×
Register Here to Apply for Jobs or Post Jobs. X

Senior Security Engineer

Remote / Online - Candidates ideally in
Mountain View, Santa Clara County, California, 94039, USA
Listing for: Credit Sesame
Remote/Work from Home position
Listed on 2026-09-12
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 170000 - 215000 USD Yearly USD 170000.00 215000.00 YEAR
Job Description & How to Apply Below

Credit Sesame is a leading financial wellness platform dedicated to helping consumers achieve better financial health through cutting-edge technology and data-driven solutions. With a decade of credit expertise and a proven track record of serving over 18 million users, Credit Sesame leverages AI and advanced analytics to empower individuals to better understand and manage their credit. Our recently launched Sesame Platform extends our mission by providing financial institutions with a turnkey AI-powered credit intelligence solution.

You’ll
  • Run security reviews for new tools, vendors, and projects — data handling, AI usage, DPAs, PII, authentication/authorization, and third-party security reports (SOC 2, PCI, ISO, pentest results);
  • Own access and infrastructure security — IAM least-privilege reviews, S3/database access controls, environment segregation, service-to-service authentication, and network configuration audits (VPC flow logs, inbound/outbound rules);
  • Run vulnerability management across cloud and endpoints, and manage IDS/IPS (e.g., Palo Alto Panorama, AWS WAF) and EDR/MDR tooling;
  • Lead security incident response end to end — triage, investigate, contain, document, and build the runbooks as you go;
  • Implement and maintain the technical controls supporting our PCI DSS and SOC 2 / ISO 27001 compliance programs, including internal audits, risk metrics, and disaster recovery planning;
  • Partner with Dev Ops/IT on patch management and secure infrastructure defaults, and present tooling and risk recommendations to engineering leadership;
  • Build our in-house App Sec scanning program — evaluate and pilot SAST/SCA/IaC tooling (Semgrep, Trivy, Upwind), integrate into Git Lab CI and Jenkins, define severity-based remediation SLAs, and drive rollout across services;
  • Build internal security tooling and automation — custom scripts and integrations (Python/boto3, APIs) that pull data from tools without native integrations into shared dashboards and reports;
  • Build and tune detection pipelines — for example, feeding traffic/bot-protection alerts (Datadome) into our log platform (ELK/Kibana) and writing rules that catch real attack patterns;
  • Threat-model and pentest our AI/LLM systems — scope risks like prompt injection and data exfiltration through MCP servers, coordinate external pentests where needed, and drive remediation;
  • Maintain security policies and practices and drive training and adoption throughout the company.
You’re a great fit because…
  • You have 7+ years of hands-on security engineering experience across application security, cloud security, and network/penetration testing — not just one lane;
  • You’ve driven tooling or architecture decisions independently (evaluated options, made the call, defended it to leadership);
  • You’re self-directed, pragmatic, and ruthless about prioritization;
  • You’ve built production automation from scratch — API integrations, custom collectors, or internal tooling — not just one‑off scripts;
  • You have hands‑on experience deploying and running OSS security tools — Burp Suite Community/OWASP ZAP, Nmap, Nuclei, Metasploit, Semgrep, Trivy, Wazuh/OSSEC, ELK/Kibana, Prowler/Scout Suite, Hashi Corp Vault, or similar;
  • You have solid AWS security experience;
  • You have working knowledge of PCI DSS, SOC 2, and ISO 27001 — enough to implement controls and support audits;
  • You’re curious about emerging security domains and comfortable threat‑modeling systems (like AI/LLM applications) that don’t have an established playbook yet;
  • You’re an excellent communicator who can translate cost/coverage tradeoffs and technical risk for both engineers and executives;
  • Bonus: OSCP, GPEN, or similar certifications; bug bounty experience; prior experience at a startup; or experience securing LLM/AI‑based…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary