Skip to content
← Back to job listings

Security Engineer (Product)

Cardless · San Francisco, United States

External listingfull-timeabout 1 month ago

About The Role

Join our team as a Product Security Lead, where you'll drive the integration of security into our platform. This hands-on role involves collaboration with various departments, including Engineering, Risk, Compliance, Legal, and Data. You'll be responsible for owning the security model for our partner-facing APIs, driving a coherent authentication strategy, and improving our security posture across the stack. Additionally, you'll lead incident response on security events and ensure compliance with security frameworks. This position offers competitive salaries, top-of-the-line healthcare, unlimited paid time off, and more.

  • Assurer la sécurité des API destinées aux partenaires, en gérant l'authentification, l'autorisation, l'isolation des locataires, la prévention des abus, la signature et la journalisation.
  • Diriger la stratégie d'authentification cohérente à travers les services et les surfaces, y compris l'authentification renforcée pour les actions sensibles.
  • Être le partenaire de conception sécurisée avec l'ingénierie, en participant aux examens d'architecture avant le lancement des fonctionnalités, en rédigeant les modèles de menace.
  • Fintech, payments, or other regulated environment experience
  • Excellent written communication. You'll write threat models, postmortems, and partner-facing security responses
  • Strong programming skills in Java, Python, or a comparable language — you write production code
  • Background in anti-ATO, anti-fraud, or authentication systems at scale (consumer fintech, marketplace, or large consumer platform)
  • Experience working alongside or building for a risk / fraud operations team
  • Threat modeling methodology background (STRIDE, attack trees, or your own)
  • Experience designing or operating secure platform / B2B APIs at scale, especially in multi-tenant environments
  • Working knowledge of AWS: IAM, KMS, networking, service-to-service auth
  • Comfortable owning the security function in-house while leveraging external specialists as a force multiplier
  • Comfort with modern AI tooling (Claude, Copilot, and similar) as a daily force multiplier across code review, threat modeling, detection engineering, and security tooling
  • Experience operating a bug bounty or vulnerability disclosure program

This is an external listing. JobSpring does not represent or verify the employer. Report this listing