TL;DR
Own and scale security posture for a growing fintech compliance platform.
• We're looking for a hands-on security engineer to own and scale our security posture as we grow. • You'll be the first dedicated security hire on our engineering team, which means you'll have a direct hand in shaping how we think about security • from compliance frameworks and vendor diligence to infrastructure hardening and secure development practices. • Key Responsibilities Detect, triage, and drive remediation of vulnerabilities across the stack • infrastructure, application, and network. • Manage third-party penetration tests and coordinate internal response to findings. • Integrate security into the development lifecycle: code review guardrails, SAST/DAST tooling, dependency scanning, and developer security guidance. • Own our SOC 2 compliance program end-to-end, including audit preparation, evidence collection, and remediation tracking. • Manage inbound security diligence requests that arise during client sales processes • completing questionnaires, coordinating evidence, and joining calls as needed. • Requirements 5–10 years of experience in security engineering, application security, or infrastructure security roles. • Hands-on experience with SOC 2 audits and at least one other compliance framework (GDPR, ISO 27001, PCI-DSS, or similar). • Strong technical foundation • you're comfortable reading code, reviewing AWS infrastructure, and working in a CI/CD environment. • Experience with vulnerability management tooling (e.g., Snyk, Semgrep, Qualys, Burp Suite, or equivalents). • Familiarity with AWS Secrets Manager and IAM best practices. Read full description View original posting →