Skip to content
FlexFlex

Senior Software Engineer, Security

Build and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.

About the job

Responsibilities

  • Threat model money movement systems, including the ledger and write path, card issuing, payouts, and stablecoin work, during design reviews and continuously after launch.
  • Build secure-by-default infrastructure, including Infrastructure as Code (IaC) guardrails, CI/CD supply-chain integrity, secrets handling, service isolation, and workload IAM.
  • Build just-in-time, least-privilege cloud access systems.
  • Own application security across new and existing systems through automated checks, secure development defaults, high-risk code review, dependency and SBOM hygiene, and static and dynamic analysis.
  • Build logging safeguards and tooling that keeps sensitive data out of logs.
  • Run the vulnerability disclosure program and grow it into a bug bounty program.
  • Scope external penetration tests and drive remediation.
  • Build security automation, including AI-assisted triage and review.
  • Partner with Engineering, IT and Corporate Engineering, Risk, and Compliance on security reviews and audits.

Requirements

  • Substantial hands-on experience building or securing systems in a fast-moving environment, including experience as the most senior person doing this work.
  • Strong software engineering ability in Python, Go, TypeScript, or a similar language.
  • Hands-on experience with AWS or GCP, Terraform or equivalent IaC, containers, and CI/CD pipelines.
  • Practical threat modeling and risk-based security judgment.
  • Experience with secrets management, workload identity, and service-to-service authorization.
  • Experience handling inbound vulnerability reports.
  • Clear written communication.

Nice-to-haves

  • Platform, infrastructure, or DevOps experience that transitioned into security.
  • Small-company or founder experience.
  • Experience running a vulnerability disclosure or bug bounty program, including triage.
  • Fintech, payments, or another regulated-environment background.
  • Production experience applying AI or LLM tooling to security work.
  • OSCP or OSWE certification.

Compensation

  • $170,000 - $230,000 per year, depending on experience, plus equity.

Skills

Python, Go, TypeScript, AWS, GCP, Terraform, Infrastructure As Code, Containers, CI/CD, Secrets Management, Workload Identity, Threat Modeling, Sbom, Static Analysis, Dynamic Analysis

Censys

Censys

United States

Research Systems Analyst
$170k+/yrRemote6+ YOESecurity Engineering

Build and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.

GitLab

GitLab

United States
Senior Manager, Product Security Engineering
$168k+/yrRemote5+ YOESecurity Engineering

Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.

Upstart

Upstart

United States

Senior Application Security Engineer
$167k+/yrRemote5+ YOESecurity Engineering

Leads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.

Wiz

Wiz

United States

Compliance Engineer - Public Sector
$174k+/yrRemote6+ YOESecurity Engineering

Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.

Jasper

Jasper

United States

Senior Security Engineer
$174k+/yrRemote8+ YOESecurity Engineering

The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.