FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Security Engineer
ReuseSenior Security Engineer securing Credit Sesame’s AI-powered financial wellness platform. Building AppSec, cloud security, incident response, compliance, detection, and LLM threat-modeling programs.
Posted 8/18/2026full-timeRemote • California, Colorado, Nevada, New Jersey, North Carolina, Texas • 🇺🇸 United StatesSenior💰 $170,000 - $215,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in security engineering, focusing on application security, cloud security, and network/penetration testing. Proficient in implementing compliance controls for PCI DSS, SOC 2, and ISO 27001 while driving security tooling and automation initiatives.
Highest-signal resume keywords
Security Engineering ExperienceApplication SecurityCloud SecurityVulnerability ManagementCompliance Implementation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security ReviewsVulnerability ManagementIncident ResponseThreat ModelingAutomation DevelopmentAccess ControlRisk AssessmentPenetration TestingSecurity ToolingData Protection
Soft Skills
Excellent CommunicationSelf-DirectedPragmaticPrioritization Focused
Tools & Technologies
AWS SecurityBurp SuiteOWASP ZAPNmapMetasploitELK/KibanaHashiCorp VaultGitLab CIJenkinsAPIs
Certifications & Qualifications
OSCPGPEN
Industry Keywords
PCI DSSSOC 2ISO 27001Data HandlingPIIIAMEDRMDRDisaster RecoveryThird-Party Security
Tech Stack
Tools & technologiesAWSCloudJenkinsPythonVault
About the role
Key responsibilities & impact- Run security reviews for new tools, vendors, and projects, including data handling, AI usage, DPAs, PII, authentication/authorization, and third-party security reports
- Own access and infrastructure security, including IAM least-privilege reviews, S3/database access controls, environment segregation, service-to-service authentication, and network configuration audits
- Run vulnerability management across cloud and endpoints and manage IDS/IPS and EDR/MDR tooling
- Lead security incident response end to end: triage, investigate, contain, document, and build runbooks
- Implement and maintain technical controls supporting PCI DSS and SOC 2 / ISO 27001 compliance programs
- Conduct internal audits, risk metrics, and disaster recovery planning
- Partner with DevOps/IT on patch management and secure infrastructure defaults
- Present tooling and risk recommendations to engineering leadership
- Build the in-house AppSec scanning program and evaluate, pilot, and integrate SAST/SCA/IaC tooling into GitLab CI and Jenkins
- Define severity-based remediation SLAs and drive rollout across services
- Build internal security tooling and automation using custom scripts, APIs, Python/boto3, dashboards, and reports
- Build and tune detection pipelines using tools such as Datadome and ELK/Kibana
- Threat-model and penetration-test AI/LLM systems, coordinate external pentests, and drive remediation
- Maintain security policies and practices and drive company-wide training and adoption
Requirements
What you’ll need- 7+ years of hands-on security engineering experience across application security, cloud security, and network/penetration testing
- Independent experience driving tooling or architecture decisions and defending recommendations to leadership
- Self-directed, pragmatic, and highly prioritization-focused
- Experience building production automation from scratch, including API integrations, custom collectors, or internal tooling
- Hands-on experience deploying and running open-source security tools such as Burp Suite Community/OWASP ZAP, Nmap, Nuclei, Metasploit, Semgrep, Trivy, Wazuh/OSSEC, ELK/Kibana, Prowler/ScoutSuite, and HashiCorp Vault, or similar
- Solid AWS security experience
- Working knowledge of PCI DSS, SOC 2, and ISO 27001 sufficient to implement controls and support audits
- Ability to threat-model emerging systems such as AI/LLM applications
- Excellent communication skills for translating cost/coverage tradeoffs and technical risk to engineers and executives
- BS in Computer Science or related field, or equivalent hands-on experience
- U.S. work authorization required; applicants must reside in CA, CO, NC, NJ, NV, or TX
- Bonus: OSCP, GPEN, or similar certifications; bug bounty experience; or experience securing LLM/AI-based systems
Benefits
Comp & perks- Equity in a pre-IPO company backed by top VCs
- Comprehensive medical, dental, and vision insurance
- Monthly home office stipend
- Professional development program
- Flexible paid time off
- 10 paid holidays
- Additional 6 Sesame Wellness days
- Culture emphasizing total wellness and work-life harmony