Credit Sesame is a leading financial wellness platform dedicated to helping consumers achieve better financial health through cutting-edge technology and data-driven solutions. With a decade of credit expertise and a proven track record of serving over 18 million users, Credit Sesame leverages AI and advanced analytics to empower individuals to better understand and manage their credit. Our recently launched Sesame Platform extends our mission by providing financial institutions with a turnkey AI-powered credit intelligence solution. As our security engineer, you'll own security end-to-end for our platform — standing up open-source tooling, writing your own scripts and automation, and running assessments on our engineering team.You'll...
Run security reviews for new tools, vendors, and projects — data handling, AI usage, DPAs, PII, authentication/authorization, and third-party security reports (SOC 2, PCI, ISO, pentest results)
Own access and infrastructure security — IAM least-privilege reviews, S3/database access controls, environment segregation, service-to-service authentication, and network configuration audits (VPC flow logs, inbound/outbound rules)
Run vulnerability management across cloud and endpoints, and manage IDS/IPS (e.g., Palo Alto Panorama, AWS WAF) and EDR/MDR tooling
Lead security incident response end to end — triage, investigate, contain, document, and build the runbooks as you go
Implement and maintain the technical controls supporting our PCI DSS and SOC 2 / ISO 27001 compliance programs, including internal audits, risk metrics, and disaster recovery planning
Partner with DevOps/IT on patch management and secure infrastructure defaults, and present tooling and risk recommendations to engineering leadership
Build our in-house AppSec scanning program — evaluate and pilot SAST/SCA/IaC tooling (Semgrep, Trivy, Upwind), integrate into GitLab CI and Jenkins, define severity-based remediation SLAs, and drive rollout across services
Build internal security tooling and automation — custom scripts and integrations (Python/boto3, APIs) that pull data from tools without native integrations into shared dashboards and reports
Build and tune detection pipelines — for example, feeding traffic/bot-protection alerts (Datadome) into our log platform (ELK/Kibana) and writing rules that catch real attack patterns
Threat-model and pentest our AI/LLM systems — scope risks like prompt injection and data exfiltration through MCP servers, coordinate external pentests where needed, and drive remediation
Maintain security policies and practices and drive training and adoption throughout the company
You're a great fit because...
You have 7+ years of hands-on security engineering experience across application security, cloud security, and network/penetration testing — not just one lane
You've driven tooling or architecture decisions independently (evaluated options, made the call, defended it to leadership)
You're self-directed, pragmatic, and ruthless about prioritization
You've built production automation from scratch — API integrations, custom collectors, or internal tooling — not just one-off scripts
You have hands-on experience deploying and running OSS security tools — Burp Suite Community/OWASP ZAP, Nmap, Nuclei, Metasploit, Semgrep, Trivy, Wazuh/OSSEC, ELK/Kibana, Prowler/ScoutSuite, HashiCorp Vault, or similar
You have solid AWS security experience
You have working knowledge of PCI DSS, SOC 2, and ISO 27001 — enough to implement controls and support audits
You're curious about emerging security domains and comfortable threat-modeling systems (like AI/LLM applications) that don't have an established playbook yet
You're an excellent communicator who can translate cost/coverage tradeoffs and technical risk for both engineers and executives
Bonus: OSCP, GPEN, or similar certifications; bug bounty experience; or experience securing LLM/AI-based systems
BS in Computer Science or related field, or equivalent hands-on experience
You'll love it here because...
You’ll have equity in a pre-IPO company backed by top VCs;
We offer comprehensive medical, dental, and vision insurance;
We offer a monthly home office stipend;
We offer a professional development program to support your continued growth
We offer flexible paid time off;
We have 10 paid holidays and additional 6 Sesame Wellness days;
We prize EQ and empathy, and have a culture that emphasizes total wellness, including work-life harmony.
At Credit Sesame, base pay is one part of our total compensation package. The estimated pay range for this role is $170,000 - $215,000 with actual salary based on a candidate’s location, qualifications, skills, and experience. Additionally, this role is eligible to participate in Credit Sesame’s equity plans.We are open to hiring for this role in the following states where we are set up to hire employees: CA, CO, NC, NJ, NV, and TX.By clicking "Submit Application" (or related call to action), you acknowledge that you have read the Credit Sesame Employment Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.
Powered by JazzHR
Numbers & Facts
Location
Mountain View, CA
Salary
$170,000–$215,000 Per Year
Skills
Access Controlunmatched
Amazon Simple Storage Service (S3)unmatched
Amazon Web Services (AWS)unmatched
Application Programming Interface (API)unmatched
Artificial Intelligence (AI)unmatched
Audit Metricsunmatched
Authenticationunmatched
Automationunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Computer Scienceunmatched
Computer Securityunmatched
DevOpsunmatched
Disaster Recoveryunmatched
Establish Prioritiesunmatched
GPEN - GIAC Penetration Testerunmatched
ISO (International Organization for Standardization)unmatched
Incident Responseunmatched
Information Technology & Information Systemsunmatched
Injectionsunmatched
Internal Auditunmatched
Intrusion Detection Systemsunmatched
Intrusion Prevention Systemsunmatched
Jenkinsunmatched
Leadershipunmatched
Leading Edge Technologyunmatched
MCP - Microsoft Certified Professionalunmatched
Machine Toolunmatched
Metasploitunmatched
NMapunmatched
Network Configuration Managementunmatched
Open Sourceunmatched
Operational Support Systems (OSS)unmatched
Options Analysisunmatched
PCIunmatched
PCI-DSSunmatched
Python Programming/Scripting Languageunmatched
Reporting Dashboardsunmatched
Riskunmatched
Scripting (Scripting Languages)unmatched
Service Level Agreement (SLA)unmatched
Software Patchesunmatched
Technical Supportunmatched
Threat Modelingunmatched
Vendor/Supplier Selectionunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.