Senior Software Engineer, Security
Posted 18hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Security engineer building automated application and infrastructure security for Flex’s AI-native private bank. Protecting money movement, cloud access, vulnerability management, and secure development at scale.
Responsibilities:
- Report directly to the CTO and set Flex’s security standard
- Threat model money movement paths including the ledger and write path, card issuing, payouts, and stablecoin systems
- Participate in design reviews for anything that touches money and continuously assess existing systems
- Build secure-by-default infrastructure, including IaC guardrails, CI/CD supply-chain integrity, secrets handling, service isolation, and workload IAM
- Build a just-in-time, least-privilege cloud access system
- Own application security across new and existing systems
- Build automated checks and secure defaults into the development lifecycle
- Perform high-risk code reviews, dependency and SBOM hygiene, and effective static and dynamic analysis
- Eliminate vulnerability classes through automation
- Build tooling and golden paths that keep sensitive data out of logs
- Run the vulnerability disclosure program end to end and grow it into a bug bounty program
- Scope and manage external penetration tests and drive remediation
- Build security automation, including AI-assisted triage and review
- Partner with Engineering, IT and Corporate Engineering, Risk, and Compliance on security reviews and audits
Requirements:
- Strong software engineer with security expertise; comfortable in the normal engineering interview loop
- Substantial hands-on experience building or securing systems in a fast-moving environment, including a period as the most senior person doing this work
- Real software engineering ability in Python, Go, TypeScript, or similar; not scripting alone
- Hands-on AWS or GCP cloud infrastructure experience
- Hands-on Terraform or equivalent Infrastructure as Code experience
- Experience with containers and CI/CD pipelines that you have changed, not only used
- Practical threat modeling on systems with real consequences
- Experience with secrets management, workload identity, and service-to-service authorization
- Experience handling inbound vulnerability reports, including at least one difficult reporter
- Clear written communication and a bias toward writing things down
- Experience shipping a security tool or control that engineers adopted
- Ability to make risk-based security decisions and identify trust boundaries
- Strongly preferred: platform, infrastructure, or DevOps background moved toward security
- Strongly preferred: small-company or founder experience
- Strongly preferred: experience running a VDP or bug bounty program, including triage
- Strongly preferred: fintech, payments, or regulated-environment experience
- Strongly preferred: production experience applying AI or LLM tooling to security work
- OSCP or OSWE certifications are welcomed but do not substitute for an engineering track record
Benefits:
- Meaningful equity if you help build something big
- Founder-level exposure with direct access to leadership, customers, and investors
- Small teams, high trust, and real accountability
- Professional opportunity to work on AI, underwriting, compliance, payments, credit, and banking at scale


















