Match score not available

Senior Security Engineer

Remote: 
Full Remote
Salary: 
186 - 228K yearly
Experience: 
Senior (5-10 years)
Work from: 

EarnIn logo
EarnIn Financial Services SME http://earnIn.com/
201 - 500 Employees
See all jobs

Job description

ABOUT EARNIN

As one of the first pioneers of earned wage access, our passion at EarnIn is building products that deliver real-time financial flexibility for those with the unique needs of living paycheck to paycheck. Our community members access their earnings as they earn them, with options to spend, save, and grow their money without mandatory fees, interest rates, or credit checks.

We’re fortunate to have an incredibly experienced leadership team, combined with world-class funding partners like A16Z, Matrix Partners, DST, Ribbit Capital, and a very healthy core business with a tremendous runway. We’re growing fast and are excited to continue bringing world-class talent onboard to help shape the next chapter of our growth journey.

POSITION SUMMARY

We are seeking a highly skilled and motivated Offensive Security Engineer to join our security team. The ideal candidate will be responsible for conducting penetration testing on our company applications, identifying vulnerabilities, and providing actionable recommendations to enhance our security posture. This position is full-time and remote. The US Remote base salary range for this position is $186,300 - $227,700 plus equity and benefits. 

WHAT YOU'LL DO

  • Conduct internal penetration testing on our product to identify security vulnerabilities and assess risk.
  • Perform security architecture reviews for new product features, ensuring robust design and threat mitigation.
  • Create, analyze, and critically review data flow diagrams (DFDs) to identify potential security weaknesses.
  • Collaborate with engineering teams to provide secure design recommendations and integrate security best practices.
  • Ensure thorough documentation and attention to detail in security assessments and findings.
  • Assist with vulnerability management, including reviewing security findings and prioritizing remediation.
  • Help develop and maintain security guidelines, best practices, and technical documentation.
  • Stay updated on the latest security threats, attack techniques, and defensive strategies.
  • Provide mentorship and security guidance to engineering teams when needed.

WHAT WE’RE LOOKING FOR

  • Strong experience in penetration testing, including identifying and exploiting security flaws in web applications, APIs, and infrastructure.
  • Proficiency in security architecture reviews, understanding of secure design principles, and ability to communicate findings effectively.
  • Experience creating and critically reviewing data flow diagrams (DFDs) to identify security issues.
  • Excellent attention to detail and ability to document findings thoroughly.
  • Programming experience (Python, Java, JavaScript, or similar)
  • Experience with security tooling such as Nmap, Burp Suite, Metasploit, or custom-built security scripts.
  • Familiarity with threat modeling methodologies and security frameworks (e.g., STRIDE, OWASP, NIST).
  • Strong understanding of web application security, authentication mechanisms, and cloud security principles.
  • Ability to work cross-functionally with product, engineering, and security teams to integrate security at every stage of development.
  • Knowledge of container security (Docker, Kubernetes) and cloud platforms (AWS, Azure).
  • Understanding of vulnerability management processes and security risk assessment frameworks.

At EarnIn, we believe that the best way to build a financial system that works for everyday people is by hiring a team that represents our diverse community. Our team is diverse not only in background and experience but also in perspective. We celebrate our diversity and strive to create a culture of belonging. EarnIn does not unlawfully discriminate based on race, color, religion, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), gender identity, gender expression, national origin, ancestry, citizenship, age, physical or mental disability, legally protected medical condition, family care status, military or veteran status, marital status, registered domestic partner status, sexual orientation, genetic information, or any other basis protected by local, state, or federal laws. EarnIn is an E-Verify participant. 

EarnIn does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job postings. No fee will be paid to third parties who submit unsolicited candidates directly to our hiring managers or HR team.

#LI-Remote

Required profile

Experience

Level of experience: Senior (5-10 years)
Industry :
Financial Services
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Detail Oriented
  • Collaboration

Security Engineer Related jobs