Jobs Companies Beyond Finance Staff Security Engineer

Über diese Staff Security Engineer Stelle bei Beyond Finance

Beyond Finance · Remote · Remote

At Beyond Finance, we've made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care, a culture focused on compliance and ethics, supportive user-centric technology, and customized financial solutions, we've helped over 1 million clients on their path to a brighter future.

While we're proud of what we've already accomplished, we're searching for new collaborators to help us get to the next level! If you're looking to join a forward-thinking, rapidly growing organization with helping people as its number one goal, we want to hear from you.

 

Role Overview

As a Staff Security Engineer, you'll get involved early with Product and Software Engineering teams to embed security into our architecture and processes as they design, build, and ship. You'll also be someone the Security team can pull into any project, at any phase and regardless of domain, to make sure it lands on the right security outcome.

This is a hands-on role, and you don't need to be an expert in all three areas: application security, cloud security, and security automation and tooling. You should be excellent in one of the three and capable enough in the other two to contribute without hand-holding. That primary expertise needs to be strong enough to raise the bar on architecture, process, and technical decisions across the whole security department, with judgment engineers trust even in systems you don't personally own.

What You'll Do

Cross-Domain Security Leadership

  • Serve as the security technical authority the Security team can bring in at any phase of a project, design, build, or post-incident, regardless of domain, to steer toward the right security outcome.
  • Raise the bar on security architecture, process, and technical decisions across the department, not just within your primary domain.
  • Partner with engineering and DevOps during design and sprint planning to proactively address risk before it ships.
  • Build and maintain secure development and secure-infrastructure standards, playbooks, and enablement materials used across engineering.

Application Security

  • Guide secure design, threat modeling, and code review for web and mobile applications.
  • Manage and improve application security tooling: SAST, SCA, secret scanning, DAST, attack surface management (ASM), and mobile application security tooling.
  • Triage application-level vulnerability findings and drive remediation with engineering teams.

Cloud Security

  • Contribute to cloud security posture across the AWS environment, including IAM, network segmentation, container security, secrets, and data exposure, using CNAPP and AWS-native tooling.
  • Establish secure defaults in Infrastructure as Code (Terraform) through reusable modules, guardrails, and policy as code, in partnership with DevOps: DevOps owns the modules, security owns the policy.
  • Operate and tune WAF: managed and custom rules, rate limiting, and bot mitigation.
  • Contribute to vulnerability management across cloud and application findings: intake, prioritization, SLA tracking, and remediation.

Security Automation & Tooling

  • Build automation and internal tooling that scales the security team: ingestion, deduplication, prioritization, and developer-facing workflows, primarily in Python.
  • Build and operate security log pipelines and tune SIEM detections and alerts.
  • Deploy and tune security controls across the endpoint fleet.
  • Instrument the security stack through its APIs and write the connective code that ties tools together.

CI/CD & Pipeline Security

  • Partner with DevOps to harden CI/CD pipelines and embed security checks, including scanning, secrets detection, and policy-as-code gates, into the developer workflow without slowing it down or getting disabled.

What We're Looking For

Requirements

  • 10+ years of hands-on security engineering experience.
  • Deep, demonstrable ownership of one of the following domains, with working proficiency across the other two:
  • Application security: secure coding practices, OWASP Top 10, SAST/DAST/ASM tooling, and secure SDLC.
  • Cloud security: AWS security background including IAM, networking, container orchestration, and logging and audit; CNAPP-driven posture management; and vulnerability management at scale.
  • Security automation and tooling: building custom tooling and log pipelines from scratch, primarily in Python; SIEM onboarding and detection engineering; and endpoint security across a mixed fleet.
  • Working knowledge of OWASP Top 10 and threat modeling.
  • Hands-on Infrastructure as Code experience; Terraform.
  • Operates independently and drives projects without day-to-day oversight.

Nice to Have

  • PCI-regulated or financial services environment experience.
  • Mobile application security experience.
  • AI/ML security exposure: prompt injection, data poisoning, model abuse, and the controls that mitigate them.
  • Identity security across human and non-human identities.
  • Development experience with Ruby on Rails, Python, Go, or similar languages.

The Ideal Candidate

The ideal candidate measures success by reduced risk, not tickets closed. They understand how an attacker would approach a system and use that understanding to favor secure design and simple guardrails over adding more scanners or approval gates. They treat application code, cloud infrastructure, identity, and the pipeline as one connected system rather than separate problems.

This person is proactive. Given an ambiguous problem, they identify the highest-impact piece and start working on it rather than waiting for a fully scoped ticket, and they'd rather deliver a partial fix now and improve it over time than spend months on the perfect design. When a fix is needed in a system they don't own, they make the change themselves, get it reviewed, and ship it rather than filing a ticket and waiting on someone else.

Engineers trust this person's judgment even on systems they don't personally own. They catch a bad design, a fragile system, or an overlooked risk before it ships, including in areas outside their primary domain, and they flag potential blockers early enough to design around them instead of working around them later.

Why Join Us

  • High-ownership role with the license to influence architecture, tooling, and process across the entire security and engineering organization, not just your own domain.
  • Work spans application security, cloud security, and security automation rather than being boxed into one lane.
  • Modern engineering environment with strong leadership support for security.
  • Competitive compensation, benefits, and growth opportunities.

#LI-LB2

The base annual salary range is listed below. This role is eligible for additional incentives, including an annual bonus.

Base Salary Range
$160,000$195,000 USD

Why Join Us?

While you make a difference for others, we’ll work to make a difference for you, providing an uplifting, collaborative work environment and benefits that reflect your value to us. For eligible full-time employees, we offer:

  • Considerable employer contributions for health, dental, and vision programs
  • Generous PTO, paid holidays, and paid parental leave
  • 401(k) matching program
  • Merit advancement opportunities
  • Career development & training

And finally, our team spirit and culture! We cultivate an environment of community, connection, and belonging across our entire organization.

Beyond Finance does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job positions.  No fee will be paid to their parties who submit unsolicited candidates directly to Beyond Finance employees or the Beyond Finance HR team.  No placement fee will be paid to any third party unless such a request has been made by the Beyond HR team.

Bereit, sich bei Beyond Finance zu bewerben?
Bei Beyond Finance bewerben

Wie sich dieses Gehalt für Security Engineer vergleicht

Diese Stelle zahlt $177,500/yrim Einklang mit der üblichen Spanne für Security Engineer Stellen.

$101,734 dem Median $187,750 $273,400

Übliche Spanne $144,047–$227,500/yr, aus 253 vergleichbaren Security Engineer Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Security Engineer ansehen →

Ähnliche Jobs

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Beyond Finance

Alle Jobs bei Beyond Finance ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos