Senior Cloud Security Engineer
Delta Exchange · 23 hours ago
About the Company
At Delta, we are re-imagining and re-building the financial system. Join our team to make a positive impact on the future of finance.
🎯 Mission Driven: Re-imagine and re-build the future of finance.
💡 Most innovative cryptocurrency derivatives exchange. With a daily traded volume of ~$0.5billion, and increasing. Delta is bigger than all the Indian crypto exchanges combined.
📈 Offer the widest range of derivative products and have been serving traders all over the globe since 2018 and growing fast.
💪🏻 The founding team is comprised of IIT and ISB graduates. Business co-founders have previously worked with Citibank, UBS and GIC; and our tech co-founder is a serial entrepreneur who previously co-founded TinyOwl and Housing.com.
💰 Funded by top crypto funds (Sino Global Capital, CoinFund, Gumi Cryptos) and crypto projects (Aave and Kyber Network).
About the role
You'll be the dedicated security engineer at a derivative exchange (~250 people, 50-100 person dev team). All infra is AWS. DevOps builds it; you make sure it's secure and can prove it. You'll be hands-on — reviewing Terraform PRs for security gaps, building automated drift detection, writing SIEM rules, and owning the credential lifecycle. When the CTO asks, "Are we secure?" you pull up a dashboard, not a slide deck. You own the security posture of the infrastructure from shaping how access and controls are modelled, to verifying they hold in practice.
What you'll do
-
Verify that infra implementations match the security model — continuously, not quarterly.
-
Build automated compliance checks and drift detection (AWS Config, Steampipe, custom tooling, whatever works)
-
Review Terraform PRs for IAM, SCP, and network security gaps before they hit production.
-
Own credential lifecycle: rotation, PAM, JIT access, session recording.
-
Write and tune detection rules in OpenSearch SIEM.
-
Build evidence dashboards that prove security posture to non-security leadership 7. Evaluate security tooling (build vs buy) and own the recommendation with documented tradeoffs.
Must-haves
-
5+ years in infrastructure or security engineering, with at least 2 years focused on AWS security
-
IAM beyond basic roles — you understand policy evaluation logic, permission boundaries, cross-account access patterns
-
Have built automated security checks that run in production (any tooling)
-
Can read and critically review Terraform for security posture
-
Have operated PAM tooling or credential rotation in production (any tool)
-
Comfortable owning a security domain end-to-end without constant direction
Strong advantages
- Worked at an org < 500 people where you were one of the very few (or the only) security engineers
- Multi-account AWS Organizations / SCP experience. Wrote SIEM detection rules in production (any platform — OpenSearch, Splunk, Elastic, etc.)
- Regulated fintech, exchange, or payments background.
- Built security evidence/reporting that non-security people actually used.