About this Head of Security Engineering role at DriveWealth
About Us
DriveWealth is on a mission to make investing easier. We believe that everyone should have the ability to control their financial future, and that access to financial markets should not be limited by geography, wealth, or legacy systems. We are a global B2B financial technology organization dedicated to democratizing access to financial independence around the world. Our mission is realized through an API-based platform, empowering our partners to offer seamless investing and trading experiences to clients worldwide, all from their mobile devices. Our technology provides partners with a modern, extensible toolkit, enabling traditional investment workflows and innovative techniques like fractional share ownership. DriveWealth has evolved into a global platform offering trading of US equities, mutual funds, ETFs, fixed income, and options.
There’s never been a better time to build a category-defining business and there has rarely been a team better positioned for this opportunity. Our culture blends the pace and agility of a fintech start-up with the impact, stability, and discipline of Wall Street. We encourage creativity and experimentation while ensuring institutional-grade execution and regulatory compliance in everything we do. Join us and help build the future of global investing!
About the Role
DriveWealth LLC is seeking a highly motivated and seasoned Head of Security Engineering to own the
security engineering strategy, roadmap, and delivery across our product platform and corporate environment.
Reporting to the Chief Information Security Officer, you will build and lead the Security Engineering team,
define its strategy and roadmap, and deliver improvements that support the security of customer data, the
firm’s growth, and regulatory obligations.
In this leadership role, you will provide both expert guidance on security and security capability
implementation across our AWS platform, Kubernetes services, low-latency trading infrastructure, and
corporate technology. This role is focused on building and maturing the Security Engineering function and we
are seeking a leader who combines strategic thinking with hands-on engineering experience to establish
scalable controls and enable product innovation. You will also lead the development and maintenance of
infrastructure, services, and automation for Security Operations, partnering with Engineering, IT, Risk, and
Compliance within an innovative and entrepreneurial culture.
What You’ll Do
What You’ll Do
Strategy & Team Leadership
- Roadmap Ownership: Define and deliver a multiyear security engineering strategy and quarterly roadmap across product and corporate environments, aligning architecture standards and investments with business priorities and risk appetite.
- Team Leadership: Hire, coach, and develop a team of high-performing security engineers, manage performance, and build technical depth as the team scales.
- Delivery & Risk Management: Manage backlogs, budgets, vendors, and dependencies. Work with Security GRC to measure control effectiveness and delivery. Communicate progress, tradeoffs, and residual risks to the CISO and technology leaders.
Product & Corporate Security
- Product Security: Embed threat modeling, architecture reviews, security testing, and secure design into development and CI/CD, strengthening API authentication, authorization, data isolation, and secrets management.
- Infrastructure Security: Secure AWS, including services such as EKS, EC2, DynamoDB, as well as co-located trading infrastructure through least privilege, segmentation, encryption, hardening, and automated guardrails, accounting for availability, recovery, and latency requirements.
- Corporate Security: Partner with IT to mature identity, access governance, endpoint, remote access, DLP, communications, and SaaS security across the corporate service estate, including phishing-resistant authentication, device compliance, and data protection.
- Exposure Management: Build scanning and remediation capabilities across cloud and on-premises environments, code, dependencies, containers, and infrastructure. Partner with Engineering and IT to prioritize fixes and prevent recurring vulnerabilities and other types of exposures.
Security Operations Enablement
- Security Platforms: Build, integrate, and maintain the infrastructure and services used for monitoring, investigation, exposure management, and response, including SIEM, SOAR, and endpoint security platforms.
- Telemetry Engineering: Own security data pipelines across product and corporate systems, ensuring coverage, quality, enrichment, availability, appropriate retention, and documented maintenance and support procedures.
- Operational Partnership: Deliver detection and response automation with Security Operations, provide incident engineering support, and implement lasting improvements. Security Operations retains day-to-day ownership of monitoring, triage, and response.
- Investigation & Response Support: Provide Security Operations with necessary expertise and support during security investigations and incident response activities.
Compliance & Assurance
- Regulatory Controls: Partner with Legal, Compliance, and GRC to implement SEC and FINRA requirements, including SEC Rule 17a-4 controls supporting record capture, preservation, integrity, access, and retrieval. Partner with Security GRC to align the Security Engineering roadmap to regulatory requirements and other necessary compliance controls and activities, such as SOC 2 Type 2 auditing.
