
Loancrate
Remote Jobs
12 Jobs
• Test our UIs and workflows end-to-end — running real loan scenarios through the product the way a processor, underwriter, or closer would, across loan types and document conditions. • Find the bugs before customers do — visual glitches, broken validations, workflow dead-ends, incorrect calculations, data that doesn't persist, integrations that quietly drop fields, and the long tail of edge cases that only break under real mortgage conditions. • Write clear, reproducible bug reports — with the exact steps, the loan scenario in play, expected vs. actual behavior, and screenshots or recordings — so engineers can fix the issue without a second round of questions. • Build and own the regression test suite — a curated set of manual test cases and lightweight automated scripts (Playwright / Cypress or similar) that cover our core flows and grow with the product. • Own release readiness — run pre-release verification on every meaningful change, sign off on what's ready to ship, and flag what isn't. • Partner directly with Engineering and Product — sitting in on design reviews, asking the "but what happens when…" questions early, and helping shape features so they're testable and correct by construction. • Define the playbook — QA SOPs, bug severity rubrics, release checklists, and quality metrics that future team members will follow. • Hire, train, and lead the QA team — within 12-18 months, you can be running the function and owning how Loancrate thinks about software quality.
• Design and build shared libraries, platform guardrails, and internal tools that make the secure path the easy path for engineers • Review architecture, technical designs, and production code for security issues in product and platform systems • Perform pragmatic threat modeling for new features, workflows, services, and integrations • Improve core security patterns across the stack, including authentication, authorization, secrets handling, secure logging/redaction, auditability, and sensitive-data protections • Build or improve developer-facing security automation in CI/CD and local workflows, including code scanning, dependency policy, secret detection, and infrastructure checks, with a bias toward low-noise, high-signal results • Work directly with engineers to remediate vulnerabilities in code and design, focusing on durable fixes and reusable patterns rather than one-off tickets • Help define and evolve a lightweight secure SDLC that fits a fast-moving startup environment • Contribute to incident analysis and postmortems when product or platform security issues arise • Write clear documentation, examples, and decision records that help teams build securely without unnecessary friction
• Shipping code to production on your first day • Diving into your first mission-critical project • Architecting, building, and launching complex, multi-step AI agents • Integrating with 3rd-party providers of lending services APIs • Architecting, building, and launching the next generation of job processing infrastructure on AWS
• Own design end-to-end for a core product area - from early discovery through high-fidelity Figma design - partnering closely with Product Management and Engineering throughout. • Lead customer discovery sessions - running usability tests, digging into workflows, and translating what you learn into design decisions that shape the product. • Design intuitive UX patterns for complex interaction paradigms - multi-step automation workflows, AI-generated content, data-dense tables, and high-stakes decision surfaces. • Design for AI-native experiences - uncertainty states, intervention affordances, streaming content, and graceful error handling. • Build and maintain Figma component libraries and design system assets that give Engineering a coherent, scalable visual language. • Advocate for accessibility - WCAG compliance, color and contrast, keyboard navigation, and inclusive design practices. • Scope design work pragmatically - making smart tradeoffs between craft and delivery velocity without compromising correctness.
• Own the end-to-end product lifecycle for your area - discovery, definition, delivery, and iteration - in lockstep with Engineering and Design. This includes driving how we turn non-deterministic LLMs into reliable, mission-critical mortgage automation: defining requirements, evaluating tradeoffs, and setting success criteria. • Lead customer discovery with mortgage lenders, loan officers, and ops teams - running interviews, digging into workflows, and turning what you learn directly into a roadmap grounded in customer evidence, business strategy, and technical feasibility. • Prototype and explore product ideas hands-on - using AI coding tools and your technical background to validate early and bring Engineering concrete starting points. • Craft well-structured product specs and acceptance criteria that give Engineering and Design the clarity to move quickly and iterate intentionally. • Define success metrics for every major initiative and drive post-launch iteration until the outcomes are there. • Be the voice of the customer in technical architecture discussions - pushing back hard when tradeoffs compromise the user experience. • Partner with Sales and Customer Success to shape positioning and influence deal cycles for your product area. • Make the hard calls on scope - you ship focused, well-executed products and know when to ship with conviction.
