859,529open jobs
54,230companies
144,691added this week
Browse all
Salary
$170k – $230k per year
Location
Remote (United States)
Seniority
Senior
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 27, 2026. First seen by Alion on Aug 21, 2026. Flex scores C on the Alion truth index.

Overview
Company
Impact
Profile match
Flex is one finance platform for international business owners: multi-currency accounts, cross-border payments, stablecoins, corporate cards, and capital.

About the Role

We're hiring our first security engineers. Both report directly to the CTO.

We want software engineers with security as their superpower, not security specialists who occasionally write code. The distinction matters here. At our size, the only way one person covers a surface this large is to build things that keep working after they move on. A findings queue you work through by hand grows faster than you can close it. A guardrail in the deployment pipeline doesn't.

The work is product and infrastructure security: making the paths that move money hard to attack, and making the secure way to build something also the easy way. The ledger and its write path, card issuing, payouts, and our stablecoin work are the systems that matter most. The job runs in both directions. You'll be in design review early on anything new, and you'll be continuously assessing what we've already shipped, because most of Flex's risk lives in code that exists today. We don't expect you to read the codebase by hand or to keep a findings queue. We expect you to build the automation and repeatable checks that keep assessing it for you, and to spend the time you get back on the golden paths that stop whole classes of problem from arriving again.

There's no security team above you and no CISO. You'd set the standard here, and own the risk decisions that come with it. Day to day, what gets fixed now, what gets mitigated, and what we knowingly accept is your call. The large ones come to the CTO, who you report to directly and who'll back you when the answer is no. Corporate security posture, endpoints, and identity sit with our IT and Corporate Engineering function, and those decisions are theirs to make.

At a company shipping this fast, a security engineer who blocks everything is worse than no security engineer. The answer isn't to wave things through. It's to understand the system, the business context, and the actual risk well enough to find the mitigation that keeps the velocity. Sometimes the answer is still no, and we'd want that to come from a real read of the risk rather than a standard applied by default. Getting engineers to adopt something matters here as much as finding the problem in the first place. The version of this job that works has Security and Engineering solving the problem together.

Compensation: $170,000 - $230,000 a year, depending on experience, plus equity.

What You'll Do

  • Threat model the paths that move money: the ledger and write path, card issuing, payouts, and the stablecoin work. Do it inside design review on anything that touches money, continuously, not as a quarterly exercise.

  • Build secure-by-default infrastructure. Infrastructure as Code (IaC) guardrails, CI/CD supply chain integrity, secrets handling, service isolation, and workload IAM.

  • Build a just-in-time, least-privilege access system for cloud access that makes engineers faster while narrowing what any one credential can do.

  • Own application security across both new and existing systems. Continuously assess the highest-risk parts of what we've already shipped, and build automated checks and secure defaults into the development lifecycle so the same problems stop arriving. Code review on high-risk paths, dependency and SBOM hygiene, and static and dynamic analysis where it earns its keep. Eliminate whole vulnerability classes; leave the instance-by-instance work to the machines.

  • Build a golden path that keeps sensitive data out of logs, and the tooling that proves it stayed out.

  • Run our vulnerability disclosure program end to end, and grow it into a bug bounty when we can triage at that volume. You'd take this over from an engineering leader who's carrying it today.

  • Scope and manage external penetration tests, and drive the remediation afterwards. We buy offensive testing; you decide what to point it at.

  • Build security automation, including AI-assisted triage and review, so that two people can cover a surface that usually takes a larger team.

  • Partner with Engineering, IT and Corporate Engineering, Risk, and Compliance. You'll be technical input on partner security reviews and audits without owning the paperwork.

What Makes You a Great Fit

  • You're a strong software engineer first. You'd be comfortable in our normal engineering interview loop.

  • You think like a builder and an attacker at the same time, and you'd rather remove a class of vulnerability than file fifty tickets about it.

  • You care about developer experience. You've shipped a security tool or control that engineers actually adopted, and you can explain why they adopted it.

  • You can tell a senior colleague that what they built isn't safe, explain why in plain language, and work alongside them to build a better alternative.

  • You're comfortable owning problems end to end with limited guidance, and comfortable saying what you need rather than quietly absorbing it.

  • You make risk-based calls. You have strong opinions about secure defaults, you can tell a real risk from a theoretical one, and you're comfortable deciding something isn't worth fixing right now.

  • You know you won't personally touch every security problem here, and you don't want to. You build the defaults and the habits that let engineers make good security decisions without you in the room.

  • You can read a system diagram and find the trust boundary nobody drew.

  • You write clearly. Much of this job is convincing people in writing, across time zones.

What We're Looking For

  • Substantial hands-on experience building or securing systems in a fast-moving environment, including a stretch where you were the most senior person doing this work. We care about what you've built, not the year count.

  • Real software engineering ability in a language we'd ship (Python, Go, TypeScript, or similar). Not scripting alone.