- Data Security & Privacy: Build and maintain capabilities for data discovery, classification, access control, encryption, retention, and secure deletion to support GDPR and other applicable privacy and data protection requirements.
- Control Assurance: Automate control validation and evidence collection. Support audits and regulatory examinations, and drive remediation of technical findings.
You Bring
- 10+ years of relevant security, software, or infrastructure engineering experience, including 4+ years directly managing technical teams.
- Demonstrated success owning a security engineering roadmap and delivering measurable improvements across production and corporate environments.
- Expertise in AWS and Kubernetes security, with practical experience securing APIs and modern software delivery pipelines.
- Strong working knowledge of identity and access management, macOS and Windows endpoint security, remote access/SASE, network security, and SaaS security. Experience with Okta, JumpCloud, or comparable platforms.
- Experience building and maintaining security platforms, telemetry pipelines, and automation used by security operations teams.
- Ability to review code and infrastructure changes and contribute engineering solutions using Python, Java, or a comparable language and infrastructure-as-code tools such as Terraform.
- Sound judgment balancing security, reliability, developer productivity, and cost.
- Ability to influence technical decisions and communicate clearly with executives, engineers, and business partners.
- Experience delivering security capabilities in regulated financial services or another environment with demanding availability, data protection, and audit requirements. Brokerage, trading infrastructure, and SEC/FINRA experience are preferred.
- Bachelor’s degree in a related field or equivalent practical experience. Relevant security, AWS, or Kubernetes certifications are a plus.
Special Knowledge (Nice to Have, But Not Required)
[Ctrl/⌘-V to paste with formatting/bullets]
Location
This role is open to candidates in the following locations: New York City, Chicago, Austin, Dallas, Denver, Miami, San Francisco Bay Area, or Seattle.
- If based in New York or Chicago: This role is expected to come into the office on a cadence set by the Hiring Manager/Team.
- If based in Austin, Dallas, Denver, Miami, San Francisco, or Seattle: This is a fully remote role, though you may need to visit our onsite offices from time to time.
- If you're not based in one of the locations listed above, this role is not a fit, and we cannot accommodate remote work outside these locations.
- Applicants must be authorized to work for any employer in the U.S. DriveWealth does not sponsor or take over sponsorship of an employment visa at this time.
Pay Range: $220,000 – $250,000 USD
Working at DriveWealth
We do our best work when we're in the same room. To maintain the speed our partners expect, our New York, Chicago, and Lithuania teams work in office on a hybrid schedule. We've found that being physically side-by-side is the only way to solve complex problems in real-time and stay truly accountable to the products we ship. When you're here, you're working directly with the people making the decisions.
To support that work, we provide competitive compensation, equity, and a 401(k) match. We also offer Medical insurance, Dental insurance, Vision insurance, Disability insurance, and Paid Parental Leave, along with a wellness reimbursement, a company-provided phone, and a personal development allowance. Finally, we value the time you spend away from the office with generous Paid Time Off (PTO) and observed holidays.
Work Authorization
Applicants must possess the legal right to work in the country where the position is located at the time of application. DriveWealth requires all employees to provide original documentation verifying their work authorization on or before their first day of employment.
For US-based roles: Applicants must be currently authorized to work in the United States on a full-time basis without the need for current or future visa sponsorship. DriveWealth does not provide visa sponsorship or support for employment authorization, including transfers, at this time. Offers of employment are strictly contingent upon an individual’s ability to secure and maintain the legal right to work at the Company.
How We Think About AI
We leverage AI to work smarter and move faster. We seek AI-curious talent who are proactive about using emerging tools to increase signal quality, reduce friction, and improve outcomes to deliver products faster, provide better service to our partners, and to streamline processes. Your ability to leverage our internal tools and technology to drive results is as important to us as your core domain expertise.
Compensation
Pay is generally based on the level, complexity, responsibility, location, and job duties/requirements of the specific position. We then source candidates with the requisite skills, expertise, education, training, and experience. If you are selected for an interview, please feel welcome to speak to a recruiter about our compensation philosophy and other available benefits. This role is eligible for base, bonus, equity, 401(k) match, and heavily subsidized benefits and perks.
Equal Employment Opportunity
To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply.
Agency Disclaimer
DriveWealth does not accept agency resumes. Do not forward resumes to our jobs alias, employees, or any other organization location. DriveWealth is not responsible for any fees related to unsolicited resumes.