Job Closed

This listing is no longer active.

Senior Security Engineer

Location

United States

Posted

98 days ago

Salary

0

No structured requirement data.

Job Description

Senior Security Engineer

Loancrate

We started Loancrate to make home-buying simpler and less expensive for lenders and borrowers (us!). Today, mortgage lenders are stuck running their companies on software products built 20 years ago. These products are slow, unstable, and don't lead to material improvements in efficiency. When using these systems, the average human cost to originate a loan is still over $11,000. Loancrate builds AI-native tooling to automate mortgage workflows. Our ultimate goal is fully automated origination, which has the potential to save lenders over $16B in operating expense per year. Since starting in 2020, our remote team has enabled our customers to power >$85 billion in new home loans. We are a group of people excited to tackle the complexity of the home-lending industry. We care about collaboration, very open communication covering the good & the bad so that we learn from our decisions quickly, and ultimately having fun while we’re building. You’ll fit in well if you like diving deep quickly! Our dreams are big and we have much to build! We’re looking for a Senior Security Engineer who makes Loancrate more secure - without making it harder to build here. You’ll build systems, guardrails, and tooling that catch issues early, make secure defaults easy, and help engineers move fast and sleep at night. We handle some of the most sensitive personal and financial data in the country, and we take that responsibility seriously - security is an enabler here, not a gatekeeper. This is an IC role with broad scope - you’ll work across application security, infrastructure security, compliance, and internal tooling. If you’ve been in fintech or another regulated industry and gotten frustrated watching security slow engineering down, this is your chance to do it differently. You’ll write code, ship tooling, and improve our defaults - not just write policies. As a Senior Security Engineer at Loancrate, you’ll get into the codebase and infrastructure quickly. Within your first month, you’ll be contributing to work such as... Conducting a comprehensive threat model of our application and infrastructure layers, identifying the highest-leverage gaps and building a pragmatic remediation roadmap. Hardening our AWS infrastructure - IAM least-privilege, secrets management, network segmentation, CloudTrail audit coverage, and GuardDuty alerting - while keeping developer workflows frictionless. Integrating security tooling into our CI/CD pipeline: SAST, dependency scanning, container image scanning, and secret detection that catches issues before they ship. Partnering with engineering on our SOC 2 Type II posture - working across evidence collection, control design, and vendor risk so that compliance is a byproduct of doing good security, not a separate workstream. Building secure-by-default patterns and libraries (authn/authz helpers, input validation, secure logging/redaction) so teams don’t have to reinvent security per service. Lead and drive Loancrate’s security posture across application security, cloud security, identity, and compliance - partnering closely with engineering and leadership. Perform regular threat modeling, vulnerability assessments, and penetration testing - and work directly with engineering to remediate findings fast. Build and maintain security tooling and automation: SAST/DAST, dependency scanning, container scanning, SBOM management, and secret detection integrated into CI/CD. Harden our AWS environment: IAM, VPC boundaries, secrets management (AWS Secrets Manager), audit logging, GuardDuty, Security Hub, KMS key management, and DDoS protection. Own our SOC 2 Type II program - design practical controls, automate evidence collection where possible, manage the auditor relationship, and drive continuous improvement. Lead or coordinate incident response for security events - runbooks, postmortems, and clear communication to customers and leadership when needed. Establish and maintain a secure SDLC - lightweight design reviews, threat modeling in planning, and developer enablement (training, docs, examples) that scales. Maintain a risk register - tracking identified threats, ownership, and remediation status so nothing falls through the cracks. Partner with Operations on endpoint and device security: laptop hardening, MDM policy, hardware key rollout, and offboarding access revocation. Manage third-party and vendor security risk, including due diligence for new integrations and annual reviews of existing vendors. Own identity and access infrastructure: SSO, MFA enforcement (including hardware key policies), SCIM provisioning, and access reviews. Contribute to security documentation, internal runbooks, and team education - you make the secure path the easy path. Our infrastructure runs on AWS and is managed 100% with Terraform and Pulumi Cloud. Application services run in Docker on ECS EC2 or Fargate. Key services include Aurora PostgreSQL, ElastiCache (Redis), MSK (Kafka), and OpenSearch. Our CI/CD runs on Buildkite with TypeScript pipeline-as-code. Observability is powered by Datadog, CloudWatch, and Sentry. DNS and CDN are handled by Cloudflare. Application code is a TypeScript monorepo running Node/Express with a React frontend and GraphQL/Apollo API layer. We use GitHub for source control. (It’s okay not to have all of these things - these are just some skills we are excited about!) 🔒 Deep application security experience: threat modeling, OWASP Top 10 (and beyond), secure code review, SAST/DAST tooling, and working directly with engineers to fix what you find. ⚡ Strong AWS security experience across IAM, VPC, GuardDuty, Security Hub, CloudTrail, KMS, Secrets Manager, and WAF. 🏠 Terraform and/or Pulumi proficiency - you can read and contribute to infrastructure-as-code, and you understand the security implications of what you’re reviewing. 📋 Hands-on SOC 2 experience: you’ve designed controls, collected evidence, and managed an auditor relationship - not just checked boxes. 🚀 CI/CD security experience: integrating security tooling into developer pipelines in a way engineers actually appreciate. 🏦 Fintech or regulated industry experience - you understand the intersection of security, compliance, and data privacy in a lending or financial services context. 🤝 Collaborative mindset - you build relationships with engineering rather than operating as an external reviewer or blocker. You measure success by how secure the product is, not how many policies you’ve issued. 🔑 Identity and access experience: SSO/SAML, SCIM, MFA enforcement, hardware security keys, and access review programs. 🛡️Familiarity with data security for sensitive personal and financial data - encryption at rest and in transit, data classification, and minimization. 📝 Strong written communication - you document decisions, write clear runbooks, and communicate security risks to non-security audiences without FUD. 🧮 Scripting and automation chops (Python, Bash, or similar) - you build tools to make security scalable, not just write policies. Loancrate is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other legally protected characteristic.

