Security Engineer, Senior at ARQ Finance answer
Is this job still open?
GMI Jobs is currently showing this Security Engineer, Senior role at ARQ Finance as an active listing from employer-controlled hiring sources. Always confirm final availability on the employer application page before applying.
How do I apply for this role?
Use the application link on this page to apply directly with ARQ Finance. GMI Jobs keeps the canonical job page, company context, and market links together so candidates can compare before leaving the site.
What should I compare before applying?
Compare the role location London, any listed pay signal, company profile, related crypto jobs, and salary context before applying. Listed pay signals are not guaranteed offers; confirm compensation with the employer.
Job Description
<h2>What We're Looking For</h2><p style="min-height:1.5em">You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one.</p><p style="min-height:1.5em">We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty.</p><p style="min-height:1.5em"></p><h2>What you'll do</h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Drive application security initiatives: threat modelling, secure code review support, API testing, and security pipeline improvements</p></li><li><p style="min-height:1.5em">Assess and secure AI/agentic workflows across the company — reviewing prompts, preventing destructive actions, and controlling data exposure</p></li><li><p style="min-height:1.5em">Build and improve SIEM detection rules, alert pipelines, and automated response playbooks (Datadog SIEM, CrowdStrike, Cloudflare)</p></li><li><p style="min-height:1.5em">Contribute to incident response readiness, including IR playbooks, tabletop exercises, and forensic procedures</p></li><li><p style="min-height:1.5em">Conduct cloud security assessments across AWS and Kubernetes environments</p></li><li><p style="min-height:1.5em">Establish and run the vendor security assessment process — building a scalable due diligence framework for third-party onboarding</p></li></ul><p style="min-height:1.5em"></p><h2>What you'll need</h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em">4–7 years in information security, ideally having built or significantly shaped the security function at a startup or high-growth company - you've been the person who sets things up, not just maintains them</p></li><li><p style="min-height:1.5em">2+ years at a regulated fintech/bank/payment company</p></li><li><p style="min-height:1.5em">Hands-on experience with cloud infrastructure security (AWS, Kubernetes)</p></li><li><p style="min-height:1.5em">Familiarity with application security practices: threat modelling, secure code review, CI/CD pipeline hardening, and API security testing</p></li><li><p style="min-height:1.5em">Ability to assess and secure emerging AI/agentic tooling - you understand the risks of LLM integrations, MCP servers, and automated workflows, and can define practical guardrails</p></li><li><p style="min-height:1.5em">Working knowledge of SIEM platforms and detection engineering - you've written detection rules</p></li><li><p style="min-height:1.5em">Experience with endpoint security tooling (EDR/XDR) and identity & access management in a SaaS-heav