DriveWealth
Head of Security Engineering
Austin, Texas, United States · Dallas, Texas, United States · Denver, Colorado, United States · Miami, Florida, United States · Office - Chicago · Office - NYC · San Francisco, California, United States · Seattle, Washington, United States
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Lead / management
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 2 Oct 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
About Us
DriveWealth is on a mission to make investing easier. We believe that everyone should have the ability to control their financial future, and that access to financial markets should not be limited by geography, wealth, or legacy systems. We are a global B2B financial technology organization dedicated to democratizing access to financial independence around the world. Our mission is realized through an API-based platform, empowering our partners to offer seamless investing and trading experiences to clients worldwide, all from their mobile devices. Our technology provides partners with a modern, extensible toolkit, enabling traditional investment workflows and innovative techniques like fractional share ownership. DriveWealth has evolved into a global platform offering trading of US equities, mutual funds, ETFs, fixed income, and options.
There’s never been a better time to build a category-defining business and there has rarely been a team better positioned for this opportunity. Our culture blends the pace and agility of a fintech start-up with the impact, stability, and discipline of Wall Street. We encourage creativity and experimentation while ensuring institutional-grade execution and regulatory compliance in everything we do. Join us and help build the future of global investing!
About the Role
DriveWealth LLC is seeking a highly motivated and seasoned Head of Security Engineering to own the security engineering strategy, roadmap, and delivery across our product platform and corporate environment. Reporting to the Chief Information Security Officer, you will build and lead the Security Engineering team, define its strategy and roadmap, and deliver improvements that support the security of customer data, the firm’s growth, and regulatory obligations.
In this leadership role, you will provide both expert guidance on security and security capability implementation across our AWS platform, Kubernetes services, low-latency trading infrastructure, and corporate technology. This role is focused on building and maturing the Security Engineering function and we are seeking a leader who combines strategic thinking with hands-on engineering experience to establish scalable controls and enable product innovation. You will also lead the development and maintenance of infrastructure, services, and automation for Security Operations, partnering with Engineering, IT, Risk, and Compliance within an innovative and entrepreneurial culture.
What You’ll Do
Strategy & Team Leadership
Roadmap Ownership: Define and deliver a multiyear security engineering strategy and quarterly roadmap across product and corporate environments, aligning architecture standards and investments with business priorities and risk appetite.
Team Leadership: Hire, coach, and develop a team of high-performing security engineers, manage performance, and build technical depth as the team scales.
Delivery & Risk Management: Manage backlogs, budgets, vendors, and dependencies. Work with Security GRC to measure control effectiveness and delivery. Communicate progress, tradeoffs, and residual risks to the CISO and technology leaders.
Product & Corporate Security
Product Security: Embed threat modeling, architecture reviews, security testing, and secure design into development and CI/CD, strengthening API authentication, authorization, data isolation, and secrets management.
Infrastructure Security: Secure AWS, including services such as EKS, EC2, DynamoDB, as well as co-located trading infrastructure through least privilege, segmentation, encryption, hardening, and automated guardrails, accounting for availability, recovery, and latency requirements.
Corporate Security: Partner with IT to mature identity, access governance, endpoint, remote access, DLP, communications, and SaaS security across the corporate service estate, including phishing-resistant authentication, device compliance, and data protection.
Exposure Management: Build scanning and remediation capabilities across cloud and on-premises environments, code, dependencies, containers, and infrastructure. Partner with Engineering and IT to prioritize fixes and prevent recurring vulnerabilities and other types of exposures.
Security Operations Enablement
Security Platforms: Build, integrate, and maintain the infrastructure and services used for monitoring, investigation, exposure management, and response, including SIEM, SOAR, and endpoint security platforms.
Telemetry Engineering: Own security data pipelines across product and corporate systems, ensuring coverage, quality, enrichment, availability, appropriate retention, and documented maintenance and support procedures.
Operational Partnership: Deliver detection and response automation with Security Operations, provide incident engineering support, and implement lasting improvements. Security Operations retains day-to-day ownership of monitoring, triage, and response.
Investigation & Response Support: Provide Security Operations with necessary expertise and support during security investigations and incident response activities.
Compliance & Assurance
Regulatory Controls: Partner with Legal, Compliance, and GRC to implement SEC and FINRA requirements, including SEC Rule 17a-4 controls supporting record capture, preservation, integrity, access, and retrieval. Partner with Security GRC to align the Security Engineering roadmap to regulatory requirements and other necessary compliance controls and activities, such as SOC 2 Type 2 auditing.
Data Security & Privacy: Build and maintain capabilities for data discovery, classification, access control, encryption, retention, and secure deletion to support GDPR and other applicable privacy and data protection requirements.
Control Assurance: Automate control validation and evidence collection. Support audits and regulatory examinations, and drive remediation of technical findings.
You Bring
10+ years of relevant security, software, or infrastructure engineering experience, including 4+ years directly managing technical teams.
Demonstrated success owning a security engineering roadmap and delivering measurable improvements across production and corporate environments.
Expertise in AWS and Kubernetes security, with practical experience securing APIs and modern software delivery pipelines.
Strong working knowledge of identity and access management, macOS and Windows endpoint security, remote access/SASE, network security, and SaaS security. Experience with Okta, JumpCloud, or comparable platforms.
Experience building and maintaining security platforms, telemetry pipelines, and automation used by security operations teams.
Ability to review code and infrastructure changes and contribute engineering solutions using Python, Java, or a comparable language and infrastructure-as-code tools such as Terraform.
Sound judgment balancing security, reliability, developer productivity, and cost.
Ability to influence technical decisions and communicate clearly with executives, engineers, and business partners.
Experience delivering security capabilities in regulated financial services or another environment with demanding availability, data protection, and audit requirements. Brokerage, trading infrastructure, and SEC/FINRA experience are preferred.
Bachelor’s degree in a related field or equivalent practical experience. Relevant security, AWS, or Kubernetes certifications are a plus.
Location
This role is open to candidates in the following locations: New York City or Chicago - Hybrid. Austin, Dallas, Denver, Miami, San Francisco Bay Area, or Seattle - Remote.
If based in New York or Chicago: This role is expected to come into the office on a cadence set by the Hiring Manager/Team.
If based in Austin, Dallas, Denver, Miami, San Francisco, or Seattle: This is a fully remote role, though you may need to visit our onsite offices from time to tim
Similar jobs
- Senior Technical Program Manager, ADC Security EngineeringAmazon · Arlington, Virginia, USA; Denver, Colorado, USA; Herndon, Virginia, USAFirst seen yesterday
- Manager, Security Engineering, Production SecuritySnapchat · 2 LocationsFirst seen 2d ago
- Manager, Security Engineering, Production SecuritySnapchat · 2 LocationsFirst seen 2d ago
- Cloud Security Engineering ManagerVanguard · 3 LocationsFirst seen 2d ago
- Senior Lead, Security Engineering and OperationsNtrs · Chicago, ILFirst seen 3d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job