You have 7+ years of hands-on security engineering experience across application security, cloud security, and network/penetration testing — not just one lane; You've driven tooling or architecture decisions independently (evaluated options, made the call, defended it to leadership); You're self-directed, pragmatic, and ruthless about prioritization; You've built production automation from scratch — API integrations, custom collectors, or internal tooling — not just one-off scripts; You have hands-on experience deploying and running OSS security tools — Burp Suite Community/OWASP ZAP, Nmap, Nuclei, Metasploit, Semgrep, Trivy, Wazuh/OSSEC, ELK/Kibana, Prowler/ScoutSuite, HashiCorp Vault, or similar; You have solid AWS security experience; You have working knowledge of PCI DSS, SOC 2, and ISO 27001 — enough to implement controls and support audits; You're curious about emerging security domains and comfortable threat-modeling systems (like AI/LLM applications) that don't have an established playbook yet; You're an excellent communicator who can translate cost/coverage tradeoffs and technical risk for both engineers and executives; Bonus: OSCP, GPEN, or similar certifications; bug bounty experience; prior experience at a startup; or experience securing LLM/AI-based systems; BS in Computer Science or related field, or equivalent hands-on experience. With a decade of credit expertise and a proven track record of serving over 18 million users, Credit Sesame leverages AI and advanced analytics to empower individuals to better understand and manage their credit.