Senior Security Engineer @Credit Sesame
All Others
Salary $170,000 - $215..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1wk ago

[Hiring] Senior Security Engineer @Credit Sesame

1wk ago - Credit Sesame is hiring a remote Senior Security Engineer. πŸ’Έ Salary: $170,000 - $215,000 per year πŸ“Location: USA

Role Description

As our security engineer, you'll own security end-to-end for our platform β€” standing up open-source tooling, writing your own scripts and automation, and running assessments.

  • Run security reviews for new tools, vendors, and projects β€” data handling, AI usage, DPAs, PII, authentication/authorization, and third-party security reports (SOC 2, PCI, ISO, pentest results);
  • Own access and infrastructure security β€” IAM least-privilege reviews, S3/database access controls, environment segregation, service-to-service authentication, and network configuration audits (VPC flow logs, inbound/outbound rules);
  • Run vulnerability management across cloud and endpoints, and manage IDS/IPS (e.g., Palo Alto Panorama, AWS WAF) and EDR/MDR tooling;
  • Lead security incident response end to end β€” triage, investigate, contain, document, and build the runbooks as you go;
  • Implement and maintain the technical controls supporting our PCI DSS and SOC 2 / ISO 27001 compliance programs, including internal audits, risk metrics, and disaster recovery planning;
  • Partner with DevOps/IT on patch management and secure infrastructure defaults, and present tooling and risk recommendations to engineering leadership;
  • Build our in-house AppSec scanning program β€” evaluate and pilot SAST/SCA/IaC tooling (Semgrep, Trivy, Upwind), integrate into GitLab CI and Jenkins, define severity-based remediation SLAs, and drive rollout across services;
  • Build internal security tooling and automation β€” custom scripts and integrations (Python/boto3, APIs) that pull data from tools without native integrations into shared dashboards and reports;
  • Build and tune detection pipelines β€” for example, feeding traffic/bot-protection alerts (Datadome) into our log platform (ELK/Kibana) and writing rules that catch real attack patterns;
  • Threat-model and pentest our AI/LLM systems β€” scope risks like prompt injection and data exfiltration through MCP servers, coordinate external pentests where needed, and drive remediation;
  • Maintain security policies and practices and drive training and adoption throughout the company.

Qualifications

  • You have 7+ years of hands-on security engineering experience across application security, cloud security, and network/penetration testing β€” not just one lane;
  • You've driven tooling or architecture decisions independently (evaluated options, made the call, defended it to leadership);
  • You're self-directed, pragmatic, and ruthless about prioritization;
  • You've built production automation from scratch β€” API integrations, custom collectors, or internal tooling β€” not just one-off scripts;
  • You have hands-on experience deploying and running OSS security tools β€” Burp Suite Community/OWASP ZAP, Nmap, Nuclei, Metasploit, Semgrep, Trivy, Wazuh/OSSEC, ELK/Kibana, Prowler/ScoutSuite, HashiCorp Vault, or similar;
  • You have solid AWS security experience;
  • You have working knowledge of PCI DSS, SOC 2, and ISO 27001 β€” enough to implement controls and support audits;
  • You're curious about emerging security domains and comfortable threat-modeling systems (like AI/LLM applications) that don't have an established playbook yet;
  • You're an excellent communicator who can translate cost/coverage tradeoffs and technical risk for both engineers and executives;
  • Bonus: OSCP, GPEN, or similar certifications; bug bounty experience; prior experience at a startup; or experience securing LLM/AI-based systems;
  • BS in Computer Science or related field, or equivalent hands-on experience.

Benefits

  • You’ll have equity in a pre-IPO company backed by top VCs;
  • We offer comprehensive medical, dental, and vision insurance;
  • We offer a monthly home office stipend;
  • We offer a professional development program to support your continued growth;
  • We offer flexible paid time off;
  • We have 10 paid holidays and additional 6 Sesame Wellness days;
  • We prize EQ and empathy, and have a culture that emphasizes total wellness, including work-life harmony.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Engineer @Credit Sesame
All Others
Salary $170,000 - $215..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1wk ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,069+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later