Member of Technical Staff, Security Engineer
New York City, NY - USA
Job Summary
This is a foundational security engineering role at a fintech startup where you will own the entire security program end-to-end as the first dedicated security hire. From infrastructure to application to compliance you will shape how security is built into the product and culture from day one making the secure path the default path for a fast-moving engineering team.
- Own infrastructure security across the full AWS environment including VPC and VPN peering network segmentation IAM and secrets management.
- Embed application security practices such as threat modeling dependency and supply-chain controls and secure code review into how the team designs and ships software across web and desktop clients.
- Build and manage identity and access controls (SSO RBAC least-privilege) for both human users and AI agents ensuring every actor has access to exactly what it needs.
- Design audit trails and access controls that make autonomous agent activity fully reconstructable capturing what it did on whose behalf with what data and why.
- Partner with the IT managed service provider to manage endpoint security device management and access controls for an in-office team.
- Stand up and run compliance auditability bug bounty vulnerability disclosure and pentest programs that demonstrate security posture to clients partners and auditors.
- 3 or more years in security engineering or infrastructure security with hands-on delivery of AWS security controls (VPC VPN peering network segmentation IAM secrets management).
- Hands-on application security experience including threat modeling dependency and supply-chain controls and secure code review.
- Experience owning security end-to-end as the first or sole security hire at a startup building programs from the ground up with minimal established process.
- Identity and access management implementation experience covering SSO RBAC and least-privilege design for both human and non-human actors.
- IT security experience spanning endpoint security device management and access controls.
- Compliance and auditability program experience such as SOC 2 pentest coordination and vulnerability management.
- Comfort operating autonomously in fast-moving environments with broad ownership.
- Experience in financial services or other regulated industries is a plus.
- Experience securing AI or agent systems including audit trails for autonomous actors is a plus.
- Experience standing up bug bounty and vulnerability disclosure programs from scratch is a plus.
Salary range: $150000 to $250000 USD annually. Visa sponsorship is not available for this role.
This role is on-site in New York City NY United States.