Lumin Digital is a fintech company specializing in cloud native digital banking solutions.
Network Security Software Engineer
Location
United States
Posted
3 days ago
Salary
$145K - $175K / year
Seniority
Senior
Job Description
Network Security Software Engineer
Lumin Digital
• Own the architecture, implementation, and continuous improvement of Lumin’s network security program across cloud, SD-WAN, and ZTNA layers—designing identity-aware, policy-driven controls that secure both human and machine (agent) identities. • Design and deliver fully automated, end-to-end network security change management pipelines that eliminate manual toil, accelerate change velocity, and maintain audit-ready evidence at every step. • Build and operate real-time network telemetry, monitoring, and alerting systems that provide deep visibility into network activity — integrating threat intelligence feeds, cloud connectivity data, and asset inventories into a unified, automated network defense posture. • Engineer production-grade tooling and services—including firewall rule lifecycle management, policy drift detection, configuration compliance validation, and telemetry enrichment—using modern backend languages (Python strongly preferred) and infrastructure-as-code. • Manage and tune network-layer detection capabilities — including IDS/IPS signatures, firewall rules, and WAF configuration — to ensure high-fidelity signals for SOC consumption. • Operate at the leading edge of AI-assisted development: write precise engineering specifications, direct AI coding agents (e.g., Claude Code, Cursor), and review/validate generated output to build secure, lights-off agentic pipelines that the broader team can learn from. • Build and maintain API integrations across the network security technology stack (e.g., Cloudflare, Zscaler, cloud-native controls) with reliability, observability, and audit-readiness designed in from day one. • Support compliance audit and assessment activities — including evidence collection, control testing, and auditor walkthroughs for network security domains; maintain an accurate network diagram inventory documenting topology, segmentation boundaries, and data flows. • Partner with the Security Operations Center, SRE, and IT to ensure network security controls integrate cleanly with existing infrastructure pipelines, CI/CD workflows, and incident response processes; participate in security architecture reviews and contribute to runbook development and operational documentation—raising the network security bar across the engineering organization. • Perform other duties as assigned.
Job Requirements
- Bachelor’s degree in Computer Science, Information Security, Network Engineering, or a related technical field, or equivalent combination of education and experience.
- 5+ years of progressive experience in network security engineering, with a demonstrated track record of designing, automating, and operating network security controls in cloud-native or hybrid environments.
- Substantive hands-on engineering experience: you write production code, build integrations, and ship tooling—not just policies and diagrams.
- Direct experience with network security platforms such as Cloudflare (WAF, Workers, Rulesets, Terraform provider), Zscaler (ZIA, ZPA), Palo Alto, or equivalent tier-one solutions.
- Experience in fintech, banking, payments, or other regulated financial services environments (PCI-DSS, SOC 2, ISO 27001) strongly preferred.
- Experience with infrastructure-as-code (Terraform, CloudFormation) and CI/CD-driven infrastructure provisioning.
- Deep expertise in network security fundamentals: firewall policy design, micro-segmentation, ZTNA, SD-WAN, DDoS mitigation, traffic analysis, DNS security, and certificate/PKI management.
- Hands-on experience with agentic coding tools and workflows (Claude Code, Cursor, or equivalent)—or demonstrated eagerness and aptitude to adopt them as a primary development methodology.
- Strong proficiency in at least one backend language (Python strongly preferred; Go or similar considered) with the ability to design and build production-grade APIs, automation frameworks, and integration platforms.
- Thorough understanding of identity-aware network security—designing controls that authenticate and authorize not just users but services, workloads, and autonomous agents.
- Demonstrated ability to write clear, precise engineering specifications and technical documentation; comfortable operating on a distributed, async-first team where written clarity drives outcomes.
- Sound engineering judgment: able to evaluate AI-generated code for correctness, security implications, and maintainability; able to architect systems for reliability and observability.
- Strong cross-functional communication skills: able to translate network security requirements into actionable engineering work and influence peers across Security, SRE, and Platform teams.
Benefits
- medical, dental, and vision insurance
- a 401(k) with company match
- flexible PTO plus 12 paid holidays
- paid sick leave
- paid parental and family leave
- a lifestyle spending account
- tuition reimbursement
- a cell phone stipend
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Technical Account Manager, SIEM / Security Analytics, Dutch
AnomaliIntelligence-Driven Extended Detection and Response (XDR)
• Serve as an Anomali Platform power user; help our customers achieve success with the technology • Build strong customer relationships, especially with key customer stakeholders • Address customer’s technical requests; proactively identify and resolve issues • Provide advice, guidance, and technical know-how to ensure successful usage and adoption • Manage customer expectations while holding them accountable • Be your customer’s advocate and internal champion • Promote advocacy • Track key account metrics; communicate progress to internal and external stakeholders • Engage with the Onboarding Engineers to ensure a smooth transition • Engage with Technical Support to ensure speedy resolution of customer issues • Engage with Engineering to resolve customer reported issues • Partner with Sales to ensure an exceptional customer experience • Engage with Product Management to promote customer feature requests
Technical Account Manager, SIEM / Security Analytics
AnomaliIntelligence-Driven Extended Detection and Response (XDR)
• Serve as an Anomali Platform power user; help our customers achieve success with the technology • Build strong customer relationships, especially with key customer stakeholders • Address customer’s technical requests; proactively identify and resolve issues • Provide advice, guidance, and technical know-how to ensure successful usage and adoption • Manage customer expectations while holding them accountable • Be your customer’s advocate and internal champion • Promote advocacy • Track key account metrics; communicate progress to internal and external stakeholders • Engage with the Onboarding Engineers to ensure a smooth transition • Engage with Technical Support to ensure speedy resolution of customer issues • Engage with Engineering to resolve customer reported issues • Partner with Sales to ensure an exceptional customer experience • Engage with Product Management to promote customer feature requests • This role includes responsibilities related to the security and privacy of Anomali’s information systems and data across corporate and cloud environments. Access to systems and data is granted based on role requirements, and individuals are expected to comply with Anomali security and privacy policies, complete required training, and safeguard sensitive company and customer information in accordance with applicable security standards and regulatory requirements.
Security Engineer – Infrastructure
CoderSoftware development on your infrastructure. Offload your team's development from local workstations to cloud servers.
• Design and implement scalable guardrails for our multi-cloud infrastructure across AWS and GCP • Harden CI/CD pipelines and platform workflows to improve our software supply chain security posture • Practice and promote an everything-as-code approach across infrastructure, configuration, and policy • Automate repetitive security and compliance tasks so teams can stay aligned with frameworks without extra drag • Triage and review findings from cloud and infrastructure security tools, including CNAPP and CSPM platforms • Partner with engineers to prioritize risk, resolve findings, and improve controls over time
Software Engineer – Security
Modern TreasuryPayment operations solutions that automate the full cycle of money movement.
• Lead application security across our payment platform, including secure code review, threat modeling, and security architecture for new products • Own product security for new payment rails, including FBO account structures, stablecoin integration, and enhanced compliance features • Design and implement DevSecOps tooling and automation to improve security posture across CI/CD and infrastructure • Partner with engineering teams to embed security into the development lifecycle through automation, secure design patterns, and security champions • Drive security architecture decisions for customer-facing APIs, authentication systems, and data protection controls • Build monitoring and detection capabilities for application-layer threats, API abuse, and fraud patterns • Design infrastructure monitoring, automation, and remediation practices that keep our systems resilient and trustworthy • Collaborate with Compliance and Legal to ensure product features meet regulatory requirements (BSA/AML, KYC/KYB, state money transmission) • Influence technical strategy across Product, Platform, and Infrastructure teams on security and risk management



