Member of Technical Staff, Security Engineer
Posted 2 days ago
About the Role
This is a foundational security engineering role at a fast-moving fintech startup, where you will own the entire security function end-to-end. You will be the first dedicated security hire, setting the standard for how the team builds, ships, and operates securely from the ground up.
What You'll Do
Own infrastructure security across the full AWS environment, including VPC and VPN peering, network segmentation, IAM, and secrets management, designing guardrails that make the secure default the fastest one.
Take ownership of application security across web and desktop clients, embedding threat modeling, dependency and supply-chain controls, and secure code review into how the team designs and ships.
Build and manage identity and access controls (SSO, RBAC, least-privilege) for both human users and AI agents, ensuring every actor reaches exactly what it needs and nothing more.
Design audit trails and access controls that make autonomous agent activity fully reconstructable, covering what it did, on whose behalf, with what data, and why.
Own IT security in partnership with a managed service provider, covering devices, endpoints, and access for a small in-office team.
Stand up and run compliance, auditability, bug bounty, vulnerability disclosure, and penetration testing programs that demonstrate security posture to clients, partners, and auditors.
What We're Looking For
3 or more years in security engineering or infrastructure security roles with hands-on delivery of AWS security controls (VPC, VPN peering, network segmentation, IAM, secrets management).
Experience owning security end-to-end as the first or sole security hire at a startup, building programs from scratch with high autonomy.
Hands-on application security experience including threat modeling, dependency and supply-chain controls, and secure code review.
Identity and access management implementation experience covering SSO, RBAC, and least-privilege design for both human and non-human actors.
IT security experience including endpoint security, device management, and access controls.
Compliance and auditability program experience such as SOC 2, penetration test coordination, and vulnerability management.
Familiarity with Kubernetes and related cloud-native tooling is a plus.
Experience in financial services or other regulated industries is a plus.
Experience securing AI or autonomous agent systems, including audit trails and scoped access controls, is a plus.
Compensation & Benefits
Salary range: $150,000 to $250,000 USD annually. Visa sponsorship is not available for this role.
Location
This is a full-time, on-site role based in New York City, NY, United States.
Similar Security Engineer jobs(8)
Jobr aggregates jobs directly from company career portals — no middlemen. Our team applies on your behalf with AI-tailored resumes, reviewed by a human before submission.