Senior Software Engineer, Security

Posted 18hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Security engineer building automated application and infrastructure security for Flex’s AI-native private bank. Protecting money movement, cloud access, vulnerability management, and secure development at scale.

Responsibilities:

  • Report directly to the CTO and set Flex’s security standard
  • Threat model money movement paths including the ledger and write path, card issuing, payouts, and stablecoin systems
  • Participate in design reviews for anything that touches money and continuously assess existing systems
  • Build secure-by-default infrastructure, including IaC guardrails, CI/CD supply-chain integrity, secrets handling, service isolation, and workload IAM
  • Build a just-in-time, least-privilege cloud access system
  • Own application security across new and existing systems
  • Build automated checks and secure defaults into the development lifecycle
  • Perform high-risk code reviews, dependency and SBOM hygiene, and effective static and dynamic analysis
  • Eliminate vulnerability classes through automation
  • Build tooling and golden paths that keep sensitive data out of logs
  • Run the vulnerability disclosure program end to end and grow it into a bug bounty program
  • Scope and manage external penetration tests and drive remediation
  • Build security automation, including AI-assisted triage and review
  • Partner with Engineering, IT and Corporate Engineering, Risk, and Compliance on security reviews and audits

Requirements:

  • Strong software engineer with security expertise; comfortable in the normal engineering interview loop
  • Substantial hands-on experience building or securing systems in a fast-moving environment, including a period as the most senior person doing this work
  • Real software engineering ability in Python, Go, TypeScript, or similar; not scripting alone
  • Hands-on AWS or GCP cloud infrastructure experience
  • Hands-on Terraform or equivalent Infrastructure as Code experience
  • Experience with containers and CI/CD pipelines that you have changed, not only used
  • Practical threat modeling on systems with real consequences
  • Experience with secrets management, workload identity, and service-to-service authorization
  • Experience handling inbound vulnerability reports, including at least one difficult reporter
  • Clear written communication and a bias toward writing things down
  • Experience shipping a security tool or control that engineers adopted
  • Ability to make risk-based security decisions and identify trust boundaries
  • Strongly preferred: platform, infrastructure, or DevOps background moved toward security
  • Strongly preferred: small-company or founder experience
  • Strongly preferred: experience running a VDP or bug bounty program, including triage
  • Strongly preferred: fintech, payments, or regulated-environment experience
  • Strongly preferred: production experience applying AI or LLM tooling to security work
  • OSCP or OSWE certifications are welcomed but do not substitute for an engineering track record

Benefits:

  • Meaningful equity if you help build something big
  • Founder-level exposure with direct access to leadership, customers, and investors
  • Small teams, high trust, and real accountability
  • Professional opportunity to work on AI, underwriting, compliance, payments, credit, and banking at scale