A venture-backed startup building a modern data platform for the real estate industry, enabling automation, analytics, and AI-powered workflows for real estate operators. The team includes engineers and leaders from companies such as major fintech, cloud, and consumer technology platforms, and is focused on solving complex infrastructure and data challenges in a large, underserved industry.
Founding Security Engineer
Location
United States
Posted
1 day ago
Salary
$180K - $230K / year
Seniority
Mid Level
Job Description
Founding Security Engineer
Map Ssg
Role Description This is the company’s first dedicated security hire. You will define and build the company’s security program from scratch, working directly with a security-minded co-founder. This role spans product security, application security, corporate security, compliance, incident response, and detection. Over time, this person may build and lead the security function. - Own the company’s security posture across product, infrastructure, and internal systems - Lead security reviews, threat modeling, and secure design work - Build foundational security systems such as secrets management, audit logging, vulnerability management, and certificate infrastructure - Drive compliance programs such as SOC 2, ISO 27001, GDPR, and CCPA - Define incident response processes and detection capabilities - Partner closely with engineering to embed security into product development - Help shape security culture across a small, high-caliber team Qualifications - 5+ years of security engineering experience - Strong application security background - Experience with secure SDLC, threat modeling, vulnerability management, and security architecture - Experience contributing to or running security programs - Compliance experience, ideally SOC 2, ISO 27001, GDPR, or similar - Backend or systems engineering fluency; Go experience is a plus - Ability to operate with high ownership in an early-stage environment - Low-ego, collaborative mindset and willingness to wear multiple hats Nice to Have - First or second security hire experience at a startup - Detection engineering experience - Identity, access management, enterprise IT, or security software background - Kubernetes, GCP, cloud security, or infrastructure security experience - Published security research, talks, or open-source security work
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
IT Security Database Engineer
Bayview Asset ManagementFounded in 1993, Bayview Asset Management is an investment management firm focused on investments in mortgage and consumer credit, including whole loans, asset-backed securities, mortgage servicing rights, and other credit-related assets.
Role Description The Database Security Engineer is responsible for securing and protecting the organization’s enterprise databases, database platforms, and related data assets. This role combines database administration expertise with information security best practices to ensure the confidentiality, integrity, and availability of sensitive company and customer data. The role is part of the Security Engineering team and will work closely with Infrastructure, Application Development, Information Security, Compliance, and business stakeholders to: - Implement database security controls - Monitor database activity - Support regulatory compliance initiatives - Reduce organizational risk The ideal candidate will have a strong background in database administration (DBA) along with hands-on experience in: - Database security - Auditing - Vulnerability management - Data protection technologies in on-premise data center and public cloud environments The candidate must be familiar with a variety of database technologies, security concepts, practices, and procedures. Qualifications - BA/BS in Computer Science, Computer Engineering, Information Systems, or equivalent experience - 7+ years of experience in database administration, database engineering, or database security - Strong hands-on experience administering enterprise database platforms such as SQL Server, Oracle, PostgreSQL, or MySQL - Experience implementing database security controls including encryption, auditing, access controls, and privileged access management - Experience with database vulnerability scanning, monitoring, and remediation processes - Experience in highly regulated environments, preferably Financial Services or similar industries - Experience supporting cloud database technologies and security best practices in AWS, Oracle and/or Azure Requirements - Strong understanding of database architecture, database administration, backup/recovery, and performance concepts - Knowledge of methods to secure databases, applications, and sensitive data assets - In-depth knowledge of data protection engineering principles, DLP, encryption, masking, and tokenization - Strong research and troubleshooting skills - Strong verbal and written communication skills - Skill with SQL, Python, Bash, or PowerShell scripting Benefits - This role will be remote based anywhere in the US - The base compensation will be based on experience - There will be an opportunity for an incentive-based bonus Certifications, Licenses, and/or Registration - Preferred: CISSP, CISA, Security+, Microsoft Certified: Azure Database Administrator Associate, Oracle Database Security Certified Implementation Specialist, AWS Certified Security – Specialty, GIAC certifications, Microsoft SQL certifications, or equivalent database/security certifications
Full Stack Engineer – IAM Security, German speaking
PROSTAFF SchweizWe provide freelance jobs in IT and data science in Switzerland. Moreover we provide payrolling services.
