What you'll own- Secure SDLC: dependency scanning, static analysis, security review of high-risk changes, and coordinating annual penetration tests. Teach engineers to catch issues before you have to.
- Partner with DevOps on IAM, secrets management, network architecture, logging, and detection.
- Policies, risk assessment, and roadmap. Decide what a company our size and risk profile actually needs, and defend that reasoning to auditors, bankers, and internally.
- Own security questionnaires, vendor risk assessments, and customer security reviews. Banks conduct rigorous third-party risk management (often against FFIEC guidance).
- Endpoint management, access reviews, phishing resistance, offboarding hygiene. The unglamorous stuff that questionnaires ask about first.
- Own SOC 2 Type II end to end: control design, evidence collection, auditor management.
- Owning incident responsne, from writing the plan, run the tabletops, and lead if it's ever real. Banks have breach-notification expectations in their contracts. You'll know them cold.
What we're looking for- 5+ years in security engineering, with breadth across appsec, cloud security, and compliance.
- Hands-on: you can read code, write scripts, and configure cloud controls yourself
- You've owned or heavily contributed to a SOC 2 audit (or ISO 27001 / equivalent)
- Experience answering enterprise or financial-institution security reviews.
- Strong written communication.
- Judgment about proportionality: you know which risks matter at our scale and which controls are theater
Nice to have- Fintech or banking-vendor experience; familiarity with FFIEC, GLBA, or bank third-party risk management
- Experience as a first or early security hire
- Detection engineering / SIEM experience
- Familiarity with core banking integrations or handling of PII/KYC data flows
We offer equity, a sponsored 401K, parental leave, and fully paid health, vision, and dental insurance. Additional benefits include unlimited PTO, a remote work stipend, a life-style stipend, and twice-yearly company retreats.