远程工作雷达

资深安全工程师

Staff Security Engineer

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Beyond Finance
薪资$160,000 - $195,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间2026-08-06
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

在Beyond Finance,我们的使命是帮助普通美国人摆脱不断加剧的债务循环,迈向更光明的财务未来。通过富有同理心、个性化的服务,以合规和道德为核心的文化,支持用户的技术以及定制化的财务解决方案,我们已帮助超过100万客户走上更美好的未来之路。

虽然我们为已取得的成就感到自豪,但我们正在寻找新的合作伙伴,帮助我们达到新的高度!如果你希望加入一个具有前瞻性、快速发展的组织,以帮助人们为首要目标,我们期待你的加入。

### **职位概述**

作为资深安全工程师,你将早期参与产品和软件工程团队,将安全嵌入到他们设计、构建和发布的过程中。你也将是安全团队可以随时拉入任何项目、任何阶段和任何领域的成员,以确保实现正确的安全结果。

这是一个实践性很强的职位,你不需要在应用安全、云安全和安全自动化与工具三个领域都是专家。你应该在其中一个领域有扎实、可证明的专业深度,同时对其他两个领域有足够的了解,能够独立贡献,并在你所负责系统之外的技术决策中成为值得信赖的声音。

### **你将负责**

- 与工程、运维和产品团队合作,在设计或构建的任何阶段提供安全建议,无论涉及哪个领域。
- 指导网页和移动应用的安全设计和代码审查,并协助管理核心应用安全工具(SAST、SCA、密钥扫描、DAST、ASM 和移动安全工具)。
- 与工程团队协作进行应用级漏洞的优先级排序和修复。
- 在AWS环境中,通过CNAPP和AWS原生工具,提升云安全态势,包括IAM、网络分段、容器安全、密钥和数据暴露。
- 支持云和应用漏洞管理,并根据需要调整WAF规则。
- 使用Python等语言构建自动化和内部工具,减少安全团队的重复工作。
- 贡献于安全日志管道、SIEM检测和端点安全控制。
- 与运维团队合作,将安全检查(如扫描和密钥检测)嵌入CI/CD流水线。
- 贡献于安全开发和

查看英文原文

At Beyond Finance, we've made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care,a culture focused on compliance and ethics, supportive user-centric technology, and customized financial solutions, we've helped over 1 million clients on their path to a brighter future.

While we're proud of what we've already accomplished, we're searching for new collaborators to help us get to the next level! If you're looking to join a forward-thinking, rapidly growing organization with helping people as its number one goal, we want to hear from you.

### **Role Overview**

As a Staff Security Engineer, you'll get involved early with Product and Software Engineering teams to embed security into our architecture and processes as they design, build, and ship. You'll also be someone the Security team can pull into any project, at any phase and regardless of domain, to make sure it lands on the right security outcome.

This is a hands-on role, and you don't need to be an expert in all three areas: application security, cloud security, and security automation and tooling. You should have strong, demonstrated depth in one of the three, along with enough working knowledge of the other two to contribute without hand-holding and to be a trusted voice on technical decisions outside the systems you personally own.

### **What You'll Do**

- Partner with Engineering, DevOps, and Product across projects, providing security input at any phase of design or build, regardless of domain.
- Guide secure design and code review for web and mobile applications, and help manage core AppSec tooling (SAST, SCA, secret scanning, DAST, ASM, and mobile security tooling).
- Help triage and remediate application-level vulnerabilities with engineering teams.
- Contribute to cloud security posture across the AWS environment, including IAM, network segmentation, container security, secrets, and data exposure, using CNAPP and AWS-native tooling.
- Support cloud and application vulnerability management, and help tune WAF rules as needed.
- Build automation and internal tooling, primarily in Python, that reduces manual work for the security team.
- Contribute to security log pipelines, SIEM detections, and endpoint security controls.
- Help embed security checks, such as scanning and secrets detection, into CI/CD pipelines in partnership with DevOps.
- Contribute to secure development and infrastructure standards, playbooks, and enablement materials used across engineering.

### **What We're Looking For**

**Requirements**

- 8+ years of hands-on security engineering experience.
- Strong, demonstrated depth in one of the following, with working knowledge of the other two: application security, cloud security, or security automation and tooling.
- Working knowledge of threat modeling.
- Operates independently and drives projects without day-to-day oversight.

**Nice to Have**

- Deeper expertise across more than one of the following: application security (SAST/DAST/ASM tooling, secure SDLC), cloud security (AWS IAM, networking, container orchestration, CNAPP-driven posture management), or security automation (Python tooling, log pipelines, SIEM detection engineering).
- Hands-on Infrastructure as Code experience, ideally Terraform.
- Red teaming or offensive security experience.
- PCI-regulated or financial services environment experience.
- Mobile application security experience.
- AI/ML security exposure: prompt injection, data poisoning, model abuse, and the controls that mitigate them.
- Identity security across human and non-human identities.
- Development experience with Ruby on Rails, Python, Go, or similar languages.

### **The Ideal Candidate**

The ideal candidate measures success by reduced risk, not tickets closed. They understand how an attacker would approach a system and use that understanding to favor secure design and simple guardrails over adding more scanners or approval gates. They treat application code, cloud infrastructure, identity, and the pipeline as one connected system rather than separate problems.

This person is proactive. Given an ambiguous problem, they identify the highest-impact piece and start working on it rather than waiting for a fully scoped ticket, and they'd rather deliver a partial fix now and improve it over time than spend months on the perfect design. When a fix is needed in a system they don't own, they make the change themselves, get it reviewed, and ship it rather than filing a ticket and waiting on someone else.

Engineers trust this person's judgment. They catch a bad design, a fragile system, or an overlooked risk before it ships, and they flag potential blockers early enough to design around them instead of working around them later.

### **Why Join Us**

- High-ownership role with room to influence architecture, tooling, and process beyond your own domain.
- Work spans application security, cloud security, and security automation rather than being boxed into one lane.
- Modern engineering environment with strong leadership support for security.
- Competitive compensation, benefits, and growth opportunities.

The base annual salary range is listed below. This role is eligible for additional incentives, including an annual bonus.

Base Salary Range

$160,000—$195,000 USD

**Why Join Us?**

While you make a difference for others, we’ll work to make a difference for you, providing an uplifting, collaborative work environment and benefits that reflect your value to us. For eligible full-time employees, we offer:

- Considerable employer contributions for health, dental, and vision programs
- Generous PTO, paid holidays, and paid parental leave
- 401(k) matching program
- Merit advancement opportunities
- Career development & training

And finally, our team spirit and culture! We cultivate an environment of community, connection, and belonging across our entire organization.

_Beyond Finance does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job positions.  No fee will be paid to their parties who submit unsolicited candidates directly to Beyond Finance employees or the Beyond Finance HR team.  No placement fee will be paid to any third party unless such a request has been made by the Beyond HR team._

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级云安全工程师

Beyond FinanceUnited States$140,000 - $165,000/年permanent2026-08-07
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

高级应用安全工程师

Beyond FinanceUnited States$140,000 - $165,000/年permanent2026-08-07
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

数据平台负责人工程师

Beyond FinanceUnited States$170,000 - $205,000/年permanent2026-07-28
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

双语客户服务中心代表

Beyond FinanceUnited Statespermanent2026-06-02
其他限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位