• Analyse und Behebung von Vulnerabilities im IAM-Umfeld • Weiterentwicklung und Optimierung bestehender Full-Stack-Anwendungen • Umsetzung sicherheitsrelevanter Anpassungen im Backend und Frontend • Betrieb und Deployment von Anwendungen auf einer OpenShift-Plattform • Durchführung von Code Reviews • Sicherstellung von Qualität, Stabilität und Wartbarkeit der Software
Security Researcher
Map SsgA venture-backed startup building a modern data platform for the real estate industry, enabling automation, analytics, and AI-powered workflows for real estate operators. The team includes engineers and leaders from companies such as major fintech, cloud, and consumer technology platforms, and is focused on solving complex infrastructure and data challenges in a large, underserved industry.
Role Description We have already disclosed vulnerabilities in curl (150+ bugs fixed), FFmpeg, django-allauth, OpenSSL, and Avahi. You will expand that list. This role sits at the intersection of manual security research and AI-augmented discovery. You will audit codebases, validate and triage findings from our LLM-powered scanner, and feed your expertise back into the detection engine. Your work directly improves what the AI catches next time. What You'll Do - Conduct security research on open-source projects and customer codebases across multiple languages - Validate and triage AI-generated vulnerability findings to calibrate false positive rates - Write detailed vulnerability reports and coordinate responsible disclosure and CVE assignment - Define and refine detection rules, heuristics, and prompt strategies for the scanning engine - Collaborate with the engineering team to improve detection of business logic and auth flaws - Contribute to our public research blog and Wall of Fame Qualifications - 3+ years of experience in application security research, penetration testing, or red teaming - Demonstrated ability to find and responsibly disclose vulnerabilities (CVEs, bug bounties, or published research) - Strong understanding of common vulnerability classes: OWASP Top 10, business logic flaws, auth bypasses, injection chains - Proficiency in reading and analyzing code across Python, JavaScript/TypeScript, Go, Java, or C/C++ - Experience with static analysis concepts, code review, and source code auditing - Excellent written communication for vulnerability reports and research write-ups Nice to Have - Published CVEs or a meaningful bug bounty track record - Experience with tree-sitter, semgrep, CodeQL, or similar code analysis tooling for benchmarking - Familiarity with LLM-powered security tools or AI-augmented research workflows - Contributions to open-source security projects Compensation $180-230K + equity
FedNow Senior Cyber Security Engineer
Federal Reserve Bank of BostonAs part of the Central bank of the United States, the Boston Fed works to promote sound growth and financial stability in New England and the nation. We contribute to communities, the region, and the nation by conducting economic research, participating in monetary policy-making, supervising certain financial institutions, providing financial services and payments, playing a leadership role in the payments industry, and supporting economic well-being in communities through a variety of efforts.
Company Federal Reserve Bank of Boston Federal Reserve Financial Services (FRFS) delivers a suite of payments services to financial institutions via FedLine® Solutions, Fedwire® Funds and Securities, the National Settlement Service (NSS), FedCash®1, FedACH®, Check Services, and the FedNow® Service. FRFS operates as a fully integrated organization with groups dedicated to customer experience, operations, technology, product and customer/industry management, enterprise services, payments system improvement, and one focused on the ongoing growth and development of the FedNow instant payment service. Our strategy defines our future direction, seeking to offer a fully integrated product suite that provides speed, resilience, and choice in meeting the payments needs of FRFS customers across the United States. Through our Enterprise structure, we strive to meet the needs of the marketplace for new products and services with speed and agility, seek to provide a robust and unified customer experience, and work to create career growth opportunities for FRFS staff. The FRFS Enterprise operates with a customer-first mindset, comprised of team members seeking to do the best work of their careers in pursuit of our important central bank mission. This job is eligible for remote work within the United States. Proximity to one of our 12 Districts is highly preferred. You may be required to attend in-person meetings and other events as business needs dictate. Remote work flexibility is contingent upon local district approval and business needs. This position is responsible for helping to ensure the security and integrity of the FedNow organization across people, operations, and technology. This individual will directly support security engineering and operations. The individual will also be expected to provide cybersecurity expertise both through consultation and hands-on technical activities. What will be expected of you - Develop code to automate security configuration management. - Build, test, and deploy cybersecurity relevant technical solutions. - Support security investigations through data analysis and information gathering. - Build tooling to conduct pro-active hunting for malicious activity impacting FedNow holistically. - Represent a technologists point of view in selecting tooling and solutions. - Participate in agile activities with geographically dispersed agile delivery teams. - Proven ability to collaborate, build relationships and