
Principal Information Security Engineer
Posted Jul 15

Posted Jul 15
This is a fully remote position, open to applicants in United States.
• Create and develop internal security tools from the ground up, including agent-based security solutions, code analysis utilities, dynamic scanning, and security assessment instruments.
• Detect vulnerabilities within SentiLink's AWS infrastructure, encompassing application code, cloud service configurations, and their integrations.
• Design AI-assisted and agent-based tools to enhance offensive security testing capabilities beyond the capacity of a small team working manually.
• Establish and manage security automation that enhances detection, response, and remediation processes throughout the organization.
• Engage in hands-on penetration testing and vulnerability research targeting SentiLink's infrastructure and applications.
• Collaborate with engineering teams to address findings and incorporate security into the development lifecycle without hindering their progress.
• Take part in the security on-call rotation, which includes incident response and routine response evaluations.
• Contribute to threat modeling and security design assessments for new systems, prioritizing cloud integrations and identity flows.
• Keep abreast of offensive security methodologies, AI-driven security tools, and emerging attack patterns pertinent to fintech and identity verification.
• Over 8 years of experience in security engineering, software engineering with a security emphasis, or closely related fields.
• Proficient in at least one systems programming language (Go, Rust, C++) and one higher-level programming language (Python, TypeScript).
• Demonstrated capability to design and deliver production software from start to finish.
• Extensive knowledge of AWS infrastructure, including IAM, EKS, RDS, networking, and managed services.
• Proven experience in identifying security misconfigurations and vulnerabilities across cloud architectures, application code, and their integrations.
• Background in conducting or developing tools for penetration testing, vulnerability assessment, or red team operations.
• History of building security automation and tools from the ground up.
• Able to operate independently on unclear challenges without extensive processes or supervision.
• Excellent communication skills and the ability to work collaboratively with engineers who lack security expertise.
• Employer-covered group health insurance for you and your dependents.
• 401(k) plan with employer matching (or equivalent for roles based outside the US).
• Flexible paid time off policy.
• Regular in-person events for the entire company.
• Home office stipend, among other perks!
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.