
IMC · Sydney
The information security team is responsible for protecting IMC’s intellectual property, IT infrastructure and business operations against external and internal...
The information security team is responsible for protecting IMC’s intellectual property, IT infrastructure and business operations
against external and internal threats. We work closely with technology, risk, compliance, internal audit and business leaders to
reduce cyber risk to acceptable levels. We are looking for an Information Security Engineer to grow and mature our Security
Operations Center function that uses EDR, SIEM, SOAR, CSPM, IAM, firewalls, NIDS/NIPS and various other security controls. We
offer an environment that allows you to broaden and deepen your information security knowledge and skills, with access to advanced
security technology, frequent training and a culture of knowledge sharing. As you gain experience with our existing SOC technology
and processes, you will be given a lot of freedom to further mature the SOC with your own initiatives.
of its limitations
enterprise IT environment, managing endpoints and applications on-prem or in the cloud
security tooling or LLM-based workflows is highly regarded.
About Us
IMC is a global trading firm powered by a cutting-edge research environment and a world-class technology backbone. Since 1989,
we’ve been a stabilizing force in financial markets, providing essential liquidity upon which market participants depend. Across
our offices in the US, Europe, Asia Pacific, and India, our talented quant researchers, engineers, traders, and business
operations professionals are united by our uniquely collaborative, high-performance culture, and our commitment to giving back.
From entering dynamic new markets to embracing disruptive technologies, and from developing an innovative research environment to
diversifying our trading strategies, we dare to continuously innovate and collaborate to succeed.
IMC is looking for a highly skilled Quantitative Microstructure Analyst to join our Performance team in Sydney. Quantitative Microstructure Analyst's at IMC collaborate with other teams, both technical and non-technical, to handle everything from optimising exchange connectivity to analysing application performance to designing systems for handling massive amounts of data. If it’s a hard problem, it’s in scope. Your Core Responsibilities: * Data and Systems Analysis: Analyse terabytes of network data to identify patterns, validate hypotheses, and optimise system performance. * Analyse, optimise, troubleshoot, and continuously tune the complete trading environment to improve the performance of our low-latency trading systems on financial exchanges. * Analyse time series exchange network captures. * Design, develop, test, and deploy simple, elegant, reusable code. * Work closely with traders and other technology teams to drive global thinking, information sharing, and sustainable, long-term solutions. * Build IMC's knowledge base to ensure a deep understanding of exchange infrastructure and protocols. * Define the direction for critical investment decisions by analysing complex technical problems in a self-directed manner. Your Skills and Experience: While not all of the below is required, a deep understanding in at least one of the following areas would be an advantage * 5+ years of experience in at least one of the areas: distributed systems, computer networks, operating system architecture, ultra-low latency environments. * Strong skills in data analytics including analysing and visualising large data sets * Knowledge of Linux kernel internals and interfaces including memory, network, and file I/O. Knowledge of eBPF is a plus. * Knowledge of networking (TCP/IP, UDP, Multicast). Knowledge of kernel network bypass technologies is a plus. * Proficiency in Python. Proficiency in C++ a bonus. * A high degree of flexibility and adaptability: willing and able to deal with uncertainty and ambiguity in a rapidly evolving environment * Strong troubleshooting and diagnostic skills; ability to solve problems creatively and proactively. * Ability to communicate complex ideas to technical and non-technical audiences. * Ability to see opportunities and to make them happen without supervision; a true self-starter. About Us IMC is a global trading firm powered by a cutting-edge research environment and a world-class technology backbone. Since 1989, we’ve been a stabilizing force in financial markets, providing essential liquidity upon which market participants depend. Across our offices in the US, Europe, Asia Pacific, and India, our talented quant researchers, engineers, traders, and business operations professionals are united by our uniquely collaborative, high-performance culture, and our commitment to giving back. From entering dynamic new markets to embracing disruptive technologies, and from developing an innovative research environment to diversifying our trading strategies, we dare to continuously innovate and collaborate to succeed.
