Sr. Security Engineer
Odyssey partners with state agencies to design, launch, and operate Education Savings Account (ESA) and grant programs, providing the technology, program operations, vendor ecosystem, and family experience that make these programs work in real-world settings. We operate across 6 states, powering programs serving 200,000+ students and over $1B in education funding. Our work sits at the intersection of GovTech, EdTech, and FinTech, delivering civic infrastructure that determines whether families can access life-changing educational opportunities.
About the Role
As Odyssey's first Security Engineer, you'll have full ownership of our security posture—shaping strategy, building programs from the ground up, and driving best practices across our entire technology stack and product suite. This high-impact, high-visibility role involves partnering with cross-functional teams to embed security into everything we build and ship, championing solutions to emerging security challenges, and ensuring we stay ahead of an evolving threat landscape. You embrace AI tools to accelerate threat detection, streamline vulnerability analysis, and improve incident response.
Responsibilities
- Collaborate closely with cross-functional teams to proactively identify, assess, and remediate security risks across Odyssey's products and infrastructure, proposing enhanced controls and process improvements where needed
- Perform static and dynamic vulnerability assessments and drive remediation efforts through to resolution
- Evaluate security risks in AI systems and data pipelines, and leverage AI-assisted tooling to enhance threat detection, vulnerability analysis, and security operations
- Maintain and mature Odyssey's SOC 2 Type II program, ensuring a secure environment for vendors, customers, end-users, and employees
- Design and implement security controls across Odyssey's full technology stack—from application layer to cloud infrastructure
- Translate complex security findings into clear, actionable remediation steps for both technical and non-technical stakeholders
- Continuously audit policies, controls, and procedures to keep security practices ahead of an evolving threat landscape
- Embed security seamlessly into the developer workflow—including CI/CD pipelines, code review processes, and internal tooling—without compromising velocity
Requirements
- 6+ years of Software Engineering experience with a focus on security, cloud security, DevOps, network security, or similar domains
- Solid understanding of industry standards and compliance frameworks (SOC 2, ISO 27001, etc.) with hands-on experience driving organizational adherence
- Experience applying AI-assisted tooling to accelerate threat detection, code review, and vulnerability analysis
- Experience deploying and operating SAST, DAST, and SCA tools across the software development lifecycle
- Strong track record managing security projects end-to-end—from planning through delivery—within timelines and budgets
- Experience with penetration testing tools, techniques, and methodologies, with a clear understanding of common vulnerabilities and remediation strategies
Schedule
This role is hybrid, based out of our NYC office in Tribeca. The full team comes together once a year for an offsite. Candidates may be asked to come in person for at least one interview.
Pay
The salary range for this role is $180,000 - $220,000 plus generous equity, depending on experience and location.
Benefits
- Medical, Dental, and Vision plans
- Health services
- Short-term disability
- Unlimited PTO