SlipstreamJobsFresh Startup & VC-Backed Jobs

Founding Security Engineer

Casca - San Francisco, CA, USA - In-office - posted 2026-09-16

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Casca is building AI-native banking technology to replace legacy systems and automate manual work. As a Founding Security Engineer, you will own security across a multi-tenant AI platform handling sensitive borrower data (tax returns, bank statements, credit information) for FDIC-insured banks. Your responsibilities include: - Building production security software: detections, libraries, policy-as-code, automation, and CI/CD checks deployed like standard services - Conducting design reviews and threat modeling on authentication, tenant isolation, data handling, and borrower PII protection - Securing the AI attack surface: prompt injection, tool-use abuse, exfiltration paths through agents, and building evals to validate controls - Managing incidents end-to-end, including write-ups and follow-up fixes - Translating bank security reviews and audit requirements into engineering improvements rather than compliance paperwork Security is not a checkbox here—it's a precondition for the company's existence. Every customer deal depends on passing security reviews, control questionnaires, pen tests, and third-party risk assessments. You will build the guardrails, defaults, and tooling that scale security across a rapidly growing engineering team shipping daily. You'll work in a collaborative environment with a talented team, shape the future of banking through AI, and have access to mentorship and professional growth opportunities. The company operates with high intensity, particularly during major launches and high-impact sprints. REQUIREMENTS: - Several years of hands-on AppSec experience with specific examples: bugs found, incidents managed, systems hardened, tooling shipped - Production code writing capability, primarily in TypeScript/Node.js and Python - Deep understanding of multi-tenant system security boundaries and authorization failures - Ability to explain security risk to engineers in technical terms and drive fixes without escalation - Experience presenting to and answering hard questions from bank security teams - Steady incident response and honest post-incident analysis - Preference for building scalable solutions over becoming a bottleneck HELPFUL (NOT REQUIRED): - Experience securing LLM or agentic products in production - Building security functions at fast-growing companies - Background in regulated financial institutions (SOC 2, GLBA, FFIEC guidance, third-party risk, exam support)

Similar roles