Senior Cloud Security Engineer - InfoSec
WFA Digital Insight
Mercury’s Senior Cloud Security Engineer role reads like a backstage pass to the invisible infrastructure that lets fintech products feel effortless. The team is looking for someone who will shape the AWS environment with a zero‑trust mindset, build automated guardrails, and translate compliance frameworks into code. What sets this opening apart is the blend of hands‑on security engineering and cross‑team collaboration—working with infrastructure, product, and remote‑access groups to keep the platform resilient while engineers move fast. Candidates should be comfortable with NIST, SOC2, and other fintech‑specific regulations, and ready to push the envelope on IaC tooling. Expect to influence the security posture from day one, not just follow a checklist.
Job Description
Medieval cathedral builders understood that the flying buttress wasn't the building. Visitors came to admire the stained glass and soaring ceilings, not the stone supports outside. But without those supports, none of the beauty could stand.
Cloud security plays a similar role at Mercury. Our customers come for products that feel remarkably simple. Behind that simplicity is an infrastructure that quietly protects billions of dollars, preserves customer trust, and gives engineers the confidence to move quickly. We're looking for a Cloud Security Engineer who enjoys building those invisible supports.
Protecting our customers’ security and privacy is a top priority. We're all about using the latest technology to do things smarter. That's why we need a Cloud Security Engineer. This person will be our go-to for designing the systems, guardrails, and automation that allow Mercury to scale without compromising security or slowing down engineering. The ideal candidate should be ready and willing to come up with innovative solutions leveraging the newest technologies to address the unique problems they encounter. We work with teams across the enterprise to solve security, privacy, and compliance challenges so be ready to collaborate.
Come be a part of helping us stay safe and maintain trust with our customers!
As we gear up for the next stages of Mercury's growth, you will:
- Help build and define cloud security posture. Enable cyber resilience. Help with zero trust initiatives.
- Have an understanding of Governance, Risk and Compliance as it relates to cloud engineering
- Work with the infrastructure and other engineering teams to improve the overall reliability and security of our cloud infrastructure
- Automate cloud security controls to ensure threats, vulnerabilities, and risk are minimized
- Shape Mercury's AWS cloud architecture around resilience, least privilege, and long-term maintainability
- Work with teams throughout Mercury to address remote access challenges in a remote-first environment
- Work with teams and stakeholders throughout Mercury to address security concerns in the cloud.
The ideal candidate should have:
- 5+ years relevant experience in cloud security, networking, information security, or other relevant fields.
- A strong desire to learn and grow and proven track record of doing so.
- Familiarity with standard security frameworks and privacy regulations (NIST CSF, FFIEC, SOX, SOC2, GLBA, ISO27018, PCI-DSS, etc.)
- Deep problem-solving and analytical skills, and poise and ability to act calmly and competently in high-pressure, high-stress situations.
- A fundamental understanding of accepted security practices, troubleshooting issues, attack vectors, and customer support.
- Familiarity with information as code (IaC) tooling.
- AWS certifications are encouraged.
If this role interests you, we invite you to explore our public demo at demo.mercury.com.
*Mercury is a fintech company, not an FDIC-insured bank. Banking services provided through Choice Financial Group and Column N.A., Members FDIC.
Mercury values diversity & belonging and is proud to be an Equal Employment Opportunity employer. All individuals seeking employment at Mercury are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, sexual orientation, or any other legally protected characteristic. We are committed to providing reasonable accommodations throughout the recruitment process for applicants with disabilities or special needs. If you need assistance, or an accommodation, please let your recruiter know once you are contacted about a role.
#LI-ME1
Total Rewards
The total rewards package at Mercury includes base salary, equity (stock options/RSUs), and benefits.
Our salary and equity ranges are highly competitive within the SaaS and fintech industry and are updated regularly using the most reliable compensation survey data for our industry. New hire offers are made based on a candidate’s experience, expertise, geographic location, and internal pay equity relative to peers.
Our target new hire base salary ranges for this role are the following:
How to Stand Out
- Highlight concrete examples where you automated security controls with IaC; include snippets or repo links in your resume.
- Prepare to discuss how you’ve applied NIST or SOC2 frameworks in real cloud environments, focusing on outcomes.
- Demonstrate familiarity with zero‑trust concepts; be ready to outline a simple remote‑access security design.
- If you have AWS certifications, list them prominently; they signal the depth of cloud expertise the team values.
- During interviews, emphasize calm decision‑making under pressure by describing a specific incident response you led.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.