• Own and evolve our AWS infrastructure using Terraform and Pulumi Cloud - treating infrastructure as a product that engineering teams depend on. • Design and maintain internal developer tooling and libraries that standardize how we build and ship - code generation, shared SDKs, data access patterns, and service scaffolding. • Create and maintain golden paths for common workflows (new service setup, background jobs, event streams, APIs) so teams can ship quickly with built-in security and observability (and consistent defaults across services). • Build and maintain CI/CD pipelines and per-PR ephemeral environments that make deploying feel easy and safe. • Drive reliability through SLOs, auto-scaling, incident response, and postmortems - and build systems that make the next incident less likely. • Create observability tooling and shared instrumentation libraries that give engineers real-time insight into their services. • Enforce security best practices across IAM, secrets management, encryption, audit logging, and DDoS protection. • Own the reliability and performance of our data platform (Aurora PostgreSQL) - provisioning, backups, failover, and tuning - and build tooling that makes safe usage the default. • Reduce toil through automation and self-service tooling so engineers can move fast without waiting on the platform. • Contribute to architecture decisions and documentation, and participate in on-call rotation (shared by the whole engineering team).
• Lead and drive Loancrate’s security posture across application security, cloud security, identity, and compliance • Perform regular threat modeling, vulnerability assessments, and penetration testing • Build and maintain security tooling and automation: SAST/DAST, dependency scanning, container scanning, SBOM management, and secret detection • Harden our AWS environment: IAM, VPC boundaries, secrets management, audit logging, GuardDuty, Security Hub, KMS key management, and DDoS protection • Own our SOC 2 Type II program • Lead or coordinate incident response for security events • Establish and maintain a secure SDLC • Maintain a risk register • Partner with Operations on endpoint and device security • Manage third-party and vendor security risk • Own identity and access infrastructure • Contribute to security documentation, internal runbooks, and team education
• Own the end-to-end design process for features • Build and maintain a design system • Write accessible, production-quality React components • Collaborate with PMs and engineers during discovery • Define and enforce visual and interaction design standards
We started Loancrate to make home-buying simpler and less expensive for lenders and borrowers (us!). Today, mortgage lenders are stuck running their companies on software products built 20 years ago. These products are slow, unstable, and don't lead to material improvements in efficiency. When using these systems, the average human cost to originate a loan is still over $11,000. Loancrate builds AI-native tooling to automate mortgage workflows. Our ultimate goal is fully automated origination, which has the potential to save lenders over $16B in operating expense per year. Since starting in 2020, our remote team has enabled our customers to power >$85 billion in new home loans. We are a group of people excited to tackle the complexity of the home-lending industry. We care about collaboration, very open communication covering the good & the bad so that we learn from our decisions quickly, and ultimately having fun while we’re building. You’ll fit in well if you like diving deep quickly! Our dreams are big and we have much to build! We’re looking for a Senior Security Engineer who makes Loancrate more secure - without making it harder to build here. You’ll build systems, guardrails, and tooling that catch issues early, make secure defaults easy, and help engineers move fast and sleep at night. We handle some of the most sensitive personal and financial data in the country, and we take that responsibility seriously - security is an enabler here, not a gatekeeper. This is an IC role with broad scope - you’ll work across application security, infrastructure security, compliance, and internal tooling. If you’ve been in fintech or another regulated industry and gotten frustrated watching security slow engineering down, this is your chance to do it differently. You’ll write code, ship tooling, and improve our defaults - not just write policies. As a Senior Security Engineer at Loancrate, you’ll get into the codebase and infrastructure quickly. Within your first month, you’ll be contributing to work such as... Conducting a comprehensive threat model of our application and infrastructure layers, identifying the highest-leverage gaps and building a pragmatic remediation roadmap. Hardening our AWS infrastructure - IAM least-privilege, secrets