Software Engineer Security
Summary
Own and scale platform security across network, infrastructure, and application layers for a fintech company, hardening Cloudflare, AWS, and implementing security features like passkey auth and rate limiting.
You will own and scale the security of the platform across network, infrastructure, and application layers. You will define and manage the security program, harden Cloudflare, AWS WAF, VPC networking, and infrastructure, implement application security features, coordinate penetration tests and bug bounty remediation, support PCI and SOC 2 compliance, establish security tooling and guardrails, secure corporate IT systems and endpoints, and communicate with customers, stakeholders, and vendors about security practices.
Responsibilities
- Own the security program end-to-end
- Manage and harden Cloudflare, AWS WAF, VPC networking, and infrastructure
- Implement application security features such as passkey authentication and SMS rate limiting
- Manage recurring penetration tests and the bug bounty program
- Coordinate security remediation across engineering
- Support PCI and SOC 2 compliance efforts
- Establish security patterns, tooling, and guardrails
- Secure company equipment and endpoints
- Answer customer, stakeholder, and vendor questions about security practices
Requirements
- Security generalist knowledge across infrastructure and application code
- Knowledge of Kubernetes/EKS, CockroachDB, Kafka, Terraform/Pulumi, and AWS
- Proficiency in TypeScript or another object-oriented language
- Ability to coordinate penetration tests, audits, and competing security priorities
- Ability to identify gaps and independently drive high-impact changes
- Current or recent founder in the security space, or 2–5 years of experience with rapid promotion to senior or staff level at companies with a high security bar
Benefits
- Equity
- Comprehensive health and benefits plan
- Unlimited PTO