Vill du ta nästa steg i karriären inom cybersäkerhet? Vill du jobba med komplexa problem i teknisk framkant och bidra till samhällsnyttiga projekt? Ta nu chansen i rollen som Information Secuity Engineer hos vår kund inom försvarsindustrin. Om tjänsten Du kommer att spela en central roll inom utveckling och säkerställande av interna IT-system. Ditt arbete kommer att kretsa kring att implementera och förbättra IT-säkerhetsåtgärder, vilket innebär ett nära samarbete med flera tvärfunktionella team. Ett av huvudansvaren är att säkerställa att organisationen ligger i framkant avseende tekniska innovationer och säkerhetsstandarder. Du kommer även att hantera tekniska gränssnitt för att säkerställa att systemen uppfyller både behov och kravställningar inom olika verksamhetsområden. Dina dagliga uppgifter kommer bland annat att inkludera säkerhetstestning, kravanalys och regeltolkning. Arbetet omfattar flera globala regelverk såsom NIST 800-171 Rev.2, NIS2, ISO-standarder samt andra internationella säkerhetsramverk. Du kommer också att vara ansvarig för att följa och implementera regelverk som ISO-standarder och GDPR, vilket är avgörande för att säkerställa organisationens compliance. För att lyckas i rollen krävs det att du har intresse för ny teknologi och en vilja att ständigt utöka din kunskap. Teamet arbetar ibland remote där virtuella verktyg används för samarbete. Det förekommer gemensamma teamdagar där det krävs fysisk närvaro on-site. Det finns möjlighet att arbeta från olika kontor/hubbar beroende på geografisk placering. Sammanfattningsvis erbjuder denna roll en rik möjlighet att bidra till och växa i en dynamisk och framåttänkande IT-miljö, där din insats kommer att vara avgörande för att framtidssäkra verksamheten och dess tekniska lösningar. Vi söker dig som har erfarenhet av en eller flera av följande områden:Säkerhetspraxis (te.x OWASP) Regelverk såsom ISO27xxx, GDPR, SOC2, DORA Kravställning och kravanalys IAM-roll-och-policybaserade behörighetssystem Praktisk erfarenhet av säkerhetstestning (t.ex. MITM) God kommunikation förmåga på svenska och engelska i tal och skrift Det kommer även läggas stor vikt vid personlig lämplighet i rekryteringen. För att trivas i rollen tror vi att du är en engagerad lagspelare med ett driv och vilja att utvecklas. Du kommer ingå i ett team där nyfikenhet och kreativitet uppmuntras, därför tror vi att du gillar innovation och gillar att komma med nya idéer och lösningar. Befattningen kräver att du genomgår och godkänns enligt gällande säkerhetsskyddsbestämmelser. För vissa roller kan detta innebära krav på säkerhetsklassning och i förekommande fall specifika medborgarskapskrav. Urval sker löpande och uppdraget kan komma att tillsättas innan sista ansökningsdatum Om anställningen: Detta är ett konsultuppdrag vilket innebär att du kommer vara anställd av Friday och arbeta som konsult ute hos vår kund. På Friday tror vi att människor som är på rätt plats har störst möjlighet att nå sin fulla potential. Vi är övertygade om att rätt människor, i rätt roller, skapar morgondagar värda att längta till. Övrig info: Omfattning: Heltid Start: Enligt överenskommelse Placering: Utångspunkt i Linköping men går att utgå från andra platser i landet Lön: Marknadsmässig månadslön Kontaktperson: Hampus Kindgren, hampus.kindgren@Friday.se Om Friday På Friday brinner vi för att ge dig som Tech-talang en riktigt bra start på karriären. Genom att lyssna på vad just du vill och drivs av, matchar vi dig med företag och möjligheter som får dig att se fram emot att gå till jobbet. Vi värderar ambition och potential högt och arbetar aktivt för en fördomsfri rekrytering, där alla ges samma chans att lyckas. Vi finns i Stockholm, Göteborg, Malmö, Linköping och Örebro. Varje år genomför vi över 5 000 karriärmöten och matchar kandidater med allt från globala företag till innovativa startups. Öppen för alla Vi fokuserar på din kompetens, inte dina övriga förutsättningar. Vi är öppna för att anpassa rollen eller arbetsplatsen efter dina behov.