management, network segmentation, CloudTrail audit coverage, and GuardDuty alerting - while keeping developer workflows frictionless. Integrating security tooling into our CI/CD pipeline: SAST, dependency scanning, container image scanning, and secret detection that catches issues before they ship. Partnering with engineering on our SOC 2 Type II posture - working across evidence collection, control design, and vendor risk so that compliance is a byproduct of doing good security, not a separate workstream. Building secure-by-default patterns and libraries (authn/authz helpers, input validation, secure logging/redaction) so teams don’t have to reinvent security per service. Lead and drive Loancrate’s security posture across application security, cloud security, identity, and compliance - partnering closely with engineering and leadership. Perform regular threat modeling, vulnerability assessments, and penetration testing - and work directly with engineering to remediate findings fast. Build and maintain security tooling and automation: SAST/DAST, dependency scanning, container scanning, SBOM management, and secret detection integrated into CI/CD. Harden our AWS environment: IAM, VPC boundaries, secrets management (AWS Secrets Manager), audit logging, GuardDuty, Security Hub, KMS key management, and DDoS protection. Own our SOC 2 Type II program - design practical controls, automate evidence collection where possible, manage the auditor relationship, and drive continuous improvement. Lead or coordinate incident response for security events - runbooks, postmortems, and clear communication to customers and leadership when needed. Establish and maintain a secure SDLC - lightweight design reviews, threat modeling in planning, and developer enablement (training, docs, examples) that scales. Maintain a risk register - tracking identified threats, ownership, and remediation status so nothing falls through the cracks. Partner with Operations on endpoint and device security: laptop hardening, MDM policy, hardware key rollout, and offboarding access revocation. Manage third-party and vendor security risk, including due diligence for new integrations and annual reviews of existing vendors. Own identity and access infrastructure: SSO, MFA enforcement (including hardware key policies), SCIM provisioning, and access reviews. Contribute to security documentation, internal runbooks, and team education - you make the secure path the easy path. Our infrastructure runs on AWS and is managed 100% with Terraform and Pulumi Cloud. Application services run in Docker on ECS EC2 or Fargate. Key services include Aurora PostgreSQL, ElastiCache (Redis), MSK (Kafka), and OpenSearch. Our CI/CD runs on Buildkite with TypeScript pipeline-as-code. Observability is powered by Datadog, CloudWatch, and Sentry. DNS and CDN are handled by Cloudflare. Application code is a TypeScript monorepo running Node/Express with a React frontend and GraphQL/Apollo API layer. We use GitHub for source control. (It’s okay not to have all of these things - these are just some skills we are excited about!) 🔒 Deep application security experience: threat modeling, OWASP Top 10 (and beyond), secure code review, SAST/DAST tooling, and working directly with engineers to fix what you find. ⚡ Strong AWS security experience across IAM, VPC, GuardDuty, Security Hub, CloudTrail, KMS, Secrets Manager, and WAF. 🏠 Terraform and/or Pulumi proficiency - you can read and contribute to infrastructure-as-code, and you understand the security implications of what you’re reviewing. 📋 Hands-on SOC 2 experience: you’ve designed controls, collected evidence, and managed an auditor relationship - not just checked boxes. 🚀 CI/CD security experience: integrating security tooling into developer pipelines in a way engineers actually appreciate. 🏦 Fintech or regulated industry experience - you understand the intersection of security, compliance, and data privacy in a lending or financial services context. 🤝 Collaborative mindset - you build relationships with engineering rather than operating as an external reviewer or blocker. You measure success by how secure the product is, not how many policies you’ve issued. 🔑 Identity and access experience: SSO/SAML, SCIM, MFA enforcement, hardware security keys, and access review programs. 🛡️Familiarity with data security for sensitive personal and financial data - encryption at rest and in transit, data classification, and minimization. 📝 Strong written communication - you document decisions, write clear runbooks, and communicate security risks to non-security audiences without FUD. 🧮 Scripting and automation chops (Python, Bash, or similar) - you build tools to make security scalable, not just write policies. Loancrate is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other legally protected characteristic.
