Senior SecOps Engineer

Remote-US /
Technology /
Full-time
About Tala

Tala is a global technology company building the world’s most accessible financial services. With more than $350 million raised from visionary investors, we are serving millions of customers around the world who have been overlooked by traditional financial institutions – and our plan is to serve millions more, and have been named by the Fortune Impact 20 list, CNBC’s Disruptor 50, and Forbes’ Fintech 50 list for four years running. We are expanding across product offerings, countries and crypto and are looking for people who have an entrepreneurial spirit and are passionate about the mission.

By creating a unique platform that enables lending and other financial services around the globe, people in emerging markets are able to start and expand small businesses, manage day-to-day needs, and pursue their financial goals with confidence. Currently, more than 6 million people across Kenya, the Philippines, Mexico, and India have used Tala products. Due to our global team, we have a remote-first approach, and also have offices in Santa Monica, CA (HQ); Nairobi, Kenya; Mexico City, Mexico; Manila, the Philippines; and Bangalore, India. 

Most Talazens join us because they connect with our mission of enabling financial agency for underbanked people around the world. If you are energized by the impact you can make at Tala, we’d love to hear from you!

We are currently seeking a Sr Secops Engineer to design, implement and maintain suitable infrastructure and application security solutions on AWS and GCP public cloud environments using DevSecOps mindset. You will bring world class cloud-native security expertise to implement solutions for security configuration hardening, vulnerability management, detection, protection and monitoring of security threats and intrusions, in an automated fashion. 

What you'll do:

    • Driving the design and implementation of defense-in-depth infrastructure and application security solutions for our customer facing SaaS platform in AWS & GCP public cloud environments
    • Driving architecture, implementation, configuration and automation of native and third party cloud security solutions for hardening, detection, prevention, logging and response solutions for security vulnerabilities and threats
    • Provide thought leadership with a security bent of mind to the organization
    • Working closely with Product, Engineering and IT in a DevSecOps model on technologies like FWs, ACLs, WAFs, IAM roles and permissions, Vulnerability management and hardening, Threat and Intrusion detection, Kubernetes Container Security solutions
    • Assisting in incident response and triaging activities as needed for security incidents and events

Qualifications:

    • B.S. Degree in Computer Science or related field or equivalent combination of professional development training and experience
    • 5-7 years of previous experience deploying and administering security infrastructure in GCP or AWS public cloud environments, using Infrastructure as Code required
    • In-depth hands-on experience with at least one public Cloud platform (AWS or GCP) with advanced knowledge of securing IaaS platforms and services like WAFs, Security Groups, EC2/Compute, EKS/GKE, ECR/GCR, S3/Cloud Storage, RDS/Cloud SQL, Logging and Monitoring
    • Prior experience working closely with Product, DevOps and CloudOps' Site Reliability Engineers on shift-left strategies, CI/CD tools and solutions needed
    • Security experience in a cloud native environment in one or more areas: authentication, access management, API security, Linux security, vulnerability scanning, threat and intrusion detection, firewalls, WAF, encryption technologies, container security etc.
    • Experience using a programming language such as Python for automation (would be a plus)
    • Security certifications such as AWS, GCP , CISSP, CEH, OSCP preferred
    • Excellent verbal and written communication skills and ability to document and explain technical details and concepts clearly and concisely
    • Agility and willingness to deal with a high level of ambiguity, change, and pressures of high-profile incidents
    • Flexibility to pitch in where needed across program and team
    • Strong influence and teamwork skills; sound problem resolution, judgment, negotiating, and decision-making skills
    • Strong knowledge of industry standards, vulnerability classifications, and attack vectors
    • Experience working effectively with global teams in multiple time zones

Our vision is to build a new financial ecosystem where everyone can participate on equal footing and access the tools they need to be financially healthy. We strongly believe that inclusion fosters innovation and we’re proud to have a diverse global team that represents a multitude of backgrounds, cultures, and experience. We hire talented people regardless of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status.