SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Footprint is hiring a Security Engineer to own the product security boundary end-to-end for Percy, an AI agent platform that automates financial crime investigations for banks and fintechs. You'll report directly to the Head of Engineering and inherit a mature security architecture built on AWS Nitro Enclaves, KMS-based key management, append-only audit ledgers, and compliance programs already passing SOC 2 Type 2, PCI DSS Level 1, GDPR, and ISO 27001 audits.
You'll own four major security domains: (1) Vault and enclave security—assessing and hardening the Nitro Enclave-backed vault holding millions of identity records, including encryption, key management, hardware attestation, and cross-tenant isolation; (2) The Percy sandbox boundary—securing isolated Modal sandboxes where AI agents operate on live PII, including sandbox isolation, token scoping, network egress, and agent audit log integrity; (3) End-user data path security—reviewing PII collection, document capture, and generative UI layers that render screens based on agent decisions; (4) Document pipeline integrity—defending against adversarial document forgery attacks through tamper detection, classification, and fraud checks.
You'll also embed product security controls into compliance programs, scope and run technical pentests, and own vulnerability remediation end-to-end. The stack includes Rust, TypeScript, Postgres, AWS (Nitro Enclaves, KMS, IAM, VPC, CloudTrail, GuardDuels), Modal, and Vercel.
Must-haves: 5+ years hands-on security engineering (application or infrastructure); deep expertise in encryption, key management, and access control; understanding of code execution environment escapes and least-privilege enforcement on ephemeral compute; offensive security experience (pen testing, threat modeling, vulnerability research); hands-on AWS security (IAM, VPC, KMS, CloudTrail, GuardDuty); SOC 2 or PCI DSS audit experience; self-directed security gap identification and closure.
Nice-to-haves: AI/LLM agent or autonomous code execution security; trusted execution environment experience (Nitro Enclaves, Intel SGX); document fraud detection or adversarial ML robustness; Rust proficiency; security tooling development (SAST, DAST, CI/CD gates); KYC and identity verification domain knowledge.