We’re looking for a Security Engineer to own and improve the security of our internal environment — the identities, SaaS apps, endpoints, AI tooling, and networks our employees use every day. This is a hands-on senior role: we expect you to design controls, find the gaps, and drive the changes that close them — and to build the automation that makes it scale.
🏢 About Vivid
At Vivid, we're on a mission to change how businesses and individuals manage their money across Europe. For businesses, we build tools that actually make a difference: multi-IBAN accounts, high-yield savings, business cashback, team cards, and accounting integrations that save real time — all in one place. And for individuals, we offer a simple way to manage and grow your wealth: access to global stocks, ETFs and 150+ cryptocurrencies, cashback, and personalised financial insights.
🎯 The Role
We’re an EMI-licensed fintech in a fully cloud-native AWS environment, we use AI heavily, and we’re growing fast. We need someone who can lead technical initiatives independently, influence our security architecture, challenge approaches that no longer fit, and explain it clearly to engineers and leadership.
✅ Key Responsibilities
Detection & Response (SIEM) — our top priority: Own SIEM alerting end-to-end: ship logs from endpoints, IdP, VPN, SaaS, and cloud; write and tune detection rules; cut false positives.
Act as first responder for security incidents — investigate, contain, drive to closure with clear runbooks — and feed recurring issues back into preventive controls.
Identity, Access & SaaS: Administer the IdP (SSO via SAML/OIDC, MFA, conditional access) and run access recertification end-to-end across IdP, SaaS, AWS, and internal tools — scope, evidence, follow-through on revocations.
Hunt down over-permissive and stale access, enforce least privilege and PAM, catch SoD gaps, and make JML and third-party access work in practice.
Improve SaaS security posture (Google/Microsoft, Slack, GitHub, others) and apply DLP controls to limit data leakage.
Endpoint, Email & Phishing Defense: Keep the endpoint stack healthy and well-tuned — MDM, XDR/AV, device-compliance checks for VPN/ZTNA — and define posture requirements (disk encryption, EDR present, OS version) with automated remediation.
Defend against phishing and spoofing — secure email gateway rules, DMARC/SPF/DKIM — and run phishing simulations and security awareness, acting on the results.
Automation & Ownership: Build internal tooling and automate repetitive operations — reduce manual work, don't just operate it.
Own the roadmap for your areas: identify gaps, lead initiatives independently, and raise the bar rather than just maintain it.
📌 Required Qualifications
5+ years in security operations, corporate/IT security, or endpoint engineering.
Strong with a SIEM (Splunk, Elastic, Panther, Sumo Logic) — detection engineering and incident response — plus an identity provider (Okta, Entra ID, Google Workspace), access recertification, and least-privilege / PAM.
Working knowledge of endpoint security (MDM, XDR/EDR/AV) and email / phishing defense.
Practical experience securing how a company uses AI internally: shadow AI discovery, DLP for AI tools, controls for AI assistants and agents, and a working risk framework for adopting new ones. You've done this for real, not from a vendor pitch deck.
Strong scripting and automation skills — you build tooling against APIs, not just configure consoles.
Track record of driving improvements end-to-end and leading initiatives with little oversight.
Сlear written and spoken English for engineers and leadership.
🎁 Benefits
Hybrid model in our Limassol office, or fully remote outside office locations.
Support for relocation to Cyprus (visa, package) when needed.
Learning & development budget to support your professional growth.
Fully paid vacation and sick leave.
Sports compensation.
Real growth prospects, significant responsibility, and the ability to make an immediate impact from day one.
🛂 Visa & Eligibility
We support relocation to Cyprus (visa, package) when needed.