B

Member of Technical Staff, Security Engineer

bareinsights Los Angeles, California, United States · $150K–$250K/yr

Yesterday
security Mid (2-5 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will own the end-to-end security posture for infrastructure, applications, and identity systems at a fintech startup. This includes implementing security controls, managing compliance programs, and securing autonomous agent activity.

What they look for

AWS Infrastructure Security Application Security Identity and Access Management Threat Modeling Secure Code Review Compliance SOC 2 Vulnerability Management Pentest Coordination Secrets Management Network Segmentation IAM Endpoint Security Kubernetes

Requirements

The role requires 3+ years of hands-on security engineering experience with a strong background in AWS and application security. Candidates should have experience building security programs from scratch in a startup environment.

Full description

About the Role

This is a founding security engineering role at a fast-moving fintech startup, giving you end-to-end ownership of infrastructure, application, and identity security across the organization. You'll set the security posture from the ground up — building programs that make the secure path the easy path, not a bottleneck — at a company where security is central to earning client and partner trust.

What You'll Do

  • Own infrastructure security across the full AWS environment, including VPC/VPN peering, network segmentation, IAM, and secrets management.
  • Lead application security for web and desktop clients, embedding threat modeling, supply-chain controls, and secure code review into the development lifecycle.
  • Design and implement identity and access controls (SSO, RBAC, least-privilege) for both human users and AI/agent systems.
  • Build audit trails and access controls that make autonomous agent activity fully reconstructable — what happened, on whose behalf, with what data, and why.
  • Partner with the IT managed service provider to secure endpoints, devices, and access for the in-office team.
  • Stand up and run compliance, auditability, bug bounty, VDP, and pentest programs that demonstrate security posture to clients, partners, and auditors.

What We're Looking For

  • 3+ years of hands-on security engineering or infrastructure security experience, with a strong track record in AWS (VPC, IAM, secrets management, network segmentation).
  • Practical application security experience: threat modeling, dependency/supply-chain controls, and secure code review.
  • Prior experience as a first or sole security hire at a startup, building programs from scratch with high autonomy.
  • Identity and access management implementation across both human and non-human (e.g. service, agent) actors.
  • Endpoint security and device management experience in an IT security context.
  • Compliance and auditability program experience (SOC 2, vulnerability management, pentest coordination).
  • Comfort operating in fast-moving environments with broad ownership and minimal established process.
  • Familiarity with Kubernetes is a plus.
  • Background in financial services or other regulated industries is a plus.
  • Experience securing AI or autonomous agent systems is a plus.

Compensation & Benefits

Base salary: $150,000 – $250,000 USD annually. Visa sponsorship is not available for this role.

Location

On-site in Los Angeles, CA. Candidates based in New York City, NY or San Francisco, CA may also be considered.

Similar roles