# Senior Software Engineer, Security

**Company:** [Flex](https://hotfix.jobs/companies/flex)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $170k – $230k/yr
**Experience:** 5+ years
**Skills:** Python, Go, TypeScript, AWS, GCP, Terraform, Infrastructure As Code, Containers, CI/CD, Secrets Management, Workload Identity, Threat Modeling, Sbom, Static Analysis, Dynamic Analysis
**Posted:** 2026-08-21

> Build and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.

## Job Description

## Responsibilities
- Threat model money movement systems, including the ledger and write path, card issuing, payouts, and stablecoin work, during design reviews and continuously after launch.
- Build secure-by-default infrastructure, including Infrastructure as Code (IaC) guardrails, CI/CD supply-chain integrity, secrets handling, service isolation, and workload IAM.
- Build just-in-time, least-privilege cloud access systems.
- Own application security across new and existing systems through automated checks, secure development defaults, high-risk code review, dependency and SBOM hygiene, and static and dynamic analysis.
- Build logging safeguards and tooling that keeps sensitive data out of logs.
- Run the vulnerability disclosure program and grow it into a bug bounty program.
- Scope external penetration tests and drive remediation.
- Build security automation, including AI-assisted triage and review.
- Partner with Engineering, IT and Corporate Engineering, Risk, and Compliance on security reviews and audits.

## Requirements
- Substantial hands-on experience building or securing systems in a fast-moving environment, including experience as the most senior person doing this work.
- Strong software engineering ability in Python, Go, TypeScript, or a similar language.
- Hands-on experience with AWS or GCP, Terraform or equivalent IaC, containers, and CI/CD pipelines.
- Practical threat modeling and risk-based security judgment.
- Experience with secrets management, workload identity, and service-to-service authorization.
- Experience handling inbound vulnerability reports.
- Clear written communication.

## Nice-to-haves
- Platform, infrastructure, or DevOps experience that transitioned into security.
- Small-company or founder experience.
- Experience running a vulnerability disclosure or bug bounty program, including triage.
- Fintech, payments, or another regulated-environment background.
- Production experience applying AI or LLM tooling to security work.
- OSCP or OSWE certification.

## Compensation
- $170,000 - $230,000 per year, depending on experience, plus equity.

## Similar jobs

- [Research Systems Analyst](https://hotfix.jobs/jobs/eddd16d1-e2f4-4e7b-95b1-e8312679a35a) - Censys - Remote - $170k – $220k/yr
- [Senior Manager, Product Security Engineering](https://hotfix.jobs/jobs/8fa92a96-1812-406c-8ae5-324c42e42eea) - GitLab - Remote - $168k – $245k/yr
- [Senior Application Security Engineer](https://hotfix.jobs/jobs/77d9af5b-0584-4512-b0a0-dde5773d5334) - Upstart - Remote - $167k – $231k/yr
- [Compliance Engineer - Public Sector](https://hotfix.jobs/jobs/1664a48a-e3c2-4c6a-91dd-ffcd986273e3) - Wiz - Remote - $174k – $238k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/b4bd3a90-c9c6-4983-b371-da5d17567c3a) - Jasper - Remote - $174k – $205k/yr

**Apply:** https://hotfix.jobs/jobs/4fb0f2e8-3bb9-4076-9b7a-739b1f661bee
**Canonical:** https://hotfix.jobs/jobs/4fb0f2e8-3bb9-4076-9b7a-739b1f661bee