Build and maintain TypeScript/JavaScript API-based ETL pipelines that connect financial institutions, manage OAuth2 authorizations, and deliver reliable data for a fintech platform.
About this role
This senior security and compliance role supports Moneytree’s fintech, open-banking and financial-data products. Alongside a Senior Security Engineer, it owns the examination surface for parent-group governance, enterprise client reviews, ISO 27001 and internal risk review; the engineering partner owns controls, remediation and incident response.
Responsibilities cover client security assessments; coordinating penetration, threat-led and vulnerability testing; threat modelling; operational risk treatment and monitoring; audit support; and maintaining the Statement of Applicability, risk, asset and incident registers. Vendor and software approvals, including AI-tool requests, use AI-assisted search and drafting with human review, Jira and Confluence.
Applicants need 5+ years in GRC, information security compliance, IT audit or third-party risk, including Japanese financial-services experience. They must have owned a client security assessment or vendor due-diligence process end to end, know ISO 27001 and a major framework such as NIST CSF or NIST SP 800-53.
This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.