog SIEM, CrowdStrike, and Cloudflare.

Successful candidates bring 4-7 Years In Information Security, Built Or Significantly Shaped Security Function At Startup Or High-Growth Company, and 2+ Years At Regulated Fintech/Bank/Payment Company. Important skills include Application Security, Security Operations, Governance Risk Compliance, Threat Modeling, Secure Code Review, and API Testing.

Skills & qualifications

RequiredNice to have

Skills

Application SecuritySecurity OperationsGovernance Risk ComplianceThreat ModelingSecure Code ReviewAPI TestingSecurity Pipeline ImprovementsAI/Agentic Workflows SecuritySIEM Detection RulesAlert PipelinesAutomated Response PlaybooksDatadog SIEMCrowdStrikeCloudflareIncident Response ReadinessIR PlaybooksTabletop ExercisesForensic ProceduresCloud Security AssessmentsAWSKubernetesVendor Security Assessment ProcessScalable Due Diligence FrameworkCloud Infrastructure SecurityCI/CD Pipeline HardeningLLM Integrations Risk AssessmentMCP Servers SecurityAutomated Workflows SecuritySIEM PlatformsDetection EngineeringEndpoint Security ToolingEDR/XDRIdentity & Access ManagementGoogle WorkspaceSSO/SCIMVendor Security AssessmentsThird-Party Due DiligenceWritten Communication in EnglishVerbal Communication in English

Qualifications

4-7 Years in Information SecurityBuilt or Significantly Shaped Security Function at Startup or High-Growth Company2+ Years at Regulated Fintech/Bank/Payment Company

Full job description

What We're Looking For You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one.

We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty.

What you'll do

  • Drive application security initiatives: threat modelling, secure code review support, API testing, and security pipeline improvements

  • Assess and secure AI/agentic workflows across the company — reviewing prompts, preventing destructive actions, and controlling data exposure

  • Build and improve SIEM detection rules, alert pipelines, and automated response playbooks (Datadog SIEM, CrowdStrike, Cloudflare)

  • Contribute to incident response readiness, including IR playbooks, tabletop exercises, and forensic procedures

  • Conduct cloud security assessments across AWS and Kubernetes environments

  • Establish and run the vendor security assessment process — building a scalable due diligence framework for third-party onboarding

What you'll need

  • 4–7 years in information security, ideally having built or significantly shaped the security function at a startup or high-growth company - you've been the person who sets things up, not just maintains them

  • 2+ years at a regulated fintech/bank/payment company

  • Hands-on experience with cloud infrastructure security (AWS, Kubernetes)

  • Familiarity with application security practices: threat modelling, secure code review, CI/CD pipeline hardening, and API security testing

  • Ability to assess and secure emerging AI/agentic tooling - you understand the risks of LLM integrations, MCP servers, and automated workflows, and can define practical guardrails

  • Working knowledge of SIEM platforms and detection engineering - you've written detection rules

  • Experience with endpoint security tooling (EDR/XDR) and identity & access management in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM)

  • Experience running or contributing to vendor security assessments and third-party due diligence

  • Strong written and verbal communication in English

Benefits

  • Competitive salary and benefits

  • Stock options, so you own part of what you build

  • Discretionary performance bonus

  • The latest tools and technology

  • A world-class team that will challenge and grow your skills

  • The opportunity to help build the best fintech app in Latin America

  • Office Policy: 3-4 days a week in-office

You've read the whole posting — now see how you match it.