SlipstreamJobsFresh Startup & VC-Backed Jobs

First Dedicated Security Engineer

Savvy - New York, NY, USA - In-office - posted 2026-09-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Savvy Wealth is a Series C fintech company ($200M raised, $100M ARR in sight) reinventing wealth management through AI-native technology. The company partners with independent financial advisors, providing them a modern platform, investment management, and back-office operations so they can focus on growth. Savvy is ranked the No. 1 fastest-growing financial services company in America (Inc. 2026) and is a Certified Great Place to Work. You will be Savvy's first dedicated security hire, reporting to the Director of IT & Information Security and CTO. This is a hands-on, technical security engineering role—not compliance or GRC. Your mission is to execute the security strategy by identifying vulnerabilities, remediating them, and closing gaps in both the product and the SaaS tools the organization uses daily. Key Responsibilities: - Own vulnerability management end-to-end: identify, triage, prioritize by real-world risk, and drive remediation across product, codebases, and cloud infrastructure (AWS, GCP, Cloudflare). - Build and operate the AppSec tooling pipeline: secrets scanning in CI/git, SCA/dependency scanning with triage SLAs, and SAST rollout on sensitive repos, tuned for signal over noise. - Set and enforce security hygiene standards in codebases, including code review standards that account for AI-generated code (authorship transparency, mandatory human review on security-sensitive paths). - Partner with the internal AI team to design guardrails for AI-assisted development (including non-technical builders using AI tools): sanctioned tooling, data handling boundaries, dependency vetting, and secure defaults. - Secure the SaaS stack: harden configurations, review OAuth grants and third-party integrations, reduce misconfiguration risk across Google Workspace, GitHub, Rippling, and Slack. - Establish conditional access and identity-layer controls in partnership with IT (SSO, phishing-resistant MFA, managed-device posture). - Define cloud and SaaS configuration baselines for the infrastructure footprint. - Contribute to detection and response readiness: high-signal detections (new OAuth grants, mass code-host downloads, credential anomalies) and participate in incident response. - Work cross-functionally with Engineering, IT, and the internal AI team; articulate risk, remediation paths, and tradeoffs to technical and non-technical stakeholders. The role is deliberately not compliance-focused. There are no audits to run, no certifications to chase, and no questionnaires to fill out. Your job is to make the secure path the easy path, enabling the organization to move fast while staying safe. Requirements: - 5+ years of hands-on security engineering experience, with significant time in application security or product security in a small security engineer organization. - Strong software engineering fundamentals; comfortable reading, writing, and remediating code, not just filing findings. - Track record of enforcing security across technical and non-technical teams without slowing anyone down. - Experience embedding security into existing workflows rather than bolting it on. - Deep experience with the modern AppSec toolchain: secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration (GitHub-centric). - Practical experience securing SaaS environments: OAuth and third-party app review, configuration hardening, and least-privilege access design. - Working knowledge of cloud security across AWS and/or GCP, and edge/CDN security (Cloudflare). - Pragmatic, risk-based mindset: prioritize by what actually gets exploited, ship iteratively, and avoid drowning teams in noise. - Strong perspective on AI-assisted development security: understand how AI coding tools change AppSec risk (hallucinated dependencies, leaked secrets, insecure patterns at scale) and how to build guardrails without killing velocity. - Excellent communication skills and ability to work independently in a fast-paced environment. - Strong writing skills; Savvy is a written culture. Nice to Have: - Experience building security programs at an early-to-mid stage company, taking a function from reactive to systematic. - Experience with SaaS security posture management, CSPM, or identity threat detection. - Familiarity with securing LLM-based tooling, agentic workflows, or internal AI platforms. - Detection engineering experience (SIEM/MDR, high-signal alerting). - Fintech or financial services environment experience. - Offensive security background (pentesting, bug bounty, red team) that informs defense.

Similar roles