Software Engineer, Security

BPT Staffing

  • San Francisco, CA
  • 7 days ago
  • $250,000–$350,000 Per Year

Highlights

The person in this role will be the first dedicated security hire, working across the full stack from cloud infrastructure hardening to application security, and will report directly to the CTO with a clear path to becoming the sole security owner. 3. Manage recurring penetration tests and the bug bounty program, triage incoming vulnerability reports, and coordinate remediation with engineering teams.

Numbers & Facts

LocationSan Francisco, CA
Salary$250,000–$350,000 Per Year

Description

About the Role
This is a rare opportunity to own and build a security program from the ground up at a fast growing, VC-backed fintech organization processing billions of dollars in business spend. The person in this role will be the first dedicated security hire, working across the full stack from cloud infrastructure hardening to application security, and will report directly to the CTO with a clear path to becoming the sole security owner.

The ideal candidate is a security generalist who has already owned or heavily shaped a security function at a high-velocity startup or a widely respected technology company. They write real code, think in systems, and can move fast without sacrificing rigor. Former founders or founding engineers from security-focused startups are a strong fit. Candidates coming exclusively from large legacy enterprise environments or narrowly specialized in a single security domain are not the right match for this role.

Key Responsibilities
1. Own the end-to-end security program, identifying gaps, setting priorities, and driving improvements independently across infrastructure and application layers
2. Harden cloud infrastructure and server configurations across AWS, Kubernetes (EKS), and network security posture
3. Manage recurring penetration tests and the bug bounty program, triage incoming vulnerability reports, and coordinate remediation with engineering teams
4. Support SOC 2 and PCI compliance initiatives by owning the engineering-side work required to meet requirements
5. Partner cross-functionally with compliance, engineering, and other teams to ship meaningful security improvements
6. Contribute hands-on security improvements to a production platform using TypeScript, Go, Rust, or C

Required Skills & Experience
  • 2 to 5 years of experience in security engineering
  • Security generalist background spanning infrastructure, network, and application security
  • Demonstrated ownership of or heavy contribution to a security program at a VC-backed startup or high-velocity, reputable technology company
  • Proficiency in at least one of: TypeScript, Go, Rust, or C
  • Hands-on experience with cloud infrastructure including AWS, Kubernetes, and Terraform or equivalent tooling
  • Experience with penetration testing, bug bounty programs, or compliance frameworks such as PCI or SOC 2
  • BS in Computer Science or a related field from a strong program

Preferred Skills
  • Experience as a founder or founding engineer at a security-focused startup
  • Familiarity with CockroachDB
  • Visa transfer eligibility (OPT, H-1B transfers welcome)

Similar Jobs

See more jobs