Jobs · Education

Senior Security Engineer

Credit Sesame · Mountain View, CA · 1 wk ago
RemoteRemoteEducation$170k–$215k/yrFull-time

About the role

As our security engineer, you'll own security end-to-end for our platform — standing up open-source tooling, writing your own scripts and automation, and running assessments on our engineering team.

Responsibilities

  • Run security reviews for new tools, vendors, and projects — data handling, AI usage, DPAs, PII, authentication/authorization, and third-party security reports (SOC 2, PCI, ISO, pentest results)
  • Own access and infrastructure security — IAM least-privilege reviews, S3/database access controls, environment segregation, service-to-service authentication, and network configuration audits (VPC flow logs, inbound/outbound rules)
  • Run vulnerability management across cloud and endpoints, and manage IDS/IPS (e.g., Palo Alto Panorama, AWS WAF) and EDR/MDR tooling
  • Lead security incident response end to end — triage, investigate, contain, document, and build the runbooks as you go
  • Implement and maintain the technical controls supporting our PCI DSS and SOC 2 / ISO 27001 compliance programs, including internal audits, risk metrics, and disaster recovery planning
  • Partner with DevOps/IT on patch management and secure infrastructure defaults, and present tooling and risk recommendations to engineering leadership
  • Build our in-house AppSec scanning program — evaluate and pilot SAST/SCA/IaC tooling (Semgrep, Trivy, Upwind), integrate into GitLab CI and Jenkins, define severity-based remediation SLAs, and drive rollout across services
  • Build internal security tooling and automation — custom scripts and integrations (Python/boto3, APIs) that pull data from tools without native integrations into shared dashboards and reports
  • Build and tune detection pipelines — for example, feeding traffic/bot-protection alerts (Datadome) into our log platform (ELK/Kibana) and writing rules that catch real attack patterns
  • Threat-model and pentest our AI/LLM systems — scope risks like prompt injection and data exfiltration through MCP servers, coordinate external pentests where needed, and drive remediation
  • Maintain security policies and practices and drive training and adoption throughout the company

Requirements

  • 7+ years of hands-on security engineering experience across application security, cloud security, and network/penetration testing — not just one lane
  • Driven tooling or architecture decisions independently (evaluated options, made the call, defended it to leadership)
  • Self-directed, pragmatic, and ruthless about prioritization
  • Built production automation from scratch — API integrations, custom collectors, or internal tooling — not just one-off scripts
  • Hands-on experience deploying and running OSS security tools — Burp Suite Community/OWASP ZAP, Nmap, Nuclei, Metasploit, Semgrep, Trivy, Wazuh/OSSEC, ELK/Kibana, Prowler/ScoutSuite, HashiCorp Vault, or similar
  • Solid AWS security experience
  • Working knowledge of PCI DSS, SOC 2, and ISO 27001 — enough to implement controls and support audits
  • Curious about emerging security domains and comfortable threat-modeling systems (like AI/LLM applications) that don't have an established playbook yet
  • Excellent communicator who can translate cost/coverage tradeoffs and technical risk for both engineers and executives
  • BS in Computer Science or related field, or equivalent hands-on experience

Qualifications

  • OSCP, GPEN, or similar certifications
  • Bug bounty experience
  • Experience securing LLM/AI-based systems

Benefits

  • Equity in a pre-IPO company backed by top VCs
  • Comprehensive medical, dental, and vision insurance
  • Monthly home office stipend
  • Professional development program to support your continued growth
  • Flexible paid time off
  • 10 paid holidays and additional 6 Sesame Wellness days

We prize EQ and empathy, and have a culture that emphasizes total wellness, including work-life harmony.

Pay

The estimated pay range for this role is $170,000 - $215,000 with actual salary based on a candidate’s location, qualifications, skills, and experience. Additionally, this role is eligible to participate in Credit Sesame’s equity plans.

We are open to hiring for this role in the following states where we are set up to hire employees: CA, CO, NC, NJ, NV, and TX.

Similar jobs

Senior Security Engineer

CGIPennsylvania, United States· 2 wk ago
Information Technology$57k–$154k/yrapply on cgi.njoyn.com