Software Engineer, Security

Raydar

San Francisco (CA)

On-site

USD 250,000 - 350,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Raydar is hiring the first dedicated security engineering role in San Francisco reporting to the CTO. You will own the security program end to end across infrastructure security, application security, vulnerability management, and bug bounty operations.

This hands-on generalist role requires 2–8 years of experience, strong cloud and container security skills, and the ability to write code and automate security tasks. On-site in SF five days a week.

Qualifications

  • 2–8 years of hands-on security engineering experience.
  • Experience across cloud infrastructure and application security.
  • Experience with AWS and container orchestration (Kubernetes/EKS).
  • Ability to write code and automate security tasks.
  • On-site five days a week in San Francisco or willing to relocate.

Responsibilities

  • Build and own the security engineering program across infrastructure and application layers.
  • Identify and prioritize security gaps, develop remediation plans, and drive high-impact changes.
  • Harden AWS infrastructure, Kubernetes and EKS clusters, server configurations, networking, access controls, and cloud security posture.
  • Improve application security across services written in TypeScript, Go, Rust, and related technologies.
  • Manage recurring penetration tests and drive findings through remediation.
  • Operate the bug bounty program, triage vulnerability reports, and coordinate responses.
  • Partner with engineering on secure design, code-level fixes, deployment patterns, secrets management, and defense in depth.
  • Own technical work supporting SOC 2, PCI, monitoring, incident readiness, and vulnerability-management workflows.
  • Approximately 2 to 8 years of hands‑on security engineering, software security, infrastructure security, or closely related experience.
  • Strong generalist ability across cloud infrastructure, application security, vulnerability management, and security operations.
  • Hands‑on experience securing AWS and container‑orchestration environments such as Kubernetes or EKS.
  • Experience assessing and remediating application vulnerabilities in production software.
  • Experience managing penetration tests, bug bounty reports, or coordinated vulnerability disclosure.
  • Familiarity with network security, identity and access controls, secrets management, web application defenses, and cloud posture management.
  • Ability to write code, automate security work, and collaborate directly with software engineers on technical fixes.
  • Strong risk judgment, high ownership, clear communication, and comfort operating independently.
  • Ability to work on‑site five days per week in San Francisco or willingness to relocate.

Skills

Security engineering
Cloud security
Application security
Vulnerability management
Penetration testing
Bug bounty
Threat modeling
Secure design
Programming

Tools

AWS
Kubernetes
EKS
Terraform
Pulumi
CI/CD pipelines

Job description

Our client is building modern financial infrastructure for businesses, combining reliable banking with industry-specific software, payments, rewards, and intelligent financial workflows. The platform powers more than $10 billion per year in business purchasing across thousands of customers. Founded in 2021, the company has grown to approximately 60 employees, reports more than $300 million in annual revenue, and has raised approximately $160 million, including a recent $100 million Series C.

This is the first dedicated security engineering hire, reporting directly to the CTO and owning the security program end to end. You will build and operate the security program across infrastructure security, application security, vulnerability management, penetration testing, bug bounty operations, and engineering support for compliance. This is a hands‑on generalist role for someone who wants to ship real security improvements rather than operate only through policy and checklists.

What you will do:
  • Build and own the security engineering program across infrastructure and application layers.
  • Identify and prioritize security gaps, develop pragmatic remediation plans, and drive high-impact changes.
  • Harden AWS infrastructure, Kubernetes and EKS clusters, server configurations, networking, access controls, and cloud security posture.
  • Improve application security across services written in TypeScript, Go, Rust, and related technologies.
  • Manage recurring penetration tests and drive findings through remediation.
  • Operate the bug bounty program, triage vulnerability reports, and coordinate responses.
  • Partner with engineering on secure design, code-level fixes, deployment patterns, secrets management, and defense in depth.
  • Own technical work supporting SOC 2, PCI, monitoring, incident readiness, and vulnerability‑management workflows.
  • Approximately 2 to 8 years of hands‑on security engineering, software security, infrastructure security, or closely related experience.
  • Strong generalist ability across cloud infrastructure, application security, vulnerability management, and security operations.
  • Hands‑on experience securing AWS and container‑orchestration environments such as Kubernetes or EKS.
  • Experience assessing and remediating application vulnerabilities in production software.
  • Experience managing penetration tests, bug bounty reports, or coordinated vulnerability disclosure.
  • Familiarity with network security, identity and access controls, secrets management, web application defenses, and cloud posture management.
  • Ability to write code, automate security work, and collaborate directly with software engineers on technical fixes.
  • Strong risk judgment, high ownership, clear communication, and comfort operating independently.
  • Ability to work on‑site five days per week in San Francisco or willingness to relocate.

Nice to have: Experience with TypeScript, Go, Rust, CockroachDB, Kafka, Terraform, Pulumi, Cloudflare, AWS WAF, PCI, SOC 2, incident response, detection engineering, threat modeling, or secure architecture reviews.

$250,000 to $350,000 base salary, based on qualifications and experience, plus competitive equity. This role is on-site five days per week in San Francisco. Existing visa transfers, including OPT and H-1B transfers, may be considered.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Software Engineer
Security Software Engineer

Raydar • San Francisco (CA)

On-site
USD 150,000 - 200,000
Competitive Equity
Software Engineer, Security
Software Engineer, Security

XOXO AI Inc. • San Francisco (CA)

On-site
USD 250,000 - 500,000
Health, dental, vision benefits
Equity between 1% and 5%
Staff Software Engineer, Security
Staff Software Engineer, Security

XOXO AI Inc. • San Francisco (CA)

On-site
USD 250,000 - 500,000
Health benefits
Dental benefits
Vision benefits
Software Engineer, Security
Software Engineer, Security

Factory • San Francisco (CA)

On-site
USD 150,000 - 190,000
Security Engineer - Product Security (Senior)
Security Engineer - Product Security (Senior)

Cogent • All (MO)

On-site
USD 100,000 - 300,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Cogent-Security • United States

On-site
USD 100,000 - 300,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Cogent Security • San Francisco (CA)

On-site
USD 100,000 - 300,000
Senior Software Security Engineer
Senior Software Security Engineer

Xcede • San Francisco (CA)

On-site
USD 120,000 - 160,000
Security Engineer
Security Engineer

OP Recruiting • New York (NY)

On-site
USD 110,000 - 150,000
100% health benefits
Professional development budget
Weekly meal allowances
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Spinwheel Solutions Inc. • Oakland (CA)

On-site
USD 140,000 - 190,000
Remote-First
Salary & Equity
Unlimited PTO
+2