远程工作雷达

高级安全工程师

Senior Security Engineer

开发工程职能支持限定地区(需当地身份)
公司Credit Sesame
薪资$170,000 - $215,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

我们是Credit Sesame,一家领先的财务健康平台,致力于通过尖端技术和数据驱动的解决方案帮助消费者实现更好的财务健康。拥有十年的信用专业知识和为超过1800万用户提供服务的可靠记录,Credit Sesame利用人工智能和高级分析技术,帮助个人更好地了解和管理自己的信用。我们最近推出的Sesame Platform通过提供现成的AI驱动的信用智能解决方案,扩展了我们的使命,为金融机构提供支持。

作为我们的安全工程师,你将负责我们平台的安全性全流程——搭建开源工具、编写脚本和自动化流程,并进行评估。

你将:
· 对新工具、供应商和项目进行安全审查——包括数据处理、AI使用、数据处理协议(DPA)、个人身份信息(PII)、认证/授权以及第三方安全报告(SOC 2、PCI、ISO、渗透测试结果);

  • 负责访问和基础设施安全——包括IAM最小权限审查、S3/数据库访问控制、环境隔离、服务间认证以及网络配置审计(VPC流量日志、入站/出站规则);
  • 在云和终端设备上运行漏洞管理,并管理入侵检测系统/入侵防御系统(IDS/IPS)(如Palo Alto Panorama、AWS WAF)和端点检测与响应/托管检测与响应(EDR/MDR)工具;
  • 全程主导安全事件响应——包括初步判断、调查、遏制、文档记录,并在过程中建立操作手册;
  • 实施并维护支持我们PCI DSS和SOC 2 / ISO 27001合规计划的技术控制措施,包括内部审计、风险指标和灾难恢复规划;
  • 与DevOps/IT合作进行补丁管理和安全基础设施默认设置,并向工程领导层提出工具和风险建议;
  • 建立我们的内部应用安全扫描计划——评估并试点静态应用安全测试(SAST)、软件组成分析(SCA)和基础设施即代码(IaC)工具(如Semgrep、Trivy、Upwind),集成到GitLab CI和Jenkins中,定义基于严重程度的修复SLA,并推动在各服务中的部署;
  • 构建内部安全工具和自动化流程——定制脚本和集成(Python/boto3、APIs),将没有原生集成的工具数据提取到共享仪表板和报告中;
  • 构建和优化检测管道——例如,将流量/反机器人警报(Datadome)输入我们的日志平台(ELK/Kibana),并编写规则以捕捉真实的攻击模式;
  • 对我们的AI/大语言模型(LLM)系统进行威胁建模和渗透测试——评估如提示注入和通过MCP服务器的数据泄露等风险;
查看英文原文

Credit Sesame is a leading financial wellness platform dedicated to helping consumers achieve better financial health through cutting-edge technology and data-driven solutions. With a decade of credit expertise and a proven track record of serving over 18 million users, Credit Sesame leverages AI and advanced analytics to empower individuals to better understand and manage their credit. Our recently launched Sesame Platform extends our mission by providing financial institutions with a turnkey AI-powered credit intelligence solution.

As our security engineer, you'll own security end-to-end for our platform — standing up open-source tooling, writing your own scripts and automation, and running assessments.

You'll...
· Run security reviews for new tools, vendors, and projects — data handling, AI usage, DPAs, PII, authentication/authorization, and third-party security reports (SOC 2, PCI, ISO, pentest results);

  • Own access and infrastructure security — IAM least-privilege reviews, S3/database access controls, environment segregation, service-to-service authentication, and network configuration audits (VPC flow logs, inbound/outbound rules);
  • Run vulnerability management across cloud and endpoints, and manage IDS/IPS (e.g., Palo Alto Panorama, AWS WAF) and EDR/MDR tooling;
  • Lead security incident response end to end — triage, investigate, contain, document, and build the runbooks as you go;
  • Implement and maintain the technical controls supporting our PCI DSS and SOC 2 / ISO 27001 compliance programs, including internal audits, risk metrics, and disaster recovery planning;
  • Partner with DevOps/IT on patch management and secure infrastructure defaults, and present tooling and risk recommendations to engineering leadership;
  • Build our in-house AppSec scanning program — evaluate and pilot SAST/SCA/IaC tooling (Semgrep, Trivy, Upwind), integrate into GitLab CI and Jenkins, define severity-based remediation SLAs, and drive rollout across services;
  • Build internal security tooling and automation — custom scripts and integrations (Python/boto3, APIs) that pull data from tools without native integrations into shared dashboards and reports;
  • Build and tune detection pipelines — for example, feeding traffic/bot-protection alerts (Datadome) into our log platform (ELK/Kibana) and writing rules that catch real attack patterns;
  • Threat-model and pentest our AI/LLM systems — scope risks like prompt injection and data exfiltration through MCP servers, coordinate external pentests where needed, and drive remediation;
  • Maintain security policies and practices and drive training and adoption throughout the company.

You're a great fit because...
· You have 7+ years of hands-on security engineering experience across application security, cloud security, and network/penetration testing — not just one lane;

  • You've driven tooling or architecture decisions independently (evaluated options, made the call, defended it to leadership);
  • You're self-directed, pragmatic, and ruthless about prioritization;
  • You've built production automation from scratch — API integrations, custom collectors, or internal tooling — not just one-off scripts;
  • You have hands-on experience deploying and running OSS security tools — Burp Suite Community/OWASP ZAP, Nmap, Nuclei, Metasploit, Semgrep, Trivy, Wazuh/OSSEC, ELK/Kibana, Prowler/ScoutSuite, HashiCorp Vault, or similar;
  • You have solid AWS security experience;
  • You have working knowledge of PCI DSS, SOC 2, and ISO 27001 — enough to implement controls and support audits;
  • You're curious about emerging security domains and comfortable threat-modeling systems (like AI/LLM applications) that don't have an established playbook yet;
  • You're an excellent communicator who can translate cost/coverage tradeoffs and technical risk for both engineers and executives;
  • Bonus: OSCP, GPEN, or similar certifications; bug bounty experience; prior experience at a startup; or experience securing LLM/AI-based systems;
  • BS in Computer Science or related field, or equivalent hands-on experience.

You'll love it here because...

  • You’ll have equity in a pre-IPO company backed by top VCs;
  • We offer comprehensive medical, dental, and vision insurance;
  • We offer a monthly home office stipend;
  • We offer a professional development program to support your continued growth
  • We offer flexible paid time off;
  • We have 10 paid holidays and additional 6 Sesame Wellness days;
  • We prize EQ and empathy, and have a culture that emphasizes total wellness, including work-life harmony.

At Credit Sesame, base pay is one part of our total compensation package. The estimated pay range for this role is $170,000 - $215,000 with actual salary based on a candidate’s location, qualifications, skills, and experience. Additionally, this role is eligible to participate in Credit Sesame’s equity plans.

We are open to hiring for this role in the following states where we are set up to hire employees: CA, CO, NC, NJ, NV, and TX.

By clicking "Submit Application" (or related call to action), you acknowledge that you have read the Credit Sesame Employment Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位