ABOUT BUREAU Bureau is a unified risk decisioning platform for Compliance, Fraud, and Transaction risks. Our platform is a single decision-making engine, powered by a 1 billion+ identity knowledge graph. Over 150 Banks, fintechs, retailers, and digital platforms use Bureau to verify identities faster and stop fraud earlier globally. Bureau has raised $50M+ from renowned Silicon Valley and global investors including Sorenson Capital and PayPal Ventures and is expanding rapidly from APAC to Americas, Europe, and beyond. WHY BUREAU? Bureau is building the infrastructure that makes digital identities and transactions safe and trustworthy for billions of people. The mission is big, the problems are complex, and the impact is real. We hire people who want that level of responsibility. People who move fast, build systems from scratch, and care deeply about turning strategy into execution. If you want predictability or narrow scope, this won't be your place. If you want to shape how a scaling global company operates—keep reading. ABOUT THE ROLE - INFORMATION SECURITY ENGINEER We are looking for a Security Engineer who can own both the hands-on technical security stack and our governance/compliance programs. What you’ll be doing In this role, you will: * Harden and monitor our cloud & container infrastructure (AWS/EKS, endpoints, network). * Run vulnerability management, security tooling and incident response. * Help maintain our ISMS and support audits (ISO 27001, SOC 2, RBI, DPDP, etc.). This is ideal for someone who doesn’t want to be only “checklist GRC” or only “pure blue-team”, but wants a blended role across security engineering + GRC.Key Responsibilities 1. Cloud & Infrastructure Security (Hands-on) * Work with DevOps to secure our AWS/EKS environment: * IAM hardening, security groups, VPC, KMS, S3, RDS, etc. * Review infra-as-code (Terraform/Helm) for security issues and misconfigurations. * Own or co-own key security tools: * Endpoint / EDR (e.g., CrowdStrike / SentinelOne), * Cloud security (CSPM / CNAPP, GuardDuty, Security Hub, WAF, etc.), * Container / runtime security where applicable. * Implement and maintain logging & monitoring for security events (CloudTrail, ALB/NLB logs, K8s logs, etc.), and integrate them with SIEM / alerting. 2. Vulnerability Management & Security Operations * Own the vulnerability management lifecycle: * Run periodic scans for cloud, endpoints, containers and apps. * Triage findings, prioritise based on risk, and drive closure with engineering. * Coordinate external pentests / bug bounties and track remediation. * Support incident response: * Help investigate alerts, gather evidence, and contribute to RCA and CAPA. * Maintain and update incident runbooks. 3. Governance, Risk & Compliance (ISMS, Audits, DPDP) * Maintain and enhance the Information Security Management System (ISMS): * Policies, procedures, SoA, risk register, control evidence and audit trails. * Support internal and external audits: ISO 27001, SOC 2, RBI/CERT-In, Data Protection. * Prepare and manage audit evidence, observations, closure reports and certification documentation. * Assist with risk assessments: * Maintain the risk register, risk treatment plans and residual risk reviews. * Conduct vendor security due diligence and maintain vendor security records (MSA, NDA, DPA, DPIA, etc.). * Support privacy & regulatory compliance operations (GDPR/DPDP basics: retention, consent, grievance logging). 4. Access, Asset & Control Assurance * Participate in and help automate access reviews, asset inventory checks, and configuration compliance checks. * Track control performance (vuln SLAs, access reviews, backup tests, etc.) and ensure gaps are documented and closed. * Maintain security awareness and training trackers (onboarding, annual refreshers, phishing simulations). What You’ll Bring * Bachelor’s degree in Computer Science, IT, Cybersecurity or related discipline. * ~4 years of experience in security engineering, cloud security, or GRC/compliance (any mix, but must be comfortable hands-on). * Good understanding of: * Security engineering fundamentals: Linux, networking, IAM, encryption, least privilege. * Cloud platforms (AWS preferred; GCP/Azure a plus) and their security services. * Core frameworks: ISO 27001, SOC 2, basic risk management and audit lifecycle. * Comfortable with: * Writing/debugging basic scripts (Bash/Python) for automation and data extraction. * Tools like Jira, Confluence, Excel/Sheets and at least one GRC / security platform (e.g., Scrut/Drata/Secureframe, etc.). * Strong documentation skills and ability to talk to both engineers and non-technical stakeholders. Preferred (Good to Have) / Willing to Learn * Cloud security certifications (e.g., AWS Security / AWS Cloud Practitioner). * ISO 27001:2022 Lead Auditor/Implementer, CompTIA Security+, ISC2 CC. * Experience with: * EDR/XDR tools, * CSPM/CNAPP (e.g., Wiz, Prisma, Defender for Cloud), * SIEM, WAF, runtime/container security (Falco, etc.). * Exposure to GDPR/DPDP or other data protection regimes. Who You Are * You enjoy both: * Getting your hands dirty in logs, configs and cloud consoles, and * Keeping things clean in policies, risk registers and audit trackers. * You’re structured and process-oriented, but still pragmatic and capable of shipping improvements. * You’re comfortable collaborating with DevOps, backend, data, HR and legal to get security actually implemented, not just written down. * You want to grow into either Security Engineering leadership (owning tools/architecture) or GRC leadership (owning audits and certifications) over the next few years. OUR CULTURE * We hire self-motivated people and get out of their way * We value performance, not hours worked * Speed, ownership, and impact matter most COMPENSATION * Competitive salary + potential equity * Health benefits, flexible PTO, learning budget