Avatar for Credit Sesame
Credit Sesame
Actively Hiring
We empower people to achieve their financial goals
  • B2C
  • Scale Stage
    Rapidly increasing operations
  • Top Investors
    This company has received a significant amount of investment from top investors
  • +1

Senior Security Engineer

Posted: 3 days ago• Recruiter recently active
Job Location
Remote Work Policy

In office - WFH flexibility

Visa Sponsorship

Not Available

RelocationAllowed
Skills
Python
Automation
Cloud Security
Jenkins
Disaster Recovery Planning
Vulnerability Management
Iso 27001
Security Policies
S3
Application Security
Ids/Ips
PCI DSS
GitLab CI
IAM
Security Incident Response
Patch Management
Pentest
Security Training
Network Penetration Testing
IaC
APIs
Risk metrics
Boto3
SAST
Palo Alto Panorama
SOC 2
AWS Security
AWS WAF
Network Configuration
Semgrep
Trivy
SCA
Runbooks
MCP Servers
Prompt Injection
Datadome
Internal Audits
Security Practices
VPC Flow Logs
ELK/Kibana
Data Exfiltration
Upwind
Attack Patterns
Detection Pipelines
Remediation SLAs
AI/LLM Systems
EDR/MDR
Database Access Controls
Inbound/outbound Rules
Secure Infrastructure Defaults
AppSec Scanning
Internal Security Tooling
Traffic/bot-Protection Alerts
Log Platform
Threat-Model
External Pentests

About the job

Credit Sesame is a leading financial wellness platform dedicated to helping consumers achieve better financial health through cutting-edge technology and data-driven solutions. With a decade of credit expertise and a proven track record of serving over 18 million users, Credit Sesame leverages AI and advanced analytics to empower individuals to better understand and manage their credit. Our recently launched Sesame Platform extends our mission by providing financial institutions with a turnkey AI-powered credit intelligence solution.

As our security engineer, you'll own security end-to-end for our platform — standing up open-source tooling, writing your own scripts and automation, and running assessments on our engineering team.

You'll...

  • Run security reviews for new tools, vendors, and projects — data handling, AI usage, DPAs, PII, authentication/authorization, and third-party security reports (SOC 2, PCI, ISO, pentest results)
  • Own access and infrastructure security — IAM least-privilege reviews, S3/database access controls, environment segregation, service-to-service authentication, and network configuration audits (VPC flow logs, inbound/outbound rules)
  • Run vulnerability management across cloud and endpoints, and manage IDS/IPS (e.g., Palo Alto Panorama, AWS WAF) and EDR/MDR tooling
  • Lead security incident response end to end — triage, investigate, contain, document, and build the runbooks as you go
  • Implement and maintain the technical controls supporting our PCI DSS and SOC 2 / ISO 27001 compliance programs, including internal audits, risk metrics, and disaster recovery planning
  • Partner with DevOps/IT on patch management and secure infrastructure defaults, and present tooling and risk recommendations to engineering leadership
  • Build our in-house AppSec scanning program — evaluate and pilot SAST/SCA/IaC tooling (Semgrep, Trivy, Upwind), integrate into GitLab CI and Jenkins, define severity-based remediation SLAs, and drive rollout across services
  • Build internal security tooling and automation — custom scripts and integrations (Python/boto3, APIs) that pull data from tools without native integrations into shared dashboards and reports
  • Build and tune detection pipelines — for example, feeding traffic/bot-protection alerts (Datadome) into our log platform (ELK/Kibana) and writing rules that catch real attack patterns
  • Threat-model and pentest our AI/LLM systems — scope risks like prompt injection and data exfiltration through MCP servers, coordinate external pentests where needed, and drive remediation
  • Maintain security policies and practices and drive training and adoption throughout the company

You're a great fit because...

  • You have 7+ years of hands-on security engineering experience across application security, cloud security, and network/penetration testing — not just one lane
  • You've driven tooling or architecture decisions independently (evaluated options, made the call, defended it to leadership)
  • You're self-directed, pragmatic, and ruthless about prioritization
  • You've built production automation from scratch — API integrations, custom collectors, or internal tooling — not just one-off scripts
  • You have hands-on experience deploying and running OSS security tools — Burp Suite Community/OWASP ZAP, Nmap, Nuclei, Metasploit, Semgrep, Trivy, Wazuh/OSSEC, ELK/Kibana, Prowler/ScoutSuite, HashiCorp Vault, or similar
  • You have solid AWS security experience
  • You have working knowledge of PCI DSS, SOC 2, and ISO 27001 — enough to implement controls and support audits
  • You're curious about emerging security domains and comfortable threat-modeling systems (like AI/LLM applications) that don't have an established playbook yet
  • You're an excellent communicator who can translate cost/coverage tradeoffs and technical risk for both engineers and executives
  • Bonus: OSCP, GPEN, or similar certifications; bug bounty experience; or experience securing LLM/AI-based systems
  • BS in Computer Science or related field, or equivalent hands-on experience

You'll love it here because...

  • You’ll have equity in a pre-IPO company backed by top VCs;
  • We offer comprehensive medical, dental, and vision insurance;
  • We offer a monthly home office stipend;
  • We offer a professional development program to support your continued growth
  • We offer flexible paid time off;
  • We have 10 paid holidays and additional 6 Sesame Wellness days;
  • We prize EQ and empathy, and have a culture that emphasizes total wellness, including work-life harmony.

At Credit Sesame, base pay is one part of our total compensation package. The estimated pay range for this role is $170,000 - $215,000 with actual salary based on a candidate’s location, qualifications, skills, and experience. Additionally, this role is eligible to participate in Credit Sesame’s equity plans.

We are open to hiring for this role in the following states where we are set up to hire employees: CA, CO, NC, NJ, NV, and TX.

By clicking "Submit Application" (or related call to action), you acknowledge that you have read the Credit Sesame Employment Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.

About the company

Credit Sesame company logo

Credit Sesame

Actively Hiring
We empower people to achieve their financial goals51-200 Employees
  • B2C
  • Scale Stage
    Rapidly increasing operations
  • Top Investors
    This company has received a significant amount of investment from top investors
  • 4.1
    Highly rated
    Credit Sesame is highly rated on Glassdoor, with 4.1 out of 5 stars
Learn more about Credit Sesame image

Funding

AMOUNT RAISED
$35.4M
FUNDED OVER
4 rounds
Rounds
D
$16000000
Series D - May 2015+3

Perks

Health Benefits and Wellness
As a TriNet partner, we offer a wide selection of benefit plan designs often found only at larger companies. We also offer free onsite fitness centers.
Flexible Spending Account
Customize your healthcare spending plan to best suit your lifestyle.
Open Paid Time Off
We have open paid time off, so you can take the time you need to be happy and healthy.
Lunch & Snacks
In addition to a fully-stocked kitchen and an endless supply of coffee and snacks, we have lunch catered daily.
Premium Credit Sesame Membership
We want our teammates to understand and improve their credit wellness.
Commuter Benefits
Save hundreds per year — whether you commute by bus, train, car or boat.
Team Events
From ping pong challenges to escape rooms to trips to Napa, we still find time to bond and have fun.
Life Insurance
We want to take care of your loved ones, too!
Equity
We offer meaningful ownership in our company so we can share in Credit Sesame's success.
Disability Insurance
Know that we’ve got your back, always.

Founders

Adrian Nazari
Founder
image
View the team image