Nomupay is hiring a Information Security Engineer to join our growing security team. This role will play a critical part in improving company’s security operations and strengthening cyber security posture across the organization.
What you'll be doing
- Design, implement, and manage security controls for cloud and infrastructure environments (AWS, Azure, GCP).
- Lead and maintain a vulnerability management program, including scanning, triaging, and remediation tracking.
- Ensure CI/CD pipelines follow best security practices and integrate security tooling (SAST, DAST, secrets detection).
- Develop and roll out a Secure Software Development Lifecycle (SDLC) across engineering teams.
- Act as a liaison with DevOps and development teams to align security objectives and meet security goals.
What we’re looking for
- 5+ years of experience in a SecOps, DevSecOps, or Cloud Security role.
- Strong knowledge of infrastructure as code, container security, and CI/CD security.
- Experience with vulnerability management tools (e.g., Tenable, Qualys).
- Familiarity with Secure SDLC frameworks (e.g., BSIMM, OWASP SAMM).
- Ability to collaborate effectively with cross-functional engineering and operations teams.
Additional skills (not essential)
- Cloud security certifications (AWS, Azure, GCP).
- Experience in fintech or payments industry.