Senior Security Engineer, AI & Cloud Defense

Credit Sesame, Inc.

United States

Remote

USD 170,000 - 215,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Credit Sesame, Inc. is seeking a security engineer who will own security end-to-end for our platform, stand up open-source tooling, write scripts, and run assessments across data handling, AI usage, and third-party security reports.

You will lead incident response, implement PCI DSS/SOC 2/ISO 27001 controls, collaborate with DevOps, and build AppSec scanning into CI pipelines while expanding internal security tooling.

Qualifications

  • 7+ years of hands-on security engineering experience across application security, cloud security, and network/penetration testing.
  • Driven tooling or architecture decisions independently and defend them to leadership.
  • Self-directed, pragmatic, and ruthless about prioritization.
  • Built production automation from scratch — API integrations, custom collectors, or internal tooling.
  • Hands‑on experience deploying OSS security tools (Burp Suite, OWASP ZAP, Nmap, Nuclei, Metasploit, Semgrep, Trivy, Wazuh/OSSEC, ELK/Kibana, Prowler/ScoutSuite, HashiCorp Vault, or similar).
  • Solid AWS security experience.
  • Working knowledge of PCI DSS, SOC 2, and ISO 27001.
  • Curious about emerging security domains and threat-modeling AI/LLM systems.
  • Excellent communicator who can translate risk for engineers and executives.
  • Bonus: OSCP, GPEN, bug bounty, startup experience, or securing LLM/AI systems.
  • BS in Computer Science or related field, or equivalent hands‑on experience.

Responsibilities

  • Run security reviews for new tools, vendors, and projects (data handling, AI usage, DPAs, PII, authentication/authorization, and third-party security reports).
  • Own access and infrastructure security with IAM least-privilege reviews, S3/database access controls, environment segregation, service-to-service authentication, and network configuration audits (VPC flow logs, inbound/outbound rules).
  • Run vulnerability management across cloud and endpoints, and manage IDS/IPS (e.g., Palo Alto Panorama, AWS WAF) and EDR/MDR tooling.
  • Lead security incident response end to end — triage, investigate, contain, document, and build runbooks.
  • Implement and maintain the technical controls supporting PCI DSS and SOC 2 / ISO 27001 compliance programs, including internal audits, risk metrics, and disaster recovery planning.
  • Partner with DevOps/IT on patch management and secure infrastructure defaults, and present tooling and risk recommendations to engineering leadership.
  • Build our in-house AppSec scanning program — evaluate and pilot SAST/SCA/IaC tooling (Semgrep, Trivy, Upwind), integrate into GitLab CI and Jenkins, define severity-based remediation SLAs, and drive rollout across services.
  • Build internal security tooling and automation — custom scripts and integrations (Python/boto3, APIs) that pull data from tools without native integrations into shared dashboards and reports.
  • Build and tune detection pipelines — e.g., feeding traffic/bot-protection alerts (Datadome) into our log platform (ELK/Kibana) and writing rules that catch real attack patterns.
  • Threat-model and pentest our AI/LLM systems — scope risks like prompt injection and data exfiltration through MCP servers, coordinate external pentests where needed, and drive remediation.
  • Maintain security policies and practices and drive training and adoption throughout the company.

Skills

Security engineering
Cloud security
Network testing
Threat modeling
OSS security tools
AWS security
Communication

Education

BS in CS or related field

Tools

Burp Suite
OWASP ZAP
Nmap
Nuclei
Metasploit
Semgrep
Trivy
Wazuh
OSSEC
ELK
Prowler
ScoutSuite
HashiCorp Vault

Job description

Credit Sesame, Inc. is seeking a security engineer who will own security end-to-end for our platform, stand up open-source tooling, write scripts, and run assessments across data handling, AI usage, and third-party security reports.

You will lead incident response, implement PCI DSS/SOC 2/ISO 27001 controls, collaborate with DevOps, and build AppSec scanning into CI pipelines while expanding internal security tooling.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Cloud & AppSec
Senior Security Engineer - Cloud & AppSec

Credit Sesame • Mountain View (CA)

On-site
USD 170,000 - 215,000
Equity in pre-IPO company
Health, dental, and vision insurance
Monthly home office stipend
+3
Remote Security Engineer for AI & Cloud Platform
Remote Security Engineer for AI & Cloud Platform

Cincsystems • United States

Remote
USD 130,000 - 190,000
Senior Security Engineer - Enterprise Security for AI SaaS
Senior Security Engineer - Enterprise Security for AI SaaS

Trynectar • Palo Alto (CA)

On-site
USD 140,000 - 190,000
Competitive compensation and early-equ
Health, vision, and dental benefits +
Senior Security Engineer: AI-Powered SaaS & Cloud Security
Senior Security Engineer: AI-Powered SaaS & Cloud Security

C1 • San Francisco (CA)

On-site
USD 180,000 - 280,000
Senior Security Engineer: Cloud, AI & Incident Response
Senior Security Engineer: Cloud, AI & Incident Response

Sentrilock • West Chester Township (OH)

On-site
USD 110,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Credit Sesame • Mountain View (CA)

On-site
USD 170,000 - 215,000
Equity in pre-IPO company
Health, dental, and vision insurance
Monthly home office stipend
+3
Senior Product Security Engineer (AI/ML SaaS)
Senior Product Security Engineer (AI/ML SaaS)

assembledhq • New York (NY)

On-site
USD 180,000 - 260,000
Senior Security Engineer — AI-Driven Security Automation
Senior Security Engineer — AI-Driven Security Automation

Garuda Ventures • San Francisco (CA)

On-site
USD 170,000 - 250,000
Comprehensive health benefits
Equity
Senior Security Operations Engineer - AI-Driven Cloud Defense
Senior Security Operations Engineer - AI-Driven Cloud Defense

Sword • United States

Remote
USD 133,000 - 209,000
Senior Security Engineer — Cloud & AI Security
Senior Security Engineer — Cloud & AI Security

FastSpring, LLC • Northern (KY)

Hybrid
USD 155,000 - 187,000