Senior Security Engineer

Credit Sesame

Mountain View (CA)

On-site

USD 170,000 - 215,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity in pre-IPO company
Health, dental, and vision insurance
Monthly home office stipend
Professional development program
Flexible paid time off
11 holidays + 6 wellness days

Job summary

Credit Sesame is seeking a Senior Security Engineer to lead security reviews, protect access controls, and drive incident response across cloud and on‑premises environments. You will implement PCI DSS and SOC 2 controls, partner with DevOps for secure defaults, and build automated AppSec scanning and tooling.

You will contribute to threat modeling for AI/LLM systems, deploy OSS security tools, and mentor teams on risk-aware decisions.

Qualifications

  • 7+ years of hands-on security engineering experience across application, cloud, and network security.
  • Experience deploying and running OSS security tools; familiar with PCI/SOC2/ISO controls.

Responsibilities

  • Run security reviews for new tools, vendors, and projects—data handling, AI usage, DPAs, PII, authentication/authorization, and third-party security reports.
  • Own access and infrastructure security—IAM least-privilege reviews, S3/database access controls, environment segregation, and network audits.
  • Lead security incident response end to end—triage, investigate, contain, document, and build runbooks.
  • Implement controls supporting PCI DSS and SOC 2/ISO 27001 programs, including audits and disaster recovery planning.
  • Partner with DevOps/IT on patch management and secure infrastructure defaults; present risk to leadership.
  • Build in-house AppSec scanning and automation—define SLAs and rollout tooling.

Skills

Security engineering
Cloud security
AppSec/Threat modelling
AWS security
Automation & scripting

Education

BS in Computer Science or related field

Tools

Burp Suite
OWASP ZAP
Nmap
Semgrep
Trivy
ELK/Kibana
HashiCorp Vault

Job description

Credit Sesame is a leading financial wellness platform dedicated to helping consumers achieve better financial health through cutting-edge technology and data-driven solutions. With a decade of credit expertise and a proven track record of serving over 18 million users, Credit Sesame leverages AI and advanced analytics to empower individuals to better understand and manage their credit. Our recently launched Sesame Platform extends our mission by providing financial institutions with a turnkey AI-powered credit intelligence solution.

You’ll
  • Run security reviews for new tools, vendors, and projects — data handling, AI usage, DPAs, PII, authentication/authorization, and third-party security reports (SOC 2, PCI, ISO, pentest results);
  • Own access and infrastructure security — IAM least-privilege reviews, S3/database access controls, environment segregation, service-to-service authentication, and network configuration audits (VPC flow logs, inbound/outbound rules);
  • Run vulnerability management across cloud and endpoints, and manage IDS/IPS (e.g., Palo Alto Panorama, AWS WAF) and EDR/MDR tooling;
  • Lead security incident response end to end — triage, investigate, contain, document, and build the runbooks as you go;
  • Implement and maintain the technical controls supporting our PCI DSS and SOC 2 / ISO 27001 compliance programs, including internal audits, risk metrics, and disaster recovery planning;
  • Partner with DevOps/IT on patch management and secure infrastructure defaults, and present tooling and risk recommendations to engineering leadership;
  • Build our in-house AppSec scanning program — evaluate and pilot SAST/SCA/IaC tooling (Semgrep, Trivy, Upwind), integrate into GitLab CI and Jenkins, define severity-based remediation SLAs, and drive rollout across services;
  • Build internal security tooling and automation — custom scripts and integrations (Python/boto3, APIs) that pull data from tools without native integrations into shared dashboards and reports;
  • Build and tune detection pipelines — for example, feeding traffic/bot-protection alerts (Datadome) into our log platform (ELK/Kibana) and writing rules that catch real attack patterns;
  • Threat-model and pentest our AI/LLM systems — scope risks like prompt injection and data exfiltration through MCP servers, coordinate external pentests where needed, and drive remediation;
  • Maintain security policies and practices and drive training and adoption throughout the company.
You’re a great fit because…
  • You have 7+ years of hands-on security engineering experience across application security, cloud security, and network/penetration testing — not just one lane;
  • You’ve driven tooling or architecture decisions independently (evaluated options, made the call, defended it to leadership);
  • You’re self-directed, pragmatic, and ruthless about prioritization;
  • You’ve built production automation from scratch — API integrations, custom collectors, or internal tooling — not just one‑off scripts;
  • You have hands‑on experience deploying and running OSS security tools — Burp Suite Community/OWASP ZAP, Nmap, Nuclei, Metasploit, Semgrep, Trivy, Wazuh/OSSEC, ELK/Kibana, Prowler/ScoutSuite, HashiCorp Vault, or similar;
  • You have solid AWS security experience;
  • You have working knowledge of PCI DSS, SOC 2, and ISO 27001 — enough to implement controls and support audits;
  • You’re curious about emerging security domains and comfortable threat‑modeling systems (like AI/LLM applications) that don’t have an established playbook yet;
  • You’re an excellent communicator who can translate cost/coverage tradeoffs and technical risk for both engineers and executives;
  • Bonus: OSCP, GPEN, or similar certifications; bug bounty experience; prior experience at a startup; or experience securing LLM/AI‑based systems;
  • BS in Computer Science or related field, or equivalent hands‑on experience.
You’ll love it here because…
  • You’ll have equity in a pre‑IPO company backed by top VCs;
  • We offer comprehensive medical, dental, and vision insurance;
  • We offer a monthly home office stipend;
  • We offer a professional development program to support your continued growth;
  • We offer flexible paid time off;
  • We have 10 paid holidays and additional 6 Sesame Wellness days;
  • We prize EQ and empathy, and have a culture that emphasizes total wellness, including work‑life harmony.

