Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will own the end-to-end security strategy and program. You will build and lead the security team, secure the financial platform and infrastructure, and manage incident response, compliance, vendor risk, testing, and board-level security reporting. You will work hands-on with architecture, threat models, cloud security, account protection, and AI-agent safeguards.
Requirements
- 10+ years of security experience, including security leadership at a fintech, payments company, bank, or crypto company
- Experience building and scaling an early-stage security program
- Deep technical security credibility across authentication flows and architecture
- Hands-on experience with PCI DSS, SOC 2, sponsor-bank expectations, and FFIEC-style examinations
- Cloud security experience, ideally with AWS
- Ability to make security tradeoffs that support engineering velocity
- Calm and decisive incident leadership
Responsibilities
- Own the end-to-end security strategy and program
- Build and lead the security team
- Secure card issuing, payments, treasury, working capital, and the public API
- Lead account-security and anti-takeover work
- Define security permissions, guardrails, auditability, and abuse prevention for AI agents
- Own cloud and infrastructure security across AWS and Cloudflare
- Build and run incident response processes
- Own SOC 2 Type II and PCI compliance frameworks and audits
- Manage third-party and vendor risk
- Run penetration testing, the bug bounty program, and red-team exercises
- Brief leadership and the board on security risk
Benefits
- Equity
- Comprehensive health, dental, and vision benefits
- Free lunch every day and dinner for employees working past 9 PM
- Unlimited PTO