Skip to content

Security Engineer - Product

190k – 260kSan Francisco, CASecurity EngineeringOnsite7+ YOE
Summary

Lead product security for a fintech credit card infrastructure platform. Own API security, auth strategy, fraud primitives, secure SDLC, and compliance for partner-facing services. Hands-on engineering role reporting to Head of Engineering.

About the role

Responsibilities

  • Own the security model for our partner-facing APIs: authentication, authorization, tenant isolation, abuse prevention, signing, and audit logging.
  • Drive a coherent auth strategy across services and surfaces, including step-up auth for sensitive actions and a strong-auth roadmap (passkeys and beyond).
  • Build the device telemetry, behavioral signals, and velocity primitives that fraud and risk functions depend on.
  • Be the secure-by-design partner with Engineering — sit in on architecture reviews before features ship, write the threat models, own the tradeoffs.
  • Own secure SDLC: SAST/DAST, dependency scanning, secret detection, and the security tooling engineers interact with daily.
  • Coordinate with our infrastructure team to improve our security posture across the stack: from infrastructure, to supply chain, to first-party applications, to third-party dependencies and SaaS platforms.
  • Be the technical authority on sensitive payment data. Keep the footprint small and well-defined as the platform grows.
  • Lead incident response on security events (containment, forensics, comms, blameless postmortems) and drive vulnerability remediation across services.
  • Own the relationship with our external security architecture partner: set priorities, scope engagements, integrate findings into our roadmap.
  • Serve as the technical counterpart to ensure compliance, translating SOC 2, PCI DSS, and other security frameworks into scalable engineering solutions and ensuring in-product controls are effective in practice.

Requirements

  • Strong programming skills in Java, Python, or a comparable language — you write production code.
  • Experience designing or operating secure platform / B2B APIs at scale, especially in multi-tenant environments.
  • Background in anti-ATO, anti-fraud, or authentication systems at scale (consumer fintech, marketplace, or large consumer platform).
  • Working knowledge of AWS: IAM, KMS, networking, service-to-service auth.
  • Comfort with modern AI tooling (Claude, Copilot, and similar) as a daily force multiplier across code review, threat modeling, detection engineering, and security tooling.
  • Excellent written communication. You'll write threat models, postmortems, and partner-facing security responses.
  • Comfortable owning the security function in-house while leveraging external specialists as a force multiplier.

Nice to Have

  • Fintech, payments, or other regulated environment experience.
  • Threat modeling methodology background (STRIDE, attack trees, or your own).
  • Experience working alongside or building for a risk / fraud operations team.
  • Experience operating a bug bounty or vulnerability disclosure program.
Skills
JavaPythonAWSIAMKMSSASTDASTSOC 2PCI DSSThreat Modeling
Similar roles at this salary range
All Security Engineering jobs →
Everlaw

Senior Software Security Engineer

Lead security engineering efforts at Everlaw, guiding a team to build secure development practices and protect customer data on AWS. Requires 4+ years in security and Python scripting skills.

215k – 272kOakland, CASecurity EngineeringOn-site4+ YOEAWSIAM
Novig

Senior Security Engineer

Senior Security Engineer building proactive, automated security systems including SOAR/SIEM workflows, AI agents, vulnerability management, and cloud hardening for a fast-growing sports prediction market platform.

200k – 250kNew York, NYSecurity EngineeringOn-site5+ YOECDKIAM
Instacart

Senior Security Engineer, Cloud, AI, Product Security

Senior Security Engineer responsible for identifying infrastructure and product risks, defining remediation roadmaps, and building scalable secure engineering systems. Requires 5+ years in security engineering and strong IaC and code review experience.

192k – 242kUnited StatesSecurity EngineeringRemote5+ YOEGoOPA
Coinbase

Senior Software Engineer

Senior Software Engineer on the Core Cryptography team building and operating Tier-0 cryptographic infrastructure including MPC systems that secure 99% of customer assets. Requires 5+ years building highly available distributed systems and experience with applied cryptography, KMS/HSMs, and systems languages (Golang-heavy).

186k – 219kUnited StatesSecurity EngineeringRemote5+ YOEC++Java
Rokt

GRC Automation & Assurance Lead

Lead GRC audit, assurance, and compliance programs while architecting and shipping AI agents to automate evidence collection, control testing, questionnaires, and audit prep for ISO 27001 and SOC 2.

174k – 215kNew York, NYSecurity EngineeringOn-site4+ YOEAWSSQL