freehire launches on Product Hunt on 26 August.

Follow →

Lead Security Engineer

Open 16d

You will establish and mature security practices across application security, security operations, and governance, risk, and compliance. You will define application, cloud, AI, detection, incident-response, and vendor-security approaches; conduct assessments; handle complex reviews; and mentor engineers without formal people-management responsibility.

Responsibilities

  • Drive the application security roadmap, including threat modelling, secure code review, API security testing, and security pipeline architecture
  • Define security guardrails for AI and agentic workflows, including prompts, destructive actions, and data exposure
  • Set technical direction for detection engineering, alert pipelines, and automated response across the security stack
  • Own incident response readiness by designing playbooks, leading tabletop exercises, and acting as technical lead during major incidents
  • Set standards for cloud security assessments across AWS and Kubernetes
  • Own and improve the vendor security assessment and third-party due diligence framework
  • Mentor mid-level and senior engineers by reviewing detection logic, assessments, and playbooks

Requirements

  • 7+ years of information security experience, including building or substantially maturing a security function or program
  • 2+ years of experience at a regulated fintech, bank, or payment company
  • Hands-on cloud infrastructure security expertise in AWS and Kubernetes
  • Experience driving application security programs, including threat modelling, secure code review, CI/CD hardening, and API security testing
  • Ability to define security guardrails for AI and agentic tooling, including LLM integrations, MCP servers, and automated workflows
  • Detection engineering experience, including designing detection strategy and mentoring others in rule writing
  • Experience with endpoint security tooling, identity and access management architecture, Google Workspace, Okta, Cloudflare Access, SSO, and SCIM
  • Experience designing or significantly evolving vendor security assessment or third-party due diligence programs
  • Written and verbal communication skills for representing security decisions to leadership and cross-functional stakeholders
  • Business-fluent English

Benefits

  • Stock options
  • Discretionary performance bonus

See also