SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior DevSecOps Engineer

Greenboard - New York, NY, USA - Hybrid - posted 2026-08-17

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 165,000 - 240,000 / annual

Greenboard is building an AI-native compliance operating system for regulated financial institutions (RIAs, fintechs, private funds, hedge funds). The company has raised over $20M from Y Combinator, General Catalyst, and Base10, with a founding team from Amazon, Google, and unicorn startups. You'll be the first dedicated security hire on the engineering team, owning and scaling security posture as the company grows internationally. This is a high-autonomy, high-impact role requiring hands-on technical work across the full security stack. Technical responsibilities include: detecting and remediating vulnerabilities across infrastructure, application, and network layers; managing third-party penetration tests; integrating security into the development lifecycle via code review guardrails, SAST/DAST tooling, and dependency scanning; managing secrets and credentials; and coordinating infrastructure patching and hardening. Compliance and frameworks work includes owning the SOC 2 compliance program end-to-end (audit prep, evidence collection, remediation tracking); maintaining and maturing GDPR compliance; leading ISO 42001 certification efforts for AI governance; and researching/implementing additional frameworks as the company expands. You'll also manage inbound security diligence during customer sales cycles, build vendor security review processes, maintain security documentation libraries, and oversee endpoint security (MDM, disk encryption, OS patching) and access control policies (SSO, MFA, least-privilege). Required: 5–10 years in security engineering, application security, or infrastructure security; hands-on SOC 2 audit experience plus at least one other compliance framework (GDPR, ISO 27001, PCI-DSS); strong technical foundation (code review, AWS infrastructure, CI/CD); experience with vulnerability management tools (Snyk, Semgrep, Qualys, Burp Suite); AWS Secrets Manager and IAM expertise; third-party pentest coordination; and clear communication across technical and non-technical audiences. Nice-to-have: fintech/regulated-industry startup experience, ISO 42001 or AI governance familiarity, MDM platform experience, international expansion security/compliance background.

Similar roles