SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Casca is building AI-native banking technology to replace legacy systems and automate manual work. As a Founding Security Engineer, you will own security across a multi-tenant AI platform handling sensitive borrower data (tax returns, bank statements, credit information) for FDIC-insured banks.
Your responsibilities include:
- Building production security software: detections, libraries, policy-as-code, automation, and CI/CD checks deployed like standard services
- Conducting design reviews and threat modeling on authentication, tenant isolation, data handling, and borrower PII protection
- Securing the AI attack surface: prompt injection, tool-use abuse, exfiltration paths through agents, and building evals to validate controls
- Managing incidents end-to-end, including write-ups and follow-up fixes
- Translating bank security reviews and audit requirements into engineering improvements rather than compliance paperwork
Security is not a checkbox here—it's a precondition for the company's existence. Every customer deal depends on passing security reviews, control questionnaires, pen tests, and third-party risk assessments. You will build the guardrails, defaults, and tooling that scale security across a rapidly growing engineering team shipping daily.
You'll work in a collaborative environment with a talented team, shape the future of banking through AI, and have access to mentorship and professional growth opportunities. The company operates with high intensity, particularly during major launches and high-impact sprints.
REQUIREMENTS:
- Several years of hands-on AppSec experience with specific examples: bugs found, incidents managed, systems hardened, tooling shipped
- Production code writing capability, primarily in TypeScript/Node.js and Python
- Deep understanding of multi-tenant system security boundaries and authorization failures
- Ability to explain security risk to engineers in technical terms and drive fixes without escalation
- Experience presenting to and answering hard questions from bank security teams
- Steady incident response and honest post-incident analysis
- Preference for building scalable solutions over becoming a bottleneck
HELPFUL (NOT REQUIRED):
- Experience securing LLM or agentic products in production
- Building security functions at fast-growing companies
- Background in regulated financial institutions (SOC 2, GLBA, FFIEC guidance, third-party risk, exam support)