# Security Engineer, Senior

[Arq](https://gurify.com/jobs?q=Arq) · London · Posted 8 weeks ago

Senior

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/arq/1117dac8-38ef-4083-b698-ba65e8bd6614)

## Job description

### WHAT WE'RE LOOKING FOR

You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one.

We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty.

### WHAT YOU'LL DO

- Drive application security initiatives: threat modelling, secure code review support, API testing, and security pipeline improvements

- Assess and secure AI/agentic workflows across the company — reviewing prompts, preventing destructive actions, and controlling data exposure

- Build and improve SIEM detection rules, alert pipelines, and automated response playbooks (Datadog SIEM, CrowdStrike, Cloudflare)

- Contribute to incident response readiness, including IR playbooks, tabletop exercises, and forensic procedures

- Conduct cloud security assessments across AWS and Kubernetes environments

- Establish and run the vendor security assessment process — building a scalable due diligence framework for third-party onboarding

### WHAT YOU'LL NEED

- 4–7 years in information security, ideally having built or significantly shaped the security function at a startup or high-growth company - you've been the person who sets things up, not just maintains them

- 2+ years at a regulated fintech/bank/payment company

- Hands-on experience with cloud infrastructure security (AWS, Kubernetes)

- Familiarity with application security practices: threat modelling, secure code review, CI/CD pipeline hardening, and API security testing

- Ability to assess and secure emerging AI/agentic tooling - you understand the risks of LLM integrations, MCP servers, and automated workflows, and can define practical guardrails

- Working knowledge of SIEM platforms and detection engineering - you've written detection rules

- Experience with endpoint security tooling (EDR/XDR) and identity & access management in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM)

- Experience running or contributing to vendor security assessments and third-party due diligence

- Strong written and verbal communication in English

### BENEFITS

- Competitive salary and benefits

- Stock options, so you own part of what you build

- Discretionary performance bonus

- The latest tools and technology

- A world-class team that will challenge and grow your skills

- The opportunity to help build the best fintech app in Latin America

- Office Policy: 3-4 days a week in-office

**Live in Arq’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- HA [Senior Security Engineer, Detection and Response](https://gurify.com/job/senior-security-engineer-detection-and-response-at-hackerone-45f09130ce13) Hackerone · London · last week
- CO [Security Engineer](https://gurify.com/job/security-engineer-at-conduct-354c5d006329) Conduct · London, United Kingdom · last week
- CO [Senior Cloud Native Security Engineer](https://gurify.com/job/senior-cloud-native-security-engineer-at-controlplane-1a80f4fea92c) Controlplane · London · 4 days ago
- MO [Senior Developer Experience Security Engineer](https://gurify.com/job/senior-developer-experience-security-engineer-at-motorway-8088847ce3c6) Motorway · London · 3 weeks ago
- CC [Cyber Security Engineer I](https://gurify.com/job/cyber-security-engineer-i-at-checkout-com-b3744d8ed0a5) Checkout Com · London · 2 weeks ago
- SM [Lead Security Engineer (DevSecOps & CISO)](https://gurify.com/job/lead-security-engineer-devsecops-ciso-at-smarkets-ac1914de51a4) Smarkets · London · 5 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Security Engineer, Senior","description":"\u003Ch3\u003EWHAT WE\u0026#39;RE LOOKING FOR\u003C/h3\u003E\u003Cp\u003EYou\u0026#39;ll be ARQ\u0026#39;s first Security Engineer based in Brazil \u2013 it\u0026#39;s the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You\u0026#39;ll work closely with our global security team but have real autonomy in deciding what \u0026quot;good\u0026quot; looks like locally, from day one.\u003C/p\u003E\u003Cp\u003EWe\u0026#39;re looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas \u2013 because in a founding role, there\u0026#39;s no one else to hand off the parts that don\u0026#39;t fit your specialty.\u003C/p\u003E\u003Ch3\u003EWHAT YOU\u0026#39;LL DO\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDrive application security initiatives: threat modelling, secure code review support, API testing, and security pipeline improvements\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAssess and secure AI/agentic workflows across the company \u2014 reviewing prompts, preventing destructive actions, and controlling data exposure\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild and improve SIEM detection rules, alert pipelines, and automated response playbooks (Datadog SIEM, CrowdStrike, Cloudflare)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContribute to incident response readiness, including IR playbooks, tabletop exercises, and forensic procedures\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EConduct cloud security assessments across AWS and Kubernetes environments\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEstablish and run the vendor security assessment process \u2014 building a scalable due diligence framework for third-party onboarding\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWHAT YOU\u0026#39;LL NEED\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E4\u20137 years in information security, ideally having built or significantly shaped the security function at a startup or high-growth company - you\u0026#39;ve been the person who sets things up, not just maintains them\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E2\u002B years at a regulated fintech/bank/payment company\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands-on experience with cloud infrastructure security (AWS, Kubernetes)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with application security practices: threat modelling, secure code review, CI/CD pipeline hardening, and API security testing\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to assess and secure emerging AI/agentic tooling - you understand the risks of LLM integrations, MCP servers, and automated workflows, and can define practical guardrails\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWorking knowledge of SIEM platforms and detection engineering - you\u0026#39;ve written detection rules\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with endpoint security tooling (EDR/XDR) and identity \u0026amp; access management in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience running or contributing to vendor security assessments and third-party due diligence\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong written and verbal communication in English\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EBENEFITS\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ECompetitive salary and benefits\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStock options, so you own part of what you build\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDiscretionary performance bonus\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThe latest tools and technology\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA world-class team that will challenge and grow your skills\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThe opportunity to help build the best fintech app in Latin America\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOffice Policy: 3-4 days a week in-office\u003C/li\u003E\u003C/ul\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"security-engineer-senior-at-arq-d05202ebd0e3"},"url":"https://gurify.com/job/security-engineer-senior-at-arq-d05202ebd0e3","datePosted":"2026-07-22","validThrough":"2026-11-02T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Arq","sameAs":"https://jobs.ashbyhq.com/arq"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Security Engineer, Senior","item":"https://gurify.com/job/security-engineer-senior-at-arq-d05202ebd0e3"}]}
```