influence direct team members in a matrix-management environment. - Provide informal guidance, direction and/or oversight to less experienced colleagues. - Actively seekto remove barriers and improve security across the program. - Document technical solutions developed and the supporting processes. - Strong interest in current security threats, techniques, and landscape, as well as a dedicated and self-driven desire to research current information security landscape. - Identify and address the root causes of issues, focusing on solving problem categories rather than individual instances. Engage early and comprehensively. Expertise you would bring - Lead and execute cyber incident response activities, including detection, analysis, containment, eradication, and recovery. - Ability to program or script in Bash, Python, Java, or Go. - Ability to utilize tools like CI/CD Automation similar to TravisCI, CircleCI, Github Action, Gitlab Pipelinesor AWS CodeDeploy. - Expertise with Cloud IAM Configuration, Container Orchestration, and Log Management. - Ability to rapidly produce proof-of-concept code to demonstrate potential solutions. - Knowledge of, and experience with, cloud computing technology. - Knowledge of IT Infrastructure designs, technologies, products, and services. This should include knowledge of networking protocols,operating systems, databases, and other technologies. - Knowledge and experience normally acquired through, or equivalent to, the completion of a Computer Science or Computer Engineering Bachelors degree witha minimum of 5-7years of job-related experience. - Strong communication skills with ability to influence at all levels of the organization; ability to simplify complex security topics for consumption and critical decision making - Proven experience as a Cyber Incident Response Analyst/Engineer, with a focus on senior-level responsibilities. - Deep understanding of cyber threats, vulnerabilities, and attack vectors. - Strong analytical and problem-solving skills. - Relevant certifications (e.g., CISSP, CISM, GIAC, AWS, AZURE). - Experience working in a software development environment. - Knowledge of cloud security best practices. Logistics and Requirements - The ability to obtain security clearance. - Federal Reserve System candidates will remain employed at current Federal Reserve Bank, but report into the FedNow team via cross-district arrangement. - Be able to support on-call and work-rotation activities The salary range for this position is $149,500 - $224,300. The Boston Fed believes in salary transparency. The final salary and offer will be determined by the applicant's background, skills, internal equity, and alignment with market data. Whether you're developing into the job or are a more seasoned candidate, we aim to pay competitively. If you reside outside of the 1st District (Boston), you may be hired by your local Federal Reserve District and compensation will follow hiring District's range and policy. All employees assigned to this position will be subject to FBI fingerprint/ criminal background and Patriot Act/ Office of Foreign Assets Control (OFAC) watch list checks at least once every five years. The above statements are intended to describe the general nature and level of work required of this position. They are not intended to be an exhaustive list of all duties, responsibilities or skills associated with this position or the personnel so classified. While this job description is intended to be an accurate reflection of this position, management reserves the right to revise this or any job description at its discretion at any time. The Federal Reserve System is committed to a diverse and inclusive workplace and to provide equal employment opportunities to all persons without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, age, genetic information, disability, or military service. All employees assigned to this position will be subject to FBI fingerprint/ criminal background and Patriot Act/ Office of Foreign Assets Control (OFAC) watch list checks at least once every five years. The above statements are intended to describe the general nature and level of work required of this position. They are not intended to be an exhaustive list of all duties, responsibilities or skills associated with this position or the personnel so classified. While this job description is intended to be an accurate reflection of this position, management reserves the right to revise this or any job description at its discretion at any time. For this job, any offer of employment is contingent upon successfully passing a two-phase security screening. The first phase consists of the satisfactory completion of a physical examination (including a drug screening), reference checks, and a security investigation consisting of credit and criminal history checks. The second phase, which might not be complete until after you begin working at the Reserve Bank, is an additional risk-based security screening determined by the risk rating of the position. Depending upon the sensitivity of the position, this phase may include, and is not limited to, work and residency eligibility verification, and personal interviews with the candidate, references, and prior employers. All applicants must have resided in the United States for at least three (3) years Full Time / Part Time Full time Regular / Temporary Regular Job Exempt (Yes / No) Yes Job Category Information Technology Family Group Work Shift First (United States of America) The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences. Always verify and apply to jobs on Federal Reserve System Careers (https://rb.wd5.myworkdayjobs.com/FRS) or through verified Federal Reserve Bank social media channels. Privacy Notice

