SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Engineer, Threat & Offensive Security

Valon Technologies - New York, NY, USA - Hybrid - posted 2026-08-31

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Valon is building an AI-native operating system for regulated finance, starting with mortgage servicing. The company operates its own mortgage servicing business managing $110+ billion in loans and has achieved 60%+ margins while improving customer experience. As a Series C company backed by a16z, Valon is transforming how regulated industries leverage AI and automation. The Security team at Valon is responsible for protecting sensitive financial information and infrastructure processing billions of dollars in mortgage loans. This Senior Security Engineer role focuses on threat and offensive security, scaling the company's security posture as it grows. Key responsibilities include conducting security testing and penetration tests across applications, infrastructure, and networks; managing and implementing security testing tools and frameworks; designing AI-enabled workflows to scale security testing and threat operations; managing threat intelligence to anticipate emerging threats; partnering with external pentesting firms; performing security reviews of new systems and integrations; collaborating with Engineering, IT, and Product teams on vulnerability remediation; developing playbooks and standards for offensive security testing and incident response; and monitoring security alerts and incidents. The ideal candidate has 5+ years in security engineering, red team, or threat management roles with hands-on experience in penetration testing, security testing, threat intelligence, and incident response. Required skills include proficiency with security testing tools (Burp Suite, Metasploit, Nmap, Cobalt Strike), demonstrated ability to leverage AI and automation for threat detection and response, understanding of common attack techniques and MITRE ATT&CK framework, experience with SIEM/EDR platforms, cloud security (GCP, AWS), and industry frameworks (OWASP, NIST, SOC 2/ISO 27001). The role requires autonomous work, project leadership, strong stakeholder communication, and the ability to explain technical findings to both technical and non-technical audiences. Startup experience is a plus. Valon has offices in New York City and San Francisco with full remote work support.

Similar roles