Haystack
← Back to Jobs
Full time
Technology
RA

Software Engineer, Security

RaydarSan Francisco, California🇺🇸United StatesPosted 21 Aug 2026

Why This Role Stands Out

This is a unique opportunity to build and own a security program from the ground up at a rapidly growing fintech company, offering significant impact and career growth. If you are a hands-on security engineer eager to implement real improvements across infrastructure and applications, you will thrive in this foundational role. Apply now to shape the future of security for a company processing billions in transactions.

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
On Site
Location
San Francisco, California, United States
Posted
11 hours ago
RustAWSSOC 2CloudflareCockroachDBComplianceKafkaKubernetesPenetration TestingPulumiTerraformTriageTypeScriptWAF

Job Description

Our client is building modern financial infrastructure for businesses, combining reliable banking with industry-specific software, payments, rewards, and intelligent financial workflows. The platform powers more than $10 billion per year in business purchasing across thousands of customers. Founded in 2021, the company has grown to approximately 60 employees, reports more than $300 million in annual revenue, and has raised approximately $160 million, including a recent $100 million Series C.

This is the first dedicated security engineering hire, reporting directly to the CTO and owning the security program end to end. You will build and operate the security program across infrastructure security, application security, vulnerability management, penetration testing, bug bounty operations, and engineering support for compliance. This is a hands-on generalist role for someone who wants to ship real security improvements rather than operate only through policy and checklists.

What you will do:

• Build and own the security engineering program across infrastructure and application layers.

• Identify and prioritize security gaps, develop pragmatic remediation plans, and drive high-impact changes.

• Harden AWS infrastructure, Kubernetes and EKS clusters, server configurations, networking, access controls, and cloud security posture.

• Improve application security across services written in TypeScript, Go, Rust, and related technologies.

• Manage recurring penetration tests and drive findings through remediation.

• Operate the bug bounty program, triage vulnerability reports, and coordinate responses.

• Partner with engineering on secure design, code-level fixes, deployment patterns, secrets management, and defense in depth.

• Own technical work supporting SOC 2, PCI, monitoring, incident readiness, and vulnerability-management workflows.

• Approximately 2 to 8 years of hands-on security engineering, software security, infrastructure security, or closely related experience.

• Strong generalist ability across cloud infrastructure, application security, vulnerability management, and security operations.

• Hands-on experience securing AWS and container-orchestration environments such as Kubernetes or EKS.

• Experience assessing and remediating application vulnerabilities in production software.

• Experience managing penetration tests, bug bounty reports, or coordinated vulnerability disclosure.

• Familiarity with network security, identity and access controls, secrets management, web application defenses, and cloud posture management.

• Ability to write code, automate security work, and collaborate directly with software engineers on technical fixes.

• Strong risk judgment, high ownership, clear communication, and comfort operating independently.

• Ability to work on-site five days per week in San Francisco or willingness to relocate.

Nice to have: Experience with TypeScript, Go, Rust, CockroachDB, Kafka, Terraform, Pulumi, Cloudflare, AWS WAF, PCI, SOC 2, incident response, detection engineering, threat modeling, or secure architecture reviews.

$250,000 to $350,000 base salary, based on qualifications and experience, plus competitive equity. This role is on-site five days per week in San Francisco. Existing visa transfers, including OPT and H-1B transfers, may be considered.

Similar jobs