This website uses cookies | More info

Get discovered

Mambu's story
Open positions
Are you up for a challenge?

We are hiring

Job description

Mambu is the leading SaaS core banking engine. If you’re a customer of the largest digital bank in the EU, then you’ve probably interacted with our platform and didn't even know it. We are at the heart of what makes digital banks and lenders work - the system that processes banking transactions and updates accounts and other financial records from deposits to loans and credit balances. But Mambu is different.  We are not just cloud-native, lean and flexible - we are helping to revolutionise financial services globally. We are in a growth phase and we’ve only just begun.

To help us on our mission, we bring together people with the best skills and attitude. It doesn’t matter where you are from, what matters is the impact you have and your passion to make a difference.

We are looking for an Infrastructure Security Analyst to join our global Platform and Reliability Engineering team and ensure secure infrastructure operations, containment of infrastructure security incidents that may harm the company, and constantly improve the maturity level of Mambu’s infrastructure security.

What you will be doing:

  • Ensure that infrastructure events and changes related to information security are timely reviewed
  • Quickly review infrastructure events that impact information security, like access to customer data, to be in line with internal policies 
  • Quickly review infrastructure changes that impact information security, like a change in firewall rules or introduction of a new SaaS solution or open source component, to be in line with internal policies
  • Work with Security Engineers to automate reviews where possible

  • Ensure that infrastructure security incidents are quickly contained
  • Quickly perform a first assessment on infrastructure security incidents, including reported vulnerabilities from several sources (IDS, WAF, vendors of third party dependencies, penetration tests), regarding their risk and derive next actions

  • Ensure that security aspects are well reflected in infrastructure risk assessments
  • Support security readiness assessments for new infrastructure services or after major changes
  • Support annual and ad-hoc risk assessment workshops with Infrastructure team members to identify and mitigate infrastructure related security risks for existing systems and during the design of new services
  • Monitor treatment of risks and support continuous improvement of the maturity of the infrastructure security program to reduce security related risks

  • Ensure security awareness among Infrastructure engineers (SREs)
  • Maintain information security and data privacy training program and train infrastructure engineers on information security and data privacy with respect to their infrastructure engineers function

  • Rensible for successful internal and external security audits and due diligences
  • Coordinate pentests from infrastructure perspective
  • Perform internal infrastructure security audits
  • Support maintaining the documentation of the infrastructure security in our Control register and security assurance documents
  • Coordinate table-top exercises for infrastructure team, covering scenarios like disaster recovery, data breaches, or cyber attacks
  • Attend internal and external audits and due diligence activities to demonstrate evidences of current practices related to infrastructure security
  • You need to have:

  • Information Security Knowledge: Concepts of information security (confidentiality, integrity, availability, etc.) and their implementation options (encryption, identity and access management, backups, redundancy & high availability, network configuration)
  • Knowledge of modern application architecture
  • Knowledge of modern infrastructure 
  • Analytical, detail oriented and creative problem solving skills
  • Strong written and verbal communication skills in English
  • Nice to have:

  • Information security risk management incl. threat modeling
  • ISO 27001 Implementation Knowledge
  • Internal Auditor Experience
  • Data Privacy / GDPR Knowledge
  • Knowledge and experience with a programming language (e.g. Python)
  • Compensation and benefits:

  • Competitive salary;
  • Flexible working hours;
  • Summer schedule (4-days/week);
  • Health insurance;
  • Global business travel insurance;
  • Free parking space at the office;
  • Professional career growth by providing access to trainings and conferences
  • Why Mambu

  • Mambu has over 250+ live deployments, helping to revolutionise financial services in more than 46 countries globally, and we're just getting started;
  • We understand nothing ensures our customers' success more than a happy team, so Mambu is built on a culture of trust and a sense of ownership in everything we do;
  • Mambu proactively takes the initiative to improve the industry for the better;
  • Mambu is using top tool for development activities;
  • Because you want more, you want to know how your lines of code impact the world.
  • Why Mambu?

    About us

    Mambuvians come from over 30 countries across six continents. Over the years we have become increasingly diverse in perspectives and ideas. To us, diversity is a company-wide value, and a strategy to boost productivity and to leave a positive, global impact on our industry. From Europe to Asia, and the Americas - Mambuvians are experts at collaborating globally.

    We are a no nonsense company that loves a good challenge and is fostering a culture of a great work-life balance. Our perks range from a 4-day-working-week in summer, to extraordinary team getaways.

    Building on collaboration and trust, we created a true ownership culture, which is integral to our success. We help and empower each other to make decisions that can have a lasting impact on our business, and influence thousands of customers and millions of their end users world-wide. Are you up for it?

    Why us?