SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Prelim builds digital account-opening infrastructure for community banks and credit unions. The company has sustained over 100% ARR growth for four consecutive years on seed funding and operates a platform critical to how banks onboard customers.
You will be Prelim's first dedicated security hire and will define the security program for the next generation of banking infrastructure. Your responsibilities span the full security lifecycle:
**Core Responsibilities:**
- Secure SDLC: implement dependency scanning, static analysis, security review of high-risk changes, and coordinate annual penetration tests. Mentor engineers to catch issues early.
- Partner with DevOps on IAM, secrets management, network architecture, logging, and detection systems.
- Develop security policies, conduct risk assessments, and build a security roadmap appropriate for the company's size and risk profile. Defend reasoning to auditors, bankers, and internal stakeholders.
- Own security questionnaires, vendor risk assessments, and customer security reviews. Banks conduct rigorous third-party risk management aligned with FFIEC guidance.
- Manage endpoint security, access reviews, phishing resistance, and offboarding hygiene.
- Own SOC 2 Type II compliance end-to-end: control design, evidence collection, and auditor management.
- Develop and own incident response: write the plan, run tabletops, and lead response if needed. Understand bank breach-notification contractual expectations.
**Requirements:**
- 5+ years in security engineering with breadth across application security, cloud security, and compliance
- Hands-on technical skills: ability to read code, write scripts, and configure cloud controls
- Owned or heavily contributed to a SOC 2 audit (or ISO 27001 / equivalent)
- Experience answering enterprise or financial-institution security reviews
- Strong written communication skills
- Judgment about proportionality: understanding which risks matter at early-stage scale and which controls are unnecessary
**Nice to Have:**
- Fintech or banking-vendor experience; familiarity with FFIEC, GLBA, or bank third-party risk management
- Experience as a first or early security hire
- Detection engineering / SIEM experience
- Familiarity with core banking integrations or handling of PII/KYC data flows