Security Engineer
CoinflowPayments company
Chicago, United States$145,000 - $195,000Senior
Pantera Capital
Coinbase Ventures
CMT Digital
The Fintech Fund
Jump Capital
Reciprocal Ventures
Software Engineering
About the role
TL;DR
Security Engineer to manage Coinflow's security posture.
- •We're hiring for a Security Engineer to own the day-to-day defensive and offensive security posture of Coinflow.
- •You'll build the SecOps backbone, hunt for weaknesses in our own stack before anyone else does, and partner with engineering to keep our SDLC fast and secure.
- •Key Responsibilities SIEM & SecOps Dashboard: Stand up and operate our SIEM.
- •Build out the SecOps dashboard that gives engineering, compliance, and leadership a real-time picture of our security posture.
- •Internal Penetration Testing: Run continuous internal pentests against Coinflow services, APIs, infrastructure, and embedded SDKs.
- •Use Claude Security and Claude Code to scale your coverage.
- •Vulnerability & Dependency Management: Own the vulnerability lifecycle end-to-end.
- •Triage CVEs across our npm, cargo, and other ecosystems.
- •Secure Development Lifecycle: Monitor and improve how we ship code.
- •Define secure-by-default patterns for new services, review threat models for high-risk changes, integrate SAST/DAST/secret scanning into CI.
- •Compliance Partnership: Work alongside our compliance function to produce the evidence, controls, and monitoring artifacts that PCI DSS, SOC 2, ISO 27001, and DORA auditors need.
- •Requirements 4+ years in a security engineering, product security, or DevSecOps role, ideally at a fintech, payments company, or other regulated environment Strong hands-on offensive skills
- •you've broken real systems, not just run scanners.
- •Comfortable with web app, API, cloud, and infrastructure pentesting Production experience operating a SIEM (Datadog, Splunk, Elastic, Panther, or similar) and building dashboards that engineers actually use Fluency in TypeScript/Node and at least passing comfort with Rust, Go, or Python
- •enough to read our code, find bugs in it, and write the tooling to find more Experience with vulnerability management at scale: CVE triage, SCA tooling, dependency upgrade automation Comfort working with AI-native tooling (Claude Code, Claude Security, or similar) as a daily driver
- •or genuine excitement to start A bias toward shipping.
- •We'd rather have a working v1 of a control today than a perfect v3 next quarter.
Required skills
TypeScriptNode.jsRustGoPythonDatadogElasticsearchCI/CDGitHub ActionsJenkinsArgoCDHelmGitLab CICircleCIAnsible
Nice-to-have skills
GitLinuxJiraConfluenceFigmaPostmanSwaggerOpenAPIREST APIgRPC
Domain expertise
fintech
Benefits & perks
equity, health insurance, 401(k) savings plan, flexible time off
Tech stack
TypeScriptNode.jsRustGoPythonDatadogElasticsearchCI/CDGitHub ActionsJenkinsArgoCDHelmGitLab CICircleCIAnsibleChefPuppetPrometheusGrafanaNew RelicPagerDutyNginxHAProxyOAuthJWTSAMLOWASPPenetration TestingSOC 2GDPR