An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Oolka is seeking a hands-on senior security engineer to own security across AWS infrastructure, the application layer, and data protection for a consumer fintech platform handling sensitive financial and personal data.
You'll work across cloud, data, and code, designing security for AI-assisted features while building the foundations of our security program, threat models, and incident response processes.
Oolka is looking for a hands-on senior security engineer to own security across our AWS infrastructure, application layer, and data protection posture for a consumer fintech platform handling sensitive financial and personal data.
Two things make this role unusual. First, it's genuinely full-stack security — cloud, application, and data, rather than one lane. Second, we're shipping AI-assisted features into a product that touches real financial data, which means you'd be designing the security model for those features at the same time as you're running the foundations underneath them.
You'll work alongside engineering to build security into the SDLC rather than bolting it on afterward. Expect to move between AWS console and Terraform, code review, AI feature design reviews, and the occasional policy document or audit response.
We're putting LLM-backed features in front of customer financial data, and the threat model doesn't map cleanly onto anything established. You'd own:
In line with current OWASP LLM guidance, but we're looking for someone who's solved this in production rather than read about it.
Design and maintain our AWS security baseline — account structure, network segmentation, IAM least-privilege — and run our detection stack (GuardDuty, Security Hub, CloudTrail, Config). You'll be first responder when something looks anomalous, and you'll own the tooling that makes anomalies visible in the first place.
Encryption strategy (KMS key management, field-level encryption and tokenization for high-sensitivity data like PAN and credit information), data classification via Macie, and access governance across RDS, MongoDB and S3. You'll also own data handling policy for non-production environments — making sure real customer PII never reaches staging or QA.
Build and maintain our SAST/SCA/secrets-scanning pipeline in CI/CD, triage and drive remediation with engineering teams, run or coordinate periodic penetration testing, and review code and architecture for injection flaws — SQL, NoSQL, and prompt injection in our AI-assisted features.
WAF rule sets, DDoS posture (Shield, rate limiting), and API-level abuse protection — balancing controls against legitimate traffic and product experience.
Maintain our incident response plan and run periodic tabletop exercises alongside our existing DR drill practice, support ISO 27001 / RBI / DPDP-aligned control documentation, and represent security in external audits. Your runbooks will need to cover AI-specific incidents too — a successful injection, an agent acting outside its intended scope, PII surfacing in model output.
You’ll partner closely with engineering leadership rather than operating as a separate gatekeeping function. The goal is security that ships with the product, not security that blocks it afterward. Expect meaningful time in AWS console and Terraform, in code review, in AI feature design discussions, and in conversation with auditors.