407,354open jobs
14,154companies
73,129added this week
Browse all
Salary
$109k – $222k per year (Estimated)
Location
Remote (United States, Canada)
Seniority
Senior · 7+ years exp
Overview
Company
Impact
Profile match
Spinwheel is a California fintech founded in 2019 that provides consumer debt data and payment APIs. Its infrastructure connects apps to student loan, credit card and other liability accounts. The company serves lenders, banks and financial wellness platforms.

About the Role

We're looking for a hands-on Senior Security Engineer to own the technical security posture of our platform, infrastructure, and AI-driven systems. You'll spend most of your time in the systems themselves: hardening infrastructure, closing vulnerabilities, and building the guardrails that keep our AI-driven workflows safe.

Following our recent Series A, we're scaling rapidly and investing deeply in platform security, AI safety, and operational resilience. This is a builder's role, not a policy role. You'll work closely with Engineering to secure production systems, find weaknesses, and keep our monitoring and incident response sharp as we scale.

As a remote-first company, we welcome applicants based anywhere in the United States or Canada.

You'll join a high-ownership, high-trust engineering culture where self-starters thrive and autonomy is the natural state of work.

Key Responsibilities

Security Engineering & System Hardening

  • Secure and harden cloud infrastructure, applications, APIs, internal systems, and operational workflows.
  • Implement and maintain security controls across production environments, CI/CD pipelines, cloud infrastructure, and internal tooling.
  • Work directly with engineering teams to remediate vulnerabilities and improve secure development practices.
  • Ensure encryption, secrets management, logging, monitoring, and access controls are properly implemented and continuously maintained.
  • Design and improve security architecture across cloud-native and distributed systems.
  • Build scalable security processes that integrate directly into engineering and operational workflows.

Vulnerability Management & Offensive Security

  • Continuously identify, assess, prioritize, and remediate security vulnerabilities across infrastructure, applications, APIs, and operational systems.
  • Proactively search for weaknesses through vulnerability scanning, penetration testing, adversarial testing, threat modeling, and manual security reviews.
  • Coordinate remediation efforts across engineering and operations teams, and validate fixes to ensure long-term mitigation.
  • Improve detection and prevention capabilities for emerging threats.
  • Help establish a culture of continuous security improvement and operational accountability.

AI Security & Emerging Threat Protection

  • Secure AI-driven systems and automated agents against prompt injection, adversarial inputs, unauthorized or unintended actions, unsafe outputs, and data leakage.
  • Design and implement guardrails and validation layers for AI-generated actions.
  • Ensure AI systems safely handle untrusted inputs from IVRs, web systems, APIs, and human interactions.
  • Monitor AI system behavior for anomalies, abuse attempts, or unsafe decision-making.
  • Partner with engineering teams to ensure AI systems are observable, auditable, bounded, and fail safely.
  • Help define operational and technical controls for responsible AI deployment.

Monitoring, Detection & Incident Response

  • Improve and maintain security monitoring, alerting, logging, and incident response capabilities.
  • Investigate suspicious activity, anomalies, and potential security incidents.
  • Lead or support incident response efforts, root cause analysis, and remediation planning.
  • Ensure operational visibility into system health, access patterns, and security events.
  • Recommend and implement preventative measures following incidents or security discoveries.

Required Qualifications

  • 7+ years of hands-on experience in security engineering, infrastructure security, application security, DevSecOps, or offensive security.
  • Exceptional knowledge of the AWS ecosystem.
  • Demonstrated experience identifying and remediating vulnerabilities in live production systems.
  • Self-starter mindset: able to drive projects, make decisions, and prioritize ruthlessly in a fast-moving environment.
  • Strong communication skills, with the ability to explain technical security issues clearly to engineering stakeholders.

Preferred Qualifications

  • Experience securing AI/LLM-powered systems or automated agents.
  • Familiarity with prompt injection attacks, adversarial AI techniques, AI guardrails, and behavioral anomaly detection.
  • Experience with cloud security tooling, SIEM and observability platforms, penetration testing tools, endpoint security platforms, and infrastructure-as-code security.
  • Prior experience in high-growth startup, fintech, banking, or payments environments.
  • Certifications such as CISSP, CISM, AWS Security Specialty, or similar.

What We Offer

  • 100% remote-first culture (work anywhere in the US or Canada)
  • Competitive salary and equity opportunities
  • Unlimited PTO, flexible schedule, and paid holidays
  • Comprehensive health, dental, and vision insurance
  • A culture built on ownership, transparency, autonomy, and craftsmanship
  • Real opportunities for architecture ownership and technical leadership
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
407,354 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
In office • 5+ years exp • Bachelor's Degree
Ruby
TypeScript
Ruby
Ruby on Rails
Databases
ElasticSearch
Redis
DevOps
Amazon S3
AWS
AWS Lambda
CDKTF
CI/CD
CircleCI
Docker
GitHub
GitHub Actions
Jenkins
Terraform
Apply
$120k – $135k per year • Remote • 5+ years exp • PhD
Python
Ruby
TypeScript
Ruby
Ruby on Rails
Databases
Amazon Aurora
DynamoDB
MySQL
OpenSearch
PostgreSQL
DevOps
Amazon EC2
Amazon ECS
AWS
AWS Fargate
AWS Lambda
CI/CD
Docker
FinOps
GitHub
IAM
Platform Engineering
Terraform
Terragrunt
Cybersecurity
Least Privilege
Apply
$128k – $214k per year • In office • 8+ years exp • Bachelor's Degree
Bash
C#
JavaScript
Python
Ruby
TypeScript
DevOps
AWS
CI/CD
Apply
$180k – $322k per year • In office • 15+ years exp • Bachelor's Degree • Herndon
Python
DevOps
Ansible
AWS
Azure
CI/CD
FinOps
GCP
Red Hat
Terraform
Cybersecurity
FedRAMP
SOC 2
Zero Trust
Management
Google Workspace
ServiceNow
Apply
$115k – $190k per year • Remote/Hybrid • High School Diploma • Ashburn
Java
SQL
Java
Apache Tomcat
Gradle
Hibernate
Maven
Spring Boot
Databases
Apache Solr
Cassandra
DynamoDB
ElasticSearch
MySQL
Oracle
PostgreSQL
AI/ML
Hadoop
Jupyter Notebook
Spark
DevOps
Amazon EC2
Amazon S3
AWS
Bamboo
Bitbucket
CI/CD
Git
Jenkins
Rest API
Management
Confluence
Jira
Apply
$77k – $162k per year (Estimated) • Remote • 5+ years exp
Python
SQL
Databases
Amazon Redshift
AI/ML
ChatGPT
Claude
Claude Code
Analytics
ETL/ELT
Power BI
Tableau
Management
Freshdesk
Jira
QuickBooks
Slack
Apply
$130k – $254k per year (Estimated) • Remote • 8+ years exp
SQL
Analytics
A/B Testing
Management
Zoom
Apply
In office
AI/ML
AI Agents
Marketing
HubSpot
Apply
See all jobs
This is one of many
407,354 more open roles from verified company boards, updated every day.