Lead Security Engineer (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Lead Security Engineer (Fintech): Building and scaling security engineering practices for a benefits platform with an accent on application security, cloud infrastructure, and supply chain integrity. Focus on designing automated controls, implementing secure SDLC, and enabling engineering teams to move fast while maintaining a robust security posture.
Location: Must be based in the United States or Canada. Role is remote with mandatory attendance at company-wide on-site events 3-4 times per year.
Salary: $190,000–$230,000 + Equity
Company
is a fintech platform helping companies reimagine employee benefits through a highly customizable and easy-to-use solution.
What you will do
- Build and operationalize security engineering practices across application, cloud, and supply chain domains.
- Partner with Engineering and Product teams to integrate security into web, mobile, and backend workflows.
- Design and implement scalable guardrails, automated controls, and secure system architectures.
- Manage vulnerability remediation, threat modeling, and CI/CD security integrations.
- Define governance for AI tooling and data protection in development workflows.
- Mentor developers and foster a culture of security through training and security champions programs.
Requirements
- 7+ years of experience in security engineering, application security, or cloud security.
- Proven track record as a senior individual contributor or technical lead in high-growth SaaS environments.
- Deep expertise in AWS-native security patterns (IAM, KMS, GuardDuty, WAF, etc.).
- Strong knowledge of secure SDLC, threat modeling, and CI/CD security hardening.
- Experience with infrastructure-as-code security and container orchestration hardening.
- Ability to balance security depth with engineering velocity and business priorities.
Nice to have
- Experience securing fintech, payroll, or payment platforms processing PII and financial data.
- Familiarity with compliance frameworks like SOC 2, HITRUST, or PCI.
- Background in mobile application security (iOS/Android).
- Experience with detection-as-code, SIEM/SOAR, and security data pipelines.
- Hands-on experience with Terraform, Kubernetes, and policy-as-code tools.
Culture & Benefits
- 95% coverage for medical, dental, and vision insurance.
- Flexible PTO policy.
- $250 one-time WFH setup stipend.
- $500/year Learning & Development benefit.
- Monthly stipends for cell phone/internet, wellness, and co-working/commuting.
- Regular team onsites to foster collaboration.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →