Senior Software Engineer - Security
Los Angeles, Los Angeles County, California, 90079, USA
Listed on 2026-05-08
-
Software Development
Software Engineer, Senior Developer, DevOps, Backend Developer
What is Loancrate?
We started Loancrate to make home-buying simpler and less expensive for lenders and borrowers (us!). Today, mortgage lenders are stuck running their companies on software products built 20 years ago. These products are slow, unstable, and don't lead to material improvements in efficiency. When using these systems, the average human cost to originate a loan is still over $11,000.
Loancrate builds AI-native tooling to automate mortgage workflows. Our ultimate goal is fully automated origination, which has the potential to save lenders over $16B in operating expense per year.
Since starting in 2020, our remote team has enabled our customers to power >$85 billion in new home loans. We are a group of people excited to tackle the complexity of the home-lending industry. We care about collaboration, very open communication covering the good & the bad so that we learn from our decisions quickly, and ultimately having fun while we’re building.
You’ll fit in well if you like diving deep quickly!
We’re looking for someone who can maintain a strong security posture without slowing down development.
This is a hands‑on senior IC software engineering role for someone who specializes in security. You will work directly in our product and platform code, build internal tooling and guardrails, review designs and implementations, and help engineers eliminate classes of vulnerabilities at the source.
We handle highly sensitive personal and financial data, so security matters deeply here. But we believe good security work shows up as better architecture, safer defaults, useful tooling, and sound engineering judgment — not process theater.
This role is focused primarily on product security and security engineering: secure design, threat modeling, code review, authentication and authorization, secrets handling, CI/CD guardrails, and internal tooling. It is not primarily a compliance‑management, endpoint‑IT, vendor‑risk, or scanner‑operations role.
This role is best suited to someone who likes startup environments: small teams, broad ownership, imperfect systems, and the chance to materially improve the product through direct engineering work. You should be comfortable making pragmatic decisions, operating with incomplete information, and focusing on the highest‑leverage fixes rather than importing heavyweight processes from much larger companies.
What To ExpectAs a senior engineer at Loancrate, you should expect to spend meaningful time in code, in design reviews, and in implementation — not primarily coordinating programs or acting as an external reviewer.
You will likely spend your time on work such as:
- building secure‑by‑default libraries, helpers, and templates that engineers use across services
- reviewing designs and pull requests for authentication, authorization, tenant isolation, secrets handling, data exposure, and abuse cases
- improving developer workflows and CI/CD guardrails so real issues are caught early with minimal noise
- partnering directly with product and platform engineers to fix vulnerabilities in code and architecture
- raising the security baseline incrementally and pragmatically in a fast‑moving environment
- Design and build shared libraries, platform guardrails, and internal tools that make the secure path the easy path for engineers
- Review architecture, technical designs, and production code for security issues in product and platform systems
- Perform pragmatic threat modeling for new features, workflows, services, and integrations
- Improve core security patterns across the stack, including authentication, authorization, secrets handling, secure logging/redaction, auditability, and sensitive‑data protections
- Build or improve developer‑facing security automation in CI/CD and local workflows, including code scanning, dependency policy, secret detection, and infrastructure checks, with a bias toward low‑noise, high‑signal results
- Work directly with engineers to remediate vulnerabilities in code and design, focusing on durable fixes and reusable patterns rather than one‑off tickets
- Help define and evolve a lightweight secure SDLC that fits a fast‑moving startup…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).