Principal Information Security Engineer
SentiLink is seeking a Principal Information Security Engineer to lead and enhance security across infrastructure, applications, and internal systems. This hands-on role involves building scalable security foundations, designing secure systems, and improving detection and response capabilities.
About the job
Responsibilities:
- Design and build internal security tooling from scratch, including agent-based security tooling, code analysis tooling, dynamic scanning, and security assessment tools
- Identify vulnerabilities across SentiLink's AWS-based stack, including application code, cloud service configurations, and integrations between the two
- Develop AI-assisted and agent-based tooling to scale offensive security testing beyond what a small team can do manually
- Build and maintain security automation that improves detection, response, and remediation across the organization
- Conduct hands-on penetration testing and vulnerability research against SentiLink's infrastructure and applications
- Partner with engineering teams to remediate findings and embed security into the development process without slowing them down
- Participate in the security on-call rotation, including incident response and regular response testing
- Contribute to threat modeling and security design reviews for new systems, with a focus on cloud integrations and identity flows
- Stay current on offensive security techniques, AI-assisted security tooling, and emerging attack patterns relevant to fintech and identity verification
Requirements:
- 8+ years of experience in security engineering, software engineering with a security focus, or closely related roles
- Proficient in at least one systems language (Go, Rust, C++) and at least one higher-level language (Python, TypeScript)
- Proven ability to design and ship production software end-to-end
- Deep AWS infrastructure expertise, including IAM, EKS, RDS, networking, and managed services
- Demonstrated ability to identify security misconfigurations and vulnerabilities across cloud architectures, application code, and the integrations between them
- Experience conducting or building tooling for penetration testing, vulnerability assessment, or red team activities
- Track record of building security automation and tooling from scratch
- Comfortable operating independently on ambiguous problems without heavy process or oversight
- Strong communication skills and the ability to partner with engineers who are not security specialists
Nice to have:
- Experience building or deploying LLM-based agents or AI-assisted security tooling
- Prior experience at a security product company (Wiz, Snyk, Datadog, etc.) or other security-forward engineering org
- Prior fintech, identity, or fraud detection experience
- Industry certifications (OSCP, OSCE, GPEN, GXPN)
- Experience with detection engineering or SIEM platforms
- Published security research, CVEs, or open source security tooling contributions
- Experience supporting compliance frameworks (FedRAMP, SOC 2, PCI DSS) without it being their primary focus
Compensation:
- $220k-280k/year + equity + benefits
Perks:
- Employer paid group health insurance for you and your dependents
- 401(k) plan with employer match (or equivalent for non US-based roles)
- Flexible paid time off
- Regular company-wide in-person events
- Home office stipend, and more!
Skills
Go, Rust, C++, Python, TypeScript, AWS, IAM, EKS, Rds, Penetration Testing
Similar jobs
Security Engineering jobsLeads offensive security research across GitLab’s codebase and AI-powered agentic surfaces, identifying systemic vulnerabilities, developing exploit proofs of concept, and driving remediation. Requires 10+ years of security research or penetration-testing experience and proficiency in multiple programming languages.
Own GitLab’s global security awareness and human-risk program, leading phishing simulations, behavior-change initiatives, training platforms, vendor strategy, and audit support. Requires 10+ years scaling enterprise awareness programs and strong stakeholder influence in a distributed organization.
Leads security, privacy, audit, vendor-risk, and AI governance programs while setting long-term GRC strategy and executing cross-functional controls. Requires 10+ years of GRC, information security, and privacy compliance experience, with deep SOC 2, privacy, and emerging AI governance expertise.
Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.
Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.