ARQ logo

Security Engineer

ARQ

London, England, United KingdomFull-timeSeen 1mo agoStill listed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
London, England, United Kingdom
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

ARQ, a fast‑growing fintech, seeks a Security Engineer to build and enhance SIEM detection, incident response, DLP, cloud and application security, and vendor assessments across its global operations.

Skills & qualifications

RequiredNice to have

Skills

SIEMDatadog SIEMCrowdStrikeCloudflareIncident ResponseDLPGoogle WorkspaceSlackAWSKubernetesThreat ModellingSecure Code ReviewAPI TestingSecurity PipelineAI Agentic WorkflowsLLM IntegrationsVendor Security AssessmentEDR XDROktaCloudflare AccessSSO SCIMCommunication

Qualifications

4–7 Years Information Security ExperienceBusiness Fluent EnglishSpanish or Portuguese

Full job description

About ARQ ARQ is one of the fastest-growing fintechs in the world. Our mission is to redefine how people interact with money across borders, building the infrastructure to move value seamlessly. We’re still early in our journey, which means every person who joins shapes the future of our product, culture, and growth. If you’re excited by big challenges, global impact, and the chance to grow fast with a world-class team, ARQ is the place to do it. What you'll do

  • Build and improve SIEM detection rules, alert pipelines, and automated response playbooks (Datadog SIEM, CrowdStrike, Cloudflare)

  • Contribute to incident response readiness, including IR playbooks, tabletop exercises, and forensic procedures

  • Support DLP strategy and data protection controls across Google Workspace, Slack, and internal tooling

  • Conduct cloud security assessments across AWS and Kubernetes environments

  • Drive application security initiatives: threat modelling, secure code review support, API testing, and security pipeline improvements

  • Assess and secure AI/agentic workflows across the company — reviewing prompts, preventing destructive actions, and controlling data exposure

  • Establish and run the vendor security assessment process — building a scalable due diligence framework for third-party onboarding

What you'll need

  • 4–7 years in information security, ideally having built or significantly shaped the security function at a startup or high-growth company - you've been the person who sets things up, not just maintains them

  • Hands-on experience with cloud infrastructure security (AWS, Kubernetes)

  • Working knowledge of SIEM platforms and detection engineering - you've written detection rules, not just consumed alerts

  • Familiarity with application security practices: threat modelling, secure code review, CI/CD pipeline hardening, and API security testing

  • Experience with endpoint security tooling (EDR/XDR) and identity & access management in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM)

  • Ability to assess and secure emerging AI/agentic tooling - you understand the risks of LLM integrations, MCP servers, and automated workflows, and can define practical guardrails

  • Experience running or contributing to vendor security assessments and third-party due diligence

  • Strong written and verbal communication

  • Business fluent in English; Spanish or Portuguese a plus

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.