creditsesame5d ago
New
New
Senior Security Engineer
Remotesenior
EngineeringSecurity Engineer
0 views0 saves0 applied
Quick Summary
Requirements Summary
CA, CO, NC, NJ, NV, and TX.By clicking "Submit Application" (or related call to action),
Technical Tools
EngineeringSecurity Engineer
Credit Sesame is a leading financial wellness platform dedicated to helping consumers achieve better financial health through cutting-edge technology and data-driven solutions. With a decade of credit expertise and a proven track record of serving over 18 million users, Credit Sesame leverages AI and advanced analytics to empower individuals to better understand and manage their credit. Our recently launched Sesame Platform extends our mission by providing financial institutions with a turnkey AI-powered credit intelligence solution.
As our security engineer, you'll own security end-to-end for our platform — standing up open-source tooling, writing your own scripts and automation, and running assessments.
You'll...
As our security engineer, you'll own security end-to-end for our platform — standing up open-source tooling, writing your own scripts and automation, and running assessments.
You'll...
- Run security reviews for new tools, vendors, and projects — data handling, AI usage, DPAs, PII, authentication/authorization, and third-party security reports (SOC 2, PCI, ISO, pentest results);
- Own access and infrastructure security — IAM least-privilege reviews, S3/database access controls, environment segregation, service-to-service authentication, and network configuration audits (VPC flow logs, inbound/outbound rules);
- Run vulnerability management across cloud and endpoints, and manage IDS/IPS (e.g., Palo Alto Panorama, AWS WAF) and EDR/MDR tooling;
- Lead security incident response end to end — triage, investigate, contain, document, and build the runbooks as you go;
- Implement and maintain the technical controls supporting our PCI DSS and SOC 2 / ISO 27001 compliance programs, including internal audits, risk metrics, and disaster recovery planning;
- Partner with DevOps/IT on patch management and secure infrastructure defaults, and present tooling and risk recommendations to engineering leadership;
- Build our in-house AppSec scanning program — evaluate and pilot SAST/SCA/IaC tooling (Semgrep, Trivy, Upwind), integrate into GitLab CI and Jenkins, define severity-based remediation SLAs, and drive rollout across services;
- Build internal security tooling and automation — custom scripts and integrations (Python/boto3, APIs) that pull data from tools without native integrations into shared dashboards and reports;
- Build and tune detection pipelines — for example, feeding traffic/bot-protection alerts (Datadome) into our log platform (ELK/Kibana) and writing rules that catch real attack patterns;
- Threat-model and pentest our AI/LLM systems — scope risks like prompt injection and data exfiltration through MCP servers, coordinate external pentests where needed, and drive remediation;
- Maintain security policies and practices and drive training and adoption throughout the company.
- You have 7+ years of hands-on security engineering experience across application security, cloud security, and network/penetration testing — not just one lane;
- You've driven tooling or architecture decisions independently (evaluated options, made the call, defended it to leadership);
- You're self-directed, pragmatic, and ruthless about prioritization;
- You've built production automation from scratch — API integrations, custom collectors, or internal tooling — not just one-off scripts;
- You have hands-on experience deploying and running OSS security tools — Burp Suite Community/OWASP ZAP, Nmap, Nuclei, Metasploit, Semgrep, Trivy, Wazuh/OSSEC, ELK/Kibana, Prowler/ScoutSuite, HashiCorp Vault, or similar;
- You have solid AWS security experience;
- You have working knowledge of PCI DSS, SOC 2, and ISO 27001 — enough to implement controls and support audits;
- You're curious about emerging security domains and comfortable threat-modeling systems (like AI/LLM applications) that don't have an established playbook yet;
- You're an excellent communicator who can translate cost/coverage tradeoffs and technical risk for both engineers and executives;
- Bonus: OSCP, GPEN, or similar certifications; bug bounty experience; prior experience at a startup; or experience securing LLM/AI-based systems;
- BS in Computer Science or related field, or equivalent hands-on experience.
- You’ll have equity in a pre-IPO company backed by top VCs;
- We offer comprehensive medical, dental, and vision insurance;
- We offer a monthly home office stipend;
- We offer a professional development program to support your continued growth
- We offer flexible paid time off;
- We have 10 paid holidays and additional 6 Sesame Wellness days;
- We prize EQ and empathy, and have a culture that emphasizes total wellness, including work-life harmony.
We are open to hiring for this role in the following states where we are set up to hire employees: CA, CO, NC, NJ, NV, and TX.
By clicking "Submit Application" (or related call to action), you acknowledge that you have read the Credit Sesame Employment Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.
Location & Eligibility
Where is the job
Worldwide
Fully remote, anywhere in the world
Who can apply
Same as job location
Listing Details
- Posted
- August 17, 2026
- First seen
- August 19, 2026
- Last seen
- August 21, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 58%
- Scored at
- August 19, 2026
Signal breakdown
freshnesssource trustcontent trustemployer trust
External application · ~5 min on creditsesame's site
Please let creditsesame know you found this job on Jobera.
2 other jobs at creditsesame
View all →Explore open roles at creditsesame.
Similar Security Engineer jobs
View all →Senior Staff Security Engineer, AI Security
USD 224000-300000
Application Security Engineer
Full-time
C
Cala HealthSecurity Engineer
$155k–$190k/yr
Infosec Engineer
PermanentRemote
Senior AI Application Security Engineer
B
BoxRemoteEnterprise Application Security Engineer II
USD 113500-121300
Remote
Browse Similar Jobs
Devops Engineer3.6kDevOps & Infrastructure2.1kSecurity2.1kFullstack Developer2kEngineering Manager2kSoftware Architect1.7kQa Engineer1.6kBackend Developer1.5kMechanical Engineer1.3kElectrical Engineer1.1kMobile Developer1kFrontend Developer976Data Engineering935Backend Engineering931Project Engineer860Design Engineer791Frontend Engineering491Automation Engineer472Product Engineer467Process Engineer452
Newsletter
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
A
B
C
D
No spam. Unsubscribe at any time.