Related Categories

Related Job Pages

More Business Development Rep Jobs

Naviant logo

Managing Director, Financial Services and Insurance

Naviant

Make your work life better by digitally transforming the way you work.

OtherRemoteTeam 51-200H1B No Sponsor

Develop a strong working knowledge of Naviant’s organizational structure, internal systems, and departmental processes. Gain a deep understanding of Naviant’s FINS clients, solution offerings, and market positioning. Assess the existing pipeline, key accounts, and team capabilities to identify opportunities for consultative, relationship-driven growth. Establish credibility and rapport with internal stakeholders and key industry contacts. Develop an initial perspective on differentiating Naviant in the market through strategic engagements. Define a clear plan to grow the FINS vertical, including refining target segments, account strategies, and value propositions. Shape and enhance key offerings to better address client priorities such as digital transformation, automation, and operational efficiency. Align sales, marketing, and delivery teams around a cohesive, client-focused engagement model. Establish executive-level relationships to expand Naviant’s influence and trusted-advisor presence in the FINS sector. Identify team capability gaps and begin enhancing consultative selling skills across the group. Fully own the FINS vertical, driving consistent revenue growth through strategic, solution-oriented selling. Strengthen executive relationships and advisory credibility with key clients. Demonstrate clear, measurable traction in pipeline development, deal closure, and strategic account management. Continuously refine the go-to-market approach and consultative sales methodology to create a repeatable, scalable engine for the practice. Mentor and develop the team, fostering a culture of accountability, high performance, collaborative problem-solving, and client-centered thinking. Comprehensive Health, Dental, & Vision Insurance Employer Paid Disability & Life Coverage 401k & Match Program Generous Paid Time Off Flex Spending Plans & Dependent Care Monthly Home Office Allowance Volunteer Time Off Charitable Giving Program Lifestyle Spending Account Employee Assistance Program, Parent Program, Wellness Initiatives, Virtual Gatherings, Employee Discount Program, Annual In-Person Celebration Week, and more! ​​​​​​​ Must be authorized to work in the U.S. Sponsorship not provided. Employees must reside in the U.S. Naviant is an Equal Opportunity and E-Verify employer seeking a diverse and talented workforce. Please use the links below for important information when applying for work with Naviant: E-Verify Notice | Right to Work Notice English or Spanish

