
Senior Software Engineer, Security
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in United States.
• Directly report to the CTO and establish Flex’s security standards.
• Conduct threat modeling for money movement paths, which include the ledger and write path, card issuing, payouts, and stablecoin systems.
• Engage in design reviews for any financial-related systems and continuously evaluate existing infrastructures.
• Develop secure-by-default infrastructures, incorporating IaC guardrails, CI/CD supply-chain integrity, secrets management, service isolation, and workload IAM.
• Create a just-in-time, least-privilege cloud access framework.
• Oversee application security for both new and existing systems.
• Integrate automated checks and secure defaults into the development lifecycle.
• Conduct high-risk code reviews, maintain dependency hygiene and SBOM, and perform effective static and dynamic analysis.
• Automate the elimination of vulnerability classes.
• Develop tools and best practices that ensure sensitive data remains out of logs.
• Manage the vulnerability disclosure program from start to finish and evolve it into a bug bounty initiative.
• Define the scope for external penetration tests and lead remediation efforts.
• Create security automation solutions, including AI-assisted triage and review.
• Collaborate with Engineering, IT, Corporate Engineering, Risk, and Compliance teams on security reviews and audits.
• Strong software engineer with a focus on security; comfortable navigating the standard engineering interview process.
• Significant hands-on experience in building or securing systems within a fast-paced environment, including a role as the leading expert in this area.
• Proficient software engineering skills in Python, Go, TypeScript, or similar languages; experience beyond basic scripting.
• Practical experience with AWS or GCP cloud infrastructure.
• Hands-on experience with Terraform or equivalent Infrastructure as Code tools.
• Experience with containers and CI/CD pipelines that you have actively modified, not just utilized.
• Practical experience in threat modeling on systems with significant real-world impacts.
• Familiarity with secrets management, workload identity, and service-to-service authorization.
• Experience in handling inbound vulnerability reports, including challenging cases.
• Strong written communication skills with an inclination towards documentation.
• Proven experience delivering a security tool or control that has been adopted by engineers.
• Ability to make risk-based security decisions and identify trust boundaries effectively.
• Strongly preferred: background in platform, infrastructure, or DevOps that transitioned toward security.
• Strongly preferred: experience in a small company or as a founder.
• Strongly preferred: experience managing a VDP or bug bounty program, including triage processes.
• Strongly preferred: background in fintech, payments, or regulated industries.
• Strongly preferred: experience applying AI or LLM tools to security tasks in production settings.
• OSCP or OSWE certifications are appreciated but do not replace a solid engineering track record.
• Meaningful equity opportunities for those contributing to significant projects.
• Founder-level exposure with direct access to leadership, customers, and investors.
• Small teams that foster high trust and genuine accountability.
• Professional opportunity to engage with AI, underwriting, compliance, payments, credit, and banking at scale.
Trail of Bits
Newxel
Wealthsimple
Xcelerate Solutions
Get handpicked remote jobs straight to your inbox weekly.