At Credit Sesame, base pay is one part of our total compensation package. The estimated pay range for this role is $170,000 - $215,000 with actual salary based on a candidate’s location, qualifications, skills, and experience. Additionally, this role is eligible to participate in Credit Sesame’s equity plans.

We are open to hiring for this role in the following states where we are set up to hire employees: CA, CO, NC, NJ, NV, and TX.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Counsel
Senior Counsel

creditsesame • Mountain View (CA)

On-site
USD 190,000 - 240,000
Equity in a pre-IPO company
Medical, dental, and vision insurance
Monthly home office stipend
+4
Senior Counsel
Senior Counsel

Credit Sesame • Mountain View (CA)

On-site
USD 190,000 - 240,000
Equity in a pre-IPO company
Medical, dental, and vision insurance
Monthly home office stipend
+4
Senior Security Engineer at Credit Genie Philadelphia, PA
Senior Security Engineer at Credit Genie Philadelphia, PA

Credit Genie • Philadelphia

On-site
USD 150,000 - 250,000
100% company-paid medical, dental, and vision coverage
Monthly fitness reimbursement
401(k) with 2.5% match
+2
Senior Security Engineer - AI/Cloud Security Lead (Equity)
Senior Security Engineer - AI/Cloud Security Lead (Equity)

Credit Sesame • United States

Remote
USD 170,000 - 215,000
Equity in a pre-IPO company
Medical, dental, and vision insurance
Home office stipend
+4
Chief Information Security Officer
Chief Information Security Officer

The Security Executive Council • San Francisco (CA)

On-site
USD 150,000 - 200,000
Company-paid medical, dental, and vision coverage
Monthly fitness reimbursement
401(k) with a 2.5% match
+2
Senior Security Engineer II
Senior Security Engineer II

Credit Karma • Charlotte (NC)

On-site
USD 120,000 - 150,000
Medical and Dental Coverage
Retirement Plan
Commuter Benefits
+4
Senior Corporate Security Engineer
Senior Corporate Security Engineer

United States Digital Space LLC • Bellevue (CA)

Hybrid
USD 166,000 - 195,000
Health insurance
Equity ownership
401(k) matching
+2
Head of Security Engineering
Head of Security Engineering

January • New York (NY)

On-site
USD 180,000 - 240,000
Principal Engineer, Security
Principal Engineer, Security

United States Digital Space LLC • Boston (MA)

On-site
USD 244,000 - 366,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Cogent-Security • United States

On-site
USD 100,000 - 300,000