Security Engineer 3 - Vulnerability Management
at Tide · 1001-5000 employees
- Location
- India, Delhi NCR
- Posted
- 5d ago
at Tide · 1001-5000 employees
Tide is a London-based fintech platform that offers SMEs digital business accounts, payments, invoicing, accounting integrations, expense management and embedded lending products through a single interface.
<div class="content-intro"><h3><strong>A</strong><strong>BOUT TIDE</strong></h3> <p>At Tide, we help SMEs save time and money in the running of their businesses by not only offering business accounts and related banking services, but also a comprehensive set of highly usable and connected administrative solutions, from invoicing to accounting.</p> <p>Tide is transforming the small business banking market and now supports over 2 million members globally across the UK, India, Germany and France.</p> <p>Using advanced technology, all solutions are designed with SMEs in mind. With quick onboarding, low fees and innovative features, we thrive on making data driven decisions to serve our mission: to help SMEs save time and money so they can get back to doing what they love.</p> <p><strong>Tide facts:</strong></p> <ul> <li>Tide is available for UK, Indian, German and French SMEs</li> <li>Over 2 million members: 900,000 UK and 1,100,000 in India and growing rapidly</li> <li>Over $300 million raised in funding</li> <li>Over 2,800 Tideans globally</li> <li>Recognised with Great Place to Work certification three years in a row, and among India’s Top 50 Best Workplaces in Banking, Financial Services, and Insurance in 2026</li> <li>We have offices in Central London, with a member support and technology centre in Sofia, Bulgaria, technology centres in Serbia, Romania, Lithuania and Hyderabad and offices in Gurugram, New Delhi, Berlin, Paris and Luxembourg</li> </ul></div><h3>ABOUT THE TEAM: <span style="color: rgb(224, 62, 45);"><br></span></h3> <p>The Product Security team at Tide is responsible for embedding security across the full product surface, from secure design and threat modelling through to application-layer controls and vulnerability management. Within Product Security, the Remediation Operations function owns the day-to-day engine of Tide's vulnerability management programme: turning a high volume of findings from across our tooling estate into clear, prioritised, actionable work for engineering and IT teams.</p> <p>This role sits at the heart of that function. You will be the connective tissue between security tooling and the teams who fix things, making sure the right vulnerabilities reach the right people with the right context, and that they actually get resolved. This is a delivery-focused role for someone who measures success not by findings raised, but by risk reduced.</p> <h3>ABOUT THE ROLE: </h3> <p>As a Security Engineer for Vulnerability Management, you will:</p> <ul> <li><strong>Triage and validate vulnerabilities</strong> surfaced by Tide's core security tooling, including Wiz, Semgrep, CrowdStrike Exposure Management and our External Attack Surface Management (EASM) platform, separating signal from noise and confirming which findings are real, exploitable and relevant to Tide.</li> <li><strong>Support risk-based prioritisation</strong>, helping to rank findings by severity, exploitability, asset criticality and business context, so that limited engineering effort is always pointed at what matters most.</li> <li><strong>Automate remediation workflows</strong> within Tide's vulnerability management platform (Seemplicity), building and refining the routing, ticketing, deduplication and escalation logic that keeps findings moving without manual overhead.</li> <li><strong>Verification and Validation of the Fix</strong> implemented through targeted re-scanning or manual checks, ensuring risks are genuinely mitigated before tickets are formally closed.</li> <li><strong>Act as a trusted partner to engineering and IT teams</strong>, explaining the importance and technical detail of specific findings, advising on practical fixes, and helping teams understand the reasoning behind each request rather than treating it as a box-ticking exercise.</li> <li><strong>Build reports and dashboards</strong> that give clear visibility of vulnerability posture, remediation progress, SLA adherence and trends, tailored for both technical owners and senior stakeholders.</li> <li><strong>Design and run nudging strategies</strong> to shift fix behaviours across engineering and IT, using data, well-timed prompts and the right incentives to drive down time-to-remediate and reduce recurring issues.</li> <li><strong>Maintain the health of the remediation pipeline</strong>, monitoring ageing findings, chasing stalled items, identifying systemic blockers and feeding that insight back into the wider vulnerability management strategy.</li> <li><strong>Contribute to continuous improvement</strong> of remediation operations, refining processes, SLAs, taxonomies and tooling configuration as Tide's environment and threat landscape evolve.</li> </ul> <h3><br>WHAT WE ARE LOOKING FOR: </h3> <ul> <li>Hands-on experience in vulnerability management, or a similar analytical security role, ideally in a fast-moving, cloud-native environment.</li> <li>Familiarity with vulnerability and exposure tooling such as Wiz, Semgrep, CrowdStrike, EASM platforms, or comparable scanners, along with a solid understanding of how to interpret and validate their findings.</li> <li>A good grasp of vulnerability scoring and prioritisation concepts, including CVSS, EPSS, CISA KEV exploitability and asset context, with the judgement to know when a severity rating needs a human sense-check.</li> <li>Facilitate the risk acceptance and exception management workflow, ensuring that deferred remediations are properly documented, justified, approved by stakeholders, and tracked for future review.</li> <li>Experience with, or a strong appetite to work with, workflow automation and orchestration, whether through a dedicated platform such as Seemplicity, light scripting, or integrations between security and ticketing tools.</li> <li>Confidence building reports and dashboards that turn messy data into clear narratives.</li> <li>Strong communication and stakeholder skills, comfortable explaining technical findings to engineers and translati