Enable job alerts via email!

Staff Security Engineer, DevSecOps

Informed, Inc

Mississippi

Remote

USD 170,000 - 220,000

Full time

6 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a forward-thinking company that is at the forefront of transforming the banking industry with innovative cloud-native solutions. As a key player in the Platform Engineering team, you'll lead the charge in ensuring security compliance and automating processes in a fast-paced environment. Your expertise in DevSecOps will be crucial as you navigate the complexities of security audits and vulnerability management. This role offers the chance to work with cutting-edge technologies while contributing to a mission that helps banks make real-time credit decisions. If you thrive in a startup culture and are passionate about building secure platforms, this opportunity is perfect for you.

Benefits

Competitive salary and stock options
Healthcare, dental, and vision partially paid
Two weeks of paid time-off
Seven paid company holidays

Qualifications

  • 5+ years experience in DevSecOps related positions.
  • Strong attention to detail and analytical capabilities.
  • Ability to write thorough, scalable and clear code.

Responsibilities

  • Lead technical/security aspects of SOC2 and other security audits.
  • Proactively identify and mitigate vulnerabilities.
  • Set secure coding best practices and participate in code reviews.

Skills

DevSecOps
Security Compliance
Vulnerability Management
AWS Services
CI/CD
Python
Infrastructure as Code

Education

BS in Computer Science
MS in Computer Science
PhD in Computer Science

Tools

Terraform
Snyk
AWS CloudTrail
GuardDuty

Job description

Remote or San Francisco; Must reside in the U.S.

Full-time

Overview

Play a leading role in baking in Security at every level of Informed.IQ’s serverless cloud native, machine learning platform. Customer and auditor facing responsibility for Industry and Customer Security Compliance. As a member of our Platform Engineering team, help us iterate our tools and techniques to support rapid development iterations, DevSecOps culture and GitOps driven CI/CD systems. Automate all things securely to ensure we smoothly handle our rapidly accelerating growth in customers, traffic and new products.

Responsibilities

  • Lead technical/security aspects of SOC2 and other Industry Security Compliance Audits
  • Customer facing lead of technical/security aspects at pre/post sales Customer Security Audits for large banks & lenders
  • Proactively identify, prevent and mitigate vulnerabilities and reduce the attack surfaces
  • Lead, automate and maintain security incident response process and post event forensics – Contribute to business and service continuity & Disaster Recovery
  • Set secure coding best practices and participate in the code review process
  • Identify, assess, and integrate outside services that make us more efficient.
  • Participate in collaborative, DevOps style, lean practices with the rest of the team

About You

  • 5+ years experience in DevSecOps related positions
  • Ability to thrive in a start-up environment, self-motivated and ingrained sense of end-to-end ownership of projects
  • Strong attention to detail, excellent analytical capabilities and a passion for building robust platforms for accelerating delivery to production.
  • Ability to write thorough, scalable and clear code and documentation as needed

Highly Desirable Experience (We don’t expect anymore to have all of these)

  • Extensive support of high compliance environments such as SOC2, ISO 27000X, PCI
    • Supporting both compliance audits & large bank 3rd party audits
    • Speaking to clients to help them understand the security posture of the application
    • Writing Security policies to utilize industry best practices
  • AWS Services particularly IAM Identity Center, Organizations, Serverless
    • Security detection tooling like AWS CloudTrail, GuardDuty, Macie, Security Hub
  • Architecting & building Identity and Access Management in AWS & Google Cloud
  • Software SDLC and Vulnerability Management (Snyk, SAST,SCA,DAST, etc)
  • Investigating and leading Security Incidents in a public cloud environment
  • CI/CD pipelines, penetration testing, software scanning, security best practices, high availability and disaster recovery
  • Solid understanding of computer networking especially in a public cloud environment.
  • Creating security training material and training teams in security best practices.

Bonus Points

  • Expertise with Python, Ruby, Rust or another high level language.
  • Contributed to Open Source projects
  • Experience writing infrastructure as code (Terraform) to build and deploy applications
  • Experience with AI, ML, MLOps
  • BS/MS/PhD in Computer Science/Engineering

Benefits and Perks

  • Competitive salary and stock options: $170,000-$220,000
  • Healthcare, dental, and vision partially paid by company
  • Two weeks of paid time-off in addition to seven paid company holidays

Our Company

Informed, Inc. is a well-funded ($20M) Series A start-up in San Francisco Bay Area with a steady and growing revenue stream helping banks automate loan funding and account opening by turning documents into decisions. Our customers include most of the top 5 banks and lenders in the automotive industry. Informed’s SOC2 Compliant Software-as-a-Service leverages state of the art machine learning and AI technologies to instantly verify income, assets, residence, insurance and other consumer data points, enabling real-time and more reliable credit decisions that better comply with Fair Lending laws.

Informed, Inc. is an EEO employer that actively pursues and hires a diverse workforce. We do not make hiring or employment decisions on the basis of race, color, religion or religious belief, ethnic or national origin, nationality, sex, gender, gender-identity, sexual orientation, disability, age, military or veteran status, or any other basis protected by applicable local, state, or federal laws. We strive to create a healthy and safe workplace where harassment of any kind is strictly prohibited. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

To apply, send your resume to jobs@informediq.com. We’d love to hear from you!

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Application Security Engineer (Remote)

Jeniusbank

California

Remote

USD 158,000 - 198,000

5 days ago
Be an early applicant

Application Security Engineer (Remote)

Jenius Bank

California

Remote

USD 158,000 - 198,000

6 days ago
Be an early applicant

Senior Security Engineer - Enterprise Security

Samsara

Philadelphia

Remote

USD 157,000 - 212,000

10 days ago

Staff Product Security Operations Engineer, Incident Response Lead

Affirm

Philadelphia

Remote

USD 200,000 - 250,000

14 days ago

Staff Software Engineer, Security

airbnb, Inc.

Remote

USD 120,000 - 180,000

3 days ago
Be an early applicant

Red Team Security Engineer

Piper Companies

Remote

USD 105,000 - 175,000

Today
Be an early applicant

Senior Security Engineer

Smarter Dx, Inc

Remote

USD 180,000 - 230,000

Today
Be an early applicant

System Security Engineer

Loft Orbital

Remote

USD 140,000 - 190,000

Yesterday
Be an early applicant

Principal Security Engineer

Upstart

Remote

USD 182,000 - 253,000

Yesterday
Be an early applicant