SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer

Thunes - San Francisco, CA, United States - Hybrid - posted 2026-04-09

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Thunes Financial Services is seeking a Security Engineer to serve as the architect of trust for their fintech platform. This hybrid role bridges Infrastructure Security and Application Security, requiring deep expertise in both domains to build resilient, compliant systems in a regulated environment. Day-to-day responsibilities include designing and maintaining CI/CD security integration, embedding SAST/DAST/SCA testing directly into deployment pipelines to make security a "paved road" for developers. You'll own full-stack security across the lifecycle—from securing AWS/GCP cloud infrastructure to performing code reviews and architectural risk assessments. The role involves managing vulnerability detection using modern scanning and dependency management tools, building automated workflows for vulnerability reporting, triage, and remediation using AI-powered agentic tools where applicable. Compliance engineering is a core focus: monitoring technical security controls to ensure they operate effectively throughout the year, supporting regulatory exams, SOC-2, and PCI audits. You'll also serve as a key member of the security response team, investigating and mitigating potential threats. You'll collaborate cross-functionally with Product, Data Engineering, Front-end Engineering, Tech Ops, Compliance, and Legal teams. The tech stack includes AWS/GCP, Kubernetes, CI/CD tools (GitHub Actions, GitLab CI, Jenkins), Python, Go, Bash, and enterprise vulnerability management platforms. Success means ensuring systems are resilient and compliant, maintaining regulatory posture, building automated scalable security guardrails, and directly impacting security strategy. Some travel is required for periodic team offsites. Required qualifications include a Bachelor's degree in Computer Science or equivalent professional experience, with proven deep experience in both Infrastructure Security and Application Security. You need hands-on experience building security guardrails in CI/CD tools, deep expertise in cloud/Kubernetes security and AppSec (OWASP Top 10, Secure SDLC), proficiency with enterprise vulnerability management platforms, and the ability to write code (Python, Go, Bash) to automate security workflows. Experience with AI-driven automation or agentic tools is required. Understanding of fintech's regulated environment and ability to translate compliance requirements into technical solutions is essential. Clear communication of trade-offs to non-technical stakeholders and a history of collaboration with engineers is expected.

Similar roles