# Senior Cloud Security Engineer

**Company:** [Delta Exchange](http://jobs.workable.com/companies/jKC28Cknr2vYKDeDjCDCA4.md)
**Location:** Remote
**Workplace:** remote

[Apply for this job](http://jobs.workable.com/view/7dbaa134-9a99-4954-a005-3da1ae3771f5)

## Description

About the Company

At Delta, we are re-imagining and re-building the financial system. Join our team to make a positive impact on the future of finance.

🎯 Mission Driven: Re-imagine and re-build the future of finance.

💡 Most innovative cryptocurrency derivatives exchange. With a daily traded volume of ~$0.5billion, and increasing. Delta is bigger than all the Indian crypto exchanges combined.

📈 Offer the widest range of derivative products and have been serving traders all over the globe since 2018 and growing fast.

💪🏻 The founding team is comprised of IIT and ISB graduates. Business co-founders have previously worked with Citibank, UBS and GIC; and our tech co-founder is a serial entrepreneur who previously co-founded TinyOwl and [Housing.com](http://housing.com).

💰 Funded by top crypto funds (Sino Global Capital, CoinFund, Gumi Cryptos) and crypto projects (Aave and Kyber Network).  
  
About the role  
  
You'll be the dedicated security engineer at a derivative exchange (~250 people, 50-100 person dev team). All infra is AWS. DevOps builds it; you make sure it's secure and can prove it.  You'll be hands-on — reviewing Terraform PRs for security gaps, building automated drift detection, writing SIEM rules, and owning the credential lifecycle. When the CTO asks, "Are we secure?" you pull up a dashboard, not a slide deck. You own the security posture of the infrastructure from shaping how access and controls are modelled, to verifying they hold in practice.  
  
  
  
What you'll do  

-   Verify that infra implementations match the security model — continuously, not quarterly.
-   Build automated compliance checks and drift detection (AWS Config, Steampipe, custom tooling, whatever works)
-   Review Terraform PRs for IAM, SCP, and network security gaps before they hit production.
-   Own credential lifecycle: rotation, PAM, JIT access, session recording.
-   Write and tune detection rules in OpenSearch SIEM.
-   Build evidence dashboards that prove security posture to non-security leadership 7. Evaluate security tooling (build vs buy) and own the recommendation with documented tradeoffs.  
      
    Must-haves  
      
    

-   5+ years in infrastructure or security engineering, with at least 2 years focused on AWS security
-   IAM beyond basic roles — you understand policy evaluation logic, permission boundaries, cross-account access patterns
-   Have built automated security checks that run in production (any tooling)
-   Can read and critically review Terraform for security posture
-   Have operated PAM tooling or credential rotation in production (any tool)
-   Comfortable owning a security domain end-to-end without constant direction

  
      Strong advantages

-   Worked at an org < 500 people where you were one of the very few (or the only) security engineers
-   Multi-account AWS Organizations / SCP experience. Wrote SIEM detection rules in production (any platform — OpenSearch, Splunk, Elastic, etc.)
-   Regulated fintech, exchange, or payments background. 
-   Built security evidence/reporting that non-security people actually used.