We started Loancrate to make home-buying simpler and less expensive for lenders and borrowers (us!). Today, mortgage lenders are stuck running their companies on software products built 20 years ago. These products are slow, unstable, and don't lead to material improvements in efficiency. When using these systems, the average human cost to originate a loan is still over $11,000. Loancrate builds AI-native tooling to automate mortgage workflows. Our ultimate goal is fully automated origination, which has the potential to save lenders over $16B in operating expense per year. Since starting in 2020, our remote team has enabled our customers to power >$85 billion in new home loans. We are a group of people excited to tackle the complexity of the home-lending industry. We care about collaboration, very open communication covering the good & the bad so that we learn from our decisions quickly, and ultimately having fun while we're building. You'll fit in well if you like diving deep quickly! Our dreams are big and we have much to build! We’re looking for a Senior Platform Engineer to build the tooling and systems that let product engineers focus on shipping features fast - without having to worry about performance, reliability, or scale. This role spans infrastructure and internal developer tooling: you’ll design self-serve platforms, libraries, and automation that “just work,” enabling complex product experiences without compromising security or uptime. As a Platform Engineer at Loancrate, you’ll ship platform improvements to production early and often - spanning infrastructure, developer tooling, and shared libraries. Within your first month, you'll be diving into mission-critical work such as... Designing and building the systems that let engineers deploy dozens of times per day with confidence - from our Buildkite CI/CD pipelines and per-PR ephemeral environments to our IaC-managed AWS infrastructure. Creating self-serve developer experiences - local dev tooling, templates, golden paths, and CI-integrated workflows - so “the right thing” is the easy thing. Extending our internal TypeScript tooling - from schema/code generation to data access libraries - so teams can build features faster with safer, more consistent primitives. Making Loancrate's platform observable and self-healing - instrumenting our services with Datadog, building alerting that actually signals rather than spams, and reducing the blast radius of incidents before they happen. Baking security into our platform defaults - across infra and developer tooling - while keeping engineering velocity high. Solving interesting scaling problems as our AI-native mortgage platform grows - from Aurora PostgreSQL tuning to Kafka throughput to cost-efficient compute autoscaling. Own and evolve our AWS infrastructure using Terraform and Pulumi Cloud - treating infrastructure as a product that engineering teams depend on. Design and maintain internal developer tooling and libraries that standardize how we build and ship - code generation, shared SDKs, data access patterns, and service scaffolding. Create and maintain golden paths for common workflows (new service setup, background jobs, event streams, APIs) so teams can ship quickly with built-in security and observability (and consistent defaults across services). Build and maintain CI/CD pipelines and per-PR ephemeral environments that make deploying feel easy and safe. Drive reliability through SLOs, auto-scaling, incident response, and postmortems - and build systems that make the next incident less likely. Create observability tooling and shared instrumentation libraries that give engineers real-time insight into their services. Enforce security best practices across IAM, secrets management, encryption, audit logging, and DDoS protection. Own the reliability and performance of our data platform (Aurora PostgreSQL) - provisioning, backups, failover, and tuning - and build tooling that makes safe usage the default. Reduce toil through automation and self-service tooling so engineers can move fast without waiting on the platform. Contribute to architecture decisions and documentation, and participate in on-call rotation (shared by the whole engineering team). Our infrastructure runs on AWS and is managed 100% with Terraform and Pulumi Cloud. Application services run in Docker on ECS EC2 or Fargate. Key services include Aurora PostgreSQL, ElastiCache (Redis), MSK (Kafka), and OpenSearch. Our CI/CD runs on Buildkite with TypeScript pipeline-as-code. We also maintain internal TypeScript platform libraries (codegen, service templates, shared data access/instrumentation) that power consistent APIs and developer workflows across the monorepo. Observability is powered by Datadog, CloudWatch, and Sentry. DNS and CDN are handled by Cloudflare. Application code is a TypeScript monorepo running Node/Express with a React frontend and GraphQL/Apollo API layer. We use GitHub for source control. (It's okay not to have all of these things - these are just some skills we are excited about!) 🧩 Experience building internal platforms / developer tooling: code generation, CLIs, templates, shared SDKs, or frameworks that improve engineering velocity. 🏗️ Strong TypeScript skills and API design taste - you enjoy building stable primitives that other engineers rely on. 🌩 Deep AWS experience across compute, networking, storage, and security (ECS, Lambda, VPC, ALB, IAM, RDS, ElastiCache, MSK, OpenSearch, S3, CloudWatch, CloudTrail, GuardDuty). 🏠 Strong Terraform and/or Pulumi proficiency: modules, workspaces, and CI-driven plan/apply workflows. 🚀 Experience designing and operating CI/CD systems that help large engineering teams ship frequently and confidently. 🔍 Track record building production observability stacks (Datadog, CloudWatch, Sentry, distributed tracing, SLOs). 🧱 You’ve built “paved roads” that bake in secure, reliable defaults (instrumentation helpers, policy-as-code, safe-by-default deployment patterns). 🔒 Security-first mindset - you proactively harden infrastructure without slowing teams down. 🛢 Aurora PostgreSQL operations at scale: backups, PITR, failover, read replicas, query tuning. 🧰 Comfort with Docker and container orchestration environments. 📊 Reliability engineering mindset: SLOs, error budgets, incident response. 🤖 Curiosity about the unique infrastructure demands of AI and LLM workloads. 📝 Strong written communication - you document decisions and help the team understand the systems they depend on. Loancrate is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other legally protected characteristic.
2more opportunities are still waiting for you.Log in now and take your next shot before someone else does.