  • Hands-on cloud infrastructure experience: AWS or GCP, Terraform or equivalent IaC, containers, and CI/CD pipelines you've changed, not only used.

  • Practical threat modeling on systems with real consequences, and the judgment to know which findings matter.

  • Experience with secrets management, workload identity, and service-to-service authorization.

  • Experience handling inbound vulnerability reports, including at least one difficult reporter.

  • Clear written communication and a bias toward writing things down.

Strongly Preferred

  • A platform, infrastructure, or DevOps background where you moved toward security by choice. A great infrastructure engineer who wants to do this work will beat a traditional security hire who wants to write policy, every time.

  • Experience at a small company, or as a founder, where you were the only person who could do this and had to decide what to skip.

  • Experience running a VDP or bug bounty program, including the triage.

  • Fintech, payments, or another regulated environment, on the building side.

  • Experience applying AI or LLM tooling to security work in a way that held up in production.

  • Certifications like OSCP or OSWE are a signal we'll happily read, but they don't substitute for an engineering track record.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
859,529 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Backend
Similar stack
Same company
In your city
$140k – $160k per year • Remote (United States) • Full-Time • 6+ years exp • Bachelor's Degree • Raleigh • Denver
Python
JavaScript
SQL
DevOps
Git
Docker
Kubernetes
Design
Figma
Apply
$34k – $41k per year • Remote (Portugal) • Full-Time • 3+ years exp
JavaScript
Java
SQL
Java
Maven
Spring Boot
Databases
Oracle
AI/ML
Copilot
Devin
DevOps
CI/CD
Git
Cybersecurity
SonarQube
Management
Confluence
Apply
≈ $43k – $106k per year (Estimated) • Remote (Portugal) • Full-Time • 10+ years exp • Bachelor's Degree • Lisbon
JavaScript
TypeScript
SQL
C#
C#
.NET
Frontend
Angular
Mobile
Dependency Injection
Management
Scrum
Apply
Senior Developer 4 days ago
≈ $43k – $106k per year (Estimated) • Remote (Portugal) • Full-Time • 5+ years exp • Lisbon
JavaScript
TypeScript
SQL
C#
C#
.NET
Frontend
Angular
Mobile
Dependency Injection
Apply
≈ $102k – $224k per year (Estimated) • Remote (United States, Canada, CT hours) • 5+ years exp
Python
Go
Java
C++
Go
Temporal
AI/ML
Copilot
Claude Code
Mobile
State Management
DevOps
Terraform
GCP
Helm
OpenTofu
Vercel
Azure
CI/CD
GitOps
ArgoCD
AWS
Kubernetes
Management
Slack
n8n
Scrum
Apply
$42k – $71k per year • Hybrid • 3+ years exp • Ottawa
JavaScript
TypeScript
C#
Node JS
C#
.NET
Node JS
Express
Frontend
React.js
DevOps
Terraform
CloudFormation
CI/CD
Git
AWS
Docker
Kubernetes
Amazon EKS
Amazon ECS
Management
Agile
Scrum
Apply
Backend Developer 2 hours ago
In office • Full-Time • 3+ years exp • Kuala Lumpur
JavaScript
SQL
C#
Node JS
C#
.NET
Databases
PostgreSQL
DevOps
Terraform
GCP
GitLab CI
Azure
CI/CD
Jenkins
Git
AWS
Docker
AWS Lambda
Amazon EC2
Amazon S3
Amazon CloudWatch
API Gateway
Management
Agile
Scrum
Apply
≈ $65k – $141k per year (Estimated) • In office • 2+ years exp • Bachelor's Degree • Baltimore
Python
MATLAB
Apply
≈ $55k – $120k per year (Estimated) • In office • 1+ year exp • Bachelor's Degree • Baltimore
Python
MATLAB
AI/ML
Computer Vision
Apply
$23k per year (net) • In office • Vladivostok
Python
SQL
Databases
ClickHouse
Apply
Software Engineer 11 months ago
$35k – $55k per year • Remote (Colombia) • Full-Time
TypeScript
Databases
PostgreSQL
DevOps
GCP
Trunk-Based Development
Apply
$55k – $100k per year • Remote (United States, Canada, Colombia) • Full-Time • 4+ years exp
JavaScript
TypeScript
Node JS
DevOps
GCP
Azure
AWS
Apply
Risk Analyst 5 days ago
$120k – $145k per year • Remote (United States) • Full-Time • 5+ years exp
Python
SQL
SAS
Management
QuickBooks
Apply
$18k – $25k per year • Remote (Brazil, US time zones hours) • Full-Time
Management
Linear
Slack
Google Sheets
Marketing
Salesforce
Zendesk
Apply
$145k – $200k per year • Remote (United States) • Full-Time
Python
TypeScript
DevOps
SLI/SLO/SLA
Windows
Cybersecurity
Okta
SOC 2
Management
Google Workspace
Apply
See all jobs
This is one of many
859,529 more open roles from verified company boards, updated every day.