United States
Job Closed
Jobgether logo

Sr. Software Engineering VP

Jobgether

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

OtherRemoteH1B No Sponsor

This position is posted by Jobgether on behalf of a partner company. We are currently looking for a VP of Software Engineering - REMOTE. In this essential role, you will lead a high-performing engineering organization responsible for delivering reliable SaaS and mobile products. Your focus will be on execution across the development lifecycle, collaborating with various teams to ensure top-notch quality and operational readiness. You will also actively engage in architecture discussions to align delivery with the overall platform direction. Your leadership will empower teams to excel while addressing complex technical challenges in a remote environment. Own delivery outcomes for SaaS and mobile, including release predictability, quality, reliability, and customer impact Lead and develop global teams across time zones, including technical leads and senior engineers Drive planning discipline, delivery cadence, and effective execution across multiple concurrent initiatives Partner with Product and QA on scope, milestones, risk, readiness criteria, and post-release follow-through Collaborate with the VP of Architecture to review solution designs for performance and scalability Translate architectural decisions into clear engineering plans and implementation sequences Identify cross-team dependencies and execution bottlenecks early Raise standards for coding practices and operational readiness

United States
Job Closed

The Major Gifts Officer is responsible for securing philanthropic support that aligns with our mission. Reporting to the Director, Development & Alumni Relations, the Major Gifts Officer will be responsible for securing funds from individual donors at the major gifts level ($100,000+) in support of the organization’s vision and revenue needs. The Major Gifts Officer will identify, cultivate, solicit, and steward a portfolio of approximately 100 to 125 accounts focused primarily on a West Coast footprint. Secure financial support from individuals, corporations, and foundations at the $100,000 level and above. Collaborate with Senior Manager, Development to identify prospective donors. Serve as solicitor and steward of major donors by developing strong relationships and cultivating continued interests in the mission. Develop and execute individualized cultivation, solicitation, and stewardship plans for assigned prospects and donors. Maintain thorough records of interactions with donors and their contributions in the CRM software. Regularly provide reports to Executive Director and Director, Development & Alumni Relations on visits, relationships, activities, results, and other key performance metrics compared to goals. Support consistent Foundation messaging through all channels to engage current and potential donors, encouraging support and investment of the vision. Support Foundation events including Olympic Trials, Golden Goggle Awards, donor cultivation events, etc. that engage and cultivate donor support. Support Executive Director and Director, Development & Alumni Relations with planned giving strategy and promote opportunities for unique engagement and stewardship. Participate in the planning, implementation, and evaluation of the major gifts fundraising plan, including individual gifts, endowment and planned gifts, the Trustees Council, special events, corporate solicitations, and donor stewardship.

United States
Job Closed
AHEAD, Inc. logo

Senior Technical Consultant-Cloud Networking

AHEAD, Inc.

AHEAD, Inc. is an IT services and consulting company that is on a mission to “accelerate the impact of technology on business.” As an employer, the company is known for its cha

We are currently looking to add a Cloud Networking expert, specifically focused on designing, automating, deploying, and integrating native and third-party networking and network security resources for our Clients in AWS, Azure, and Google Cloud Platform (GCP). Additionally, the PTC, Cloud Networking, will focus on ensuring the on-premises networks are optimized for adoption of cloud services in terms of resiliency and manageability. The ideal candidate for this position will possess knowledge and experience in architecting, engineering, automating, and deploying networking solutions across these platforms, with a strong background in traditional networking technologies. Lead design, deployment and automation efforts related to public cloud platforms Serve as a technical point of escalation and drive incidents/problems until resolution utilizing advice and assistance from manufacturers and other team members as required Keep client stakeholders and project managers apprised of project status throughout the project life cycle with detailed and thorough communication Serve as the subject matter expert in cross-functional client workshops and engagements Develop a wide range of client assessment and design deliverables including written documents and precise low-level diagrams Constantly evolve technical skill sets with certifications, training, and conferences during free time based on business requirements Support and mentor less experienced team members through training sessions and on-the-job mentoring Represent AHEAD in a professional manner to clients, partners, and peers Track, maintain, and report travel and expense activities in accordance with AHEAD policies Track, maintain, and report weekly time in accordance with AHEAD policies

United States
Job Closed