Security Engineer

Thunes Financial Services Inc.
San Francisco, CA, United States
2 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Bash Shell Cloud Computing Code Review Continuous Integration Information Engineering Github Python (Programming Language) Open Web Application Security Systems Development Life Cycle Software Vulnerability Management
+9 more
Software Security Gitlab-ci Kubernetes Front End Software Development Security Orchestration, Automation & Response Jenkins Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Thunes Financial Services is hiring a Security Engineer to be the architect of trust for our fintech platform. We are looking for a hybrid specialist who can bridge the gap between Infrastructure Security and Application Security, ensuring our systems are as resilient as they are compliant. This role will play a critical part in maintaining our regulatory compliance posture while building automated, scalable security guardrails. This role reports to the VP of Engineering., As a Security Engineer, you will be responsible for security across the full lifecycle of our fintech platform. This hybrid specialist role requires deep engagement with both infrastructure and application security, focusing heavily on automation and regulatory compliance within a high-stakes, regulated environment.

Day-to-day:

  • CI/CD Security Integration: Design, build, and maintain automation to integrate security testing (SAST/DAST/SCA) directly into our deployment pipelines. You’ll ensure that security is a “paved road” for developers, not a bottleneck.
  • Full-Stack Security: Own security across the lifecycle-from securing our cloud infrastructure (AWS/GCP) to performing code reviews and architectural risk assessments.
  • Vulnerability Management: Manage our detection stack using modern vulnerability scanning and dependency management tools to identify, prioritize, and track risks across the environment.
  • Security Automation: Build and maintain automated workflows for vulnerability reporting, triage, and remediation. We want someone who leverages AI-powered agentic coding tools or similar automation to eliminate manual toil and accelerate response times.
  • Compliance Engineering: Monitor our technical security controls to ensure that they are operating effectively throughout the year to meet the rigorous cybersecurity compliance requirements to support regulatory exams as well as SOC-2 and PCI audits.
  • Incident Response: Serve as a key member of our security response team, helping to investigate and mitigate potential threats.

Collaborate with:

  • Product, data engineering, front-end engineering, tech ops, compliance, and legal

Tech stack:

Cloud (AWS/GCP, K8s), CI/CD tools (GitHub Actions, GitLab CI, or Jenkins), Python, Go, or Bash, SAST/DAST/SCA, enterprise vulnerability management platforms, automated dependency scanning solutions.

Success in this role means:

  • Ensuring systems are resilient and compliant.
  • Maintaining our regulatory compliance posture.
  • Building automated, scalable security guardrails.
  • Having a direct impact on the security strategy.

Requirements

A Bachelor’s degree in Computer Science or a related field, but similar professional experience is equally valued., A proven track record of deep experience in both Infrastructure Security and Application Security is required., * Pipeline Proficiency: Hands-on experience building security guardrails within CI/CD tools (e.g., GitHub Actions, GitLab CI, or Jenkins).

  • Hybrid Expertise: Deep experience in both Infrastructure Security (Cloud/K8s) and AppSec (OWASP Top 10, Secure SDLC).
  • Tooling Experience: Proven proficiency with enterprise vulnerability management platforms and automated dependency scanning solutions.
  • Automation Mindset: You don’t just find bugs; you write code (Python, Go, or Bash) to handle them. Experience using AI-driven automation or agentic tools to streamline security workflows is required.
  • Fintech Fluency: You understand the high-stakes nature of working in a regulated environment and can translate compliance requirements into technical reality.

Leadership and collaboration:

  • Clear, effective communication of trade-offs to non-technical stakeholders
  • History of collaboration with engineers and others

Nice to have but in no way required:

  • Certifications such as CISSP
  • Prior experience in startups, especially Fintech

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier ¡ World Congress 2023

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters ¡ World Congress 2023

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

57 sec

Extracting API schemas automatically during continuous integration builds

Axel Barbier ¡ World Congress 2023

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle ¡ Coffee With Developers

Videos

See all

Related articles

See all