Senior IT Security Engineer
LemFi
About our Company
LemFi (YC S21, Series B) is revolutionising cross-border financial services for immigrants through its multi-currency platform, processing over $1 billion in monthly transactions. We provide instant remittances, foreign exchange services, and multi-currency accounts, all in one seamless experience.
With 300+ employees across 15+ countries, we’ve secured our Series B funding from top investors like Highland Europe, Left Lane Capital, and Y Combinator.
Our vision: To build the first full-stack financial services hub for the world’s immigrant population. 🚀
Who you are
Join a fast-growing, multinational fintech start-up where security, resilience, and trust are central to everything we build. You are impact-oriented, focused on protecting customer data, strengthening regulatory trust, and delivering measurable improvements such as fewer incidents and faster detection. You collaborate naturally with Engineering, Cloud, Risk, and Compliance, communicating clearly and working effectively in a distributed team. You take ownership of our security posture—from infrastructure hardening to audit readiness—acting proactively, responding quickly, and continuously improving. You’re always looking for ways to automate, streamline reporting, and enhance visibility, understanding that strong security is built on iteration and transparency.
Job Summary
Our Security Engineering team ensures that our infrastructure, processes, and controls meet the highest standards, from AWS configuration to compliance with DORA, SOC 2, PCI DSS, and ISO 27001. We’re seeking a Senior Security Engineer to strengthen our cloud security posture, improve visibility through SIEM and automation, and maintain compliance with evolving EU and Irish regulations. In this hands-on role, you will work across AWS, tooling, and governance to translate regulatory requirements into practical, measurable security improvements.
Responsibilities are as follows:
- Manage and enhance AWS security, including IAM, network segmentation, key management, and logging.
- Configure and maintain SIEM, vulnerability scanners, IDS/IPS, and endpoint protection.
- Build monitoring and alerting for critical systems and embed security into CI/CD workflows.
- Harden infrastructure and ensure compliance with ISO 27001, PCI DSS, and DORA.
- Prepare regulatory reports, coordinate audit evidence, and support inspections.
- Translate regulatory requirements into actionable controls and maintain security documentation.
- Operate and tune SIEM to detect suspicious activity; lead incident triage and post-incident reviews.
- Maintain incident, vulnerability, and threat intelligence playbooks; improve first-line detection through training.
- Align security strategy with Risk, Compliance, and IT; provide metrics for executive reporting.
- Coordinate cross-entity policies and advise on third-party/vendor compliance with DORA and PCI DSS.
Requirements:
- 5+ years in Security Engineering, Cloud Security, or Infrastructure Security roles within AWS environments.
- Deep understanding of AWS security services (IAM, KMS, CloudHSM, Security Hub, CloudTrail, etc.).
- Hands-on experience with SIEM platforms and cloud/endpoint telemetry integration.
- Strong knowledge of vulnerability management, incident response, and security monitoring.
- Familiarity with financial-sector compliance frameworks (DORA, PCI DSS, ISO 27001, NIST CSF).
- Experience preparing security reports and technical evidence for regulators or auditors (e.g., CBI, PCI QSA).
- Practical experience with Infrastructure-as-Code (Terraform) and CI/CD security integration.
- Competence in scripting and automation (Python, Bash, or similar) to improve detection, response, and reporting.
- Strong ownership and accountability; able to work independently and collaborate across Security, Engineering, and Compliance.
- Excellent communication skills, able to explain complex security topics to non-technical stakeholders and regulators.
- Analytical, structured problem-solver focused on continuous improvement and operational resilience.
- Pragmatic approach balancing security rigor with business agility and delivery speed.
Desirables:
- Experience working in regulated financial or payments institutions (EMI, PSP, or banking).
- Hands-on involvement in DORA, PCI DSS, or ISO 27001 audits and gap assessments.
- Familiarity with governance, risk, and compliance tools (e.g., SecureFrame, Drata, or similar).
- Experience mentoring junior security engineers or leading cross-functional security initiatives.