Lumin Digital's Security Engineering team is a true engineering organization that protects a cloud-hosted digital banking platform serving financial institutions and their members. As a Cybersecurity Engineer, you will build software and infrastructure that heals itself, automatically enforces controls at scale, and converges on correct operation across hundreds of environments. Your scope includes the lifecycle of our cryptographic material and the architecture of our security telemetry. You will work in AI-assisted engineering tools every day: agentic coding assistants like Claude Code, MCP-based integrations, and custom agent harnesses. This role exists for engineers fluent in AI tools who have something to teach the rest of us about working with them. Success means our security infrastructure doesn't go bump in the night.
🏢 About Lumin Digital
Lumin Digital is a company that provides a cloud-hosted digital banking platform for financial institutions and their members. The company emphasizes engineering excellence and innovation in security practices.
🎯 The Role
As a Cybersecurity Engineer at Lumin Digital, you will be responsible for building and maintaining the security infrastructure that the rest of the company depends on. This includes working with AWS and Kubernetes, developing agentic AI workflows, managing cryptographic material lifecycle, and ensuring compliance automation across hundreds of environments.
✅ Key Responsibilities
Engineer the security infrastructure across AWS and Kubernetes: telemetry pipelines, cryptographic material lifecycle, compliance automation, and architecture patterns that scale across hundreds of environments.
Build and maintain agentic AI workflows using tools like Claude Code, MCP-based integrations, and custom agent harnesses to automate security engineering tasks.
Engineer the lifecycle of cryptographic material as code, including key generation, secure storage, certificate issuance, rotation, and revocation.
Build security telemetry pipelines that detect, enrich, and route signals with the fidelity our auto-remediation systems require.
Embed security controls into deployment pipelines so vulnerabilities are prevented or resolved at build time rather than discovered post-deployment.
Build compliance evidence collection and continuous control monitoring as engineered systems that produce auditor-ready outputs from continuous data flows.
Develop and maintain threat models that inform security architecture decisions and prioritize where engineered controls earn their place.
Consult, review, and approve architectural decisions by other infrastructure and product teams for security compliance and outcomes.
Provide engineering support to Security Operations during incident response: build the tooling, telemetry, and automation that aids detection, containment, and recovery.
Partner with other Risk functions, technical teams, auditors, vendors, and clients to translate security requirements into engineered systems and validate posture across all environments.
Evaluate emerging AI-assisted engineering patterns and tooling through proof-of-concept work.
Operate our COTS security tooling when needed, usually through IaC and automation we've built ourselves.
📌 Required Qualifications
Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or a related field, or equivalent combination of demonstrated engineering experience, shipped projects, and certifications in security engineering, cryptography, or cloud-native automation.
5+ years of hands-on experience in security engineering with a strong emphasis on building engineered systems rather than operating manual processes.
At least 1 year of production experience with at least 2 agentic coding tools, such as Claude Code, Gemini, Cursor, Codex, AMP, or OpenCode.
Demonstrated experience building and shipping production code in Python or a similarly capable language, with infrastructure-as-code tools such as Terraform.
Proven track record of working in cloud-native environments, with deep familiarity in AWS, Kubernetes, containerized workloads, and CI/CD pipeline integration.
Strong software engineering fundamentals: version control, code review, testing, CI/CD, and API design, with the ability to write production-quality, maintainable code.
Hands-on proficiency with cloud-native engineering: AWS (KMS, IAM, Lambda, EKS, and supporting services), Kubernetes, and Terraform or equivalent IaC tools.
Technical knowledge of cybersecurity concepts, threat modeling, and secure design principles sufficient to consult on, review, and approve security-critical architecture.
⭐ Desirable Experience
Industry certifications that demonstrate hands-on technical depth, such as AWS Security Specialty, HashiCorp Terraform Associate, HashiCorp Vault Associate, CKS (Certified Kubernetes Security Specialist), GPYC (GIAC Python Coder), GCSA (GIAC Cloud Security Automation), or (ISC)² CCSP.
Experience with security telemetry platforms (OpenSearch or similar), PKI / certificate lifecycle management, or compliance automation.
🎁 Benefits
Base Compensation: $135K – $155K • Offers Bonus
🛂 Visa & Eligibility
No specific visa or eligibility information provided.
Please let Lumin Digital know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.