> Markdown version of [/jobs/ext/1312197-security-engineer](https://www.wearedevelopers.com/jobs/ext/1312197-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** COINFLOW LLC - **Location:** Chicago, IL, United States - **Experience:** Experienced - **Salary:** $145,000.0 - $195,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Cloud Computing, Code Review, Cyber Security, Fuzz Testing, Python (Programming Language), Node.Js, PCI Data Security Standards, Systems Development Life Cycle, Secure Coding, Security Information and Event Management, TypeScript, Software Vulnerability Management, Web Applications, Datadog, Splunk, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 17, 2026 - **Apply:** https://www.dice.com/job-detail/efebdbb3-d2fc-4ae1-9a16-25ec1f092496 ## About the Role * 4+ years in a security engineering, product security, or DevSecOps role, ideally at a fintech, payments company, or other regulated environment * Strong hands-on offensive skills - you've broken real systems, not just run scanners. Comfortable with web app, API, cloud, and infrastructure pentesting * Production experience operating a SIEM (Datadog, Splunk, Elastic, Panther, or similar) and building dashboards that engineers actually use * Fluency in TypeScript/Node and at least passing comfort with Rust, Go, or Python - enough to read our code, find bugs in it, and write the tooling to find more * Experience with vulnerability management at scale: CVE triage, SCA tooling, dependency upgrade automation * Comfort working with AI-native tooling (Claude Code, Claude Security, or similar) as a daily driver - or genuine excitement to start * A bias toward shipping. We'd rather have a working v1 of a control today than a perfect v3 next quarter. ## Description We're hiring for a Security Engineer to own the day-to-day defensive and offensive security posture of Coinflow. You'll build the SecOps backbone, hunt for weaknesses in our own stack before anyone else does, and partner with engineering to keep our SDLC fast and secure. This role reports to the CTO and has a direct line into every part of the engineering org. You'll be hands-on with modern AI-native security tooling - we use Claude Security and Claude Code as force multipliers for internal pentesting, code review, and remediation. If you're excited about being one of the first security engineers building this way, you'll fit in well here. What You'll Own * SIEM & SecOps Dashboard: Stand up and operate our SIEM. Build out the SecOps dashboard that gives engineering, compliance, and leadership a real-time picture of our security posture - alerts, anomalies, auth events, infrastructure changes, and audit-ready evidence in one place. * Internal Penetration Testing: Run continuous internal pentests against Coinflow services, APIs, infrastructure, and embedded SDKs. Use Claude Security and Claude Code to scale your coverage - automate reconnaissance, fuzzing, code review, and exploit development. Document findings, drive remediation, and measure mean-time-to-fix. * Vulnerability & Dependency Management: Own the vulnerability lifecycle end-to-end. Triage CVEs across our npm, cargo, and other ecosystems. Build the automation that keeps packages patched without breaking production - including Dependabot tuning, lockfile hygiene, and gated auto-merge for low-risk upgrades. * Secure Development Lifecycle: Monitor and improve how we ship code. Define secure-by-default patterns for new services, review threat models for high-risk changes, integrate SAST/DAST/secret scanning into CI, and make the secure path the fast path for engineers. * Compliance Partnership: Work alongside our compliance function to produce the evidence, controls, and monitoring artifacts that PCI DSS, SOC 2, ISO 27001, and DORA auditors need - without turning engineering into a paperwork shop. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Software Engineering Social Connection: Yubo’s lean approach to scaling an 80M-user infrastructure](https://www.wearedevelopers.com/videos/1583-software-engineering-social-connection-yubo-s-lean-approach-to-scaling-an-80m-user-infrastructure) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss)