SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Slash is a rapidly growing fintech company building industry-specific business banking infrastructure. Founded in 2021 and recently funded with $100M Series C, Slash powers over $10B annually in business purchasing and is headquartered in San Francisco with a strong in-person culture.
You will own and scale Slash's security program end-to-end as a senior security engineer. This is a high-autonomy role where you'll be responsible for keeping systems secure across the entire stack—from network and infrastructure to application-level security—while establishing patterns and guardrails that enable the broader engineering team to move quickly without security concerns.
Key responsibilities include:
- Owning the complete security program: identifying gaps, prioritizing initiatives, and driving changes independently
- Network security: managing and hardening Cloudflare, AWS WAF, VPC networking, and overall infrastructure posture
- Application security: shipping features like passkey authentication, SMS rate limiting, and product-level hardening
- Managing recurring penetration tests and bug bounty programs, coordinating remediation across engineering
- Supporting compliance efforts (PCI, SOC 2)
- Establishing security patterns, tooling, and guardrails for the engineering team
- Corporate IT security: maintaining company equipment and endpoint security
- Interfacing with customers, internal stakeholders, and vendors on security practices
You should be a security generalist with knowledge across the stack (infrastructure to application code). You'll need to understand and work with Kubernetes/EKS, CockroachDB, Kafka, Terraform/Pulumi, and AWS while spending 100% of your time focused on security improvements. Proficiency in TypeScript or another object-oriented language is required. You should be organized, able to coordinate complex security initiatives independently, and comfortable finding gaps and driving high-impact changes without direction.
Ideal candidates fit one of two profiles: current/recent founders in the security space, or engineers with 2–5 years of experience and rapid promotion to senior/staff level at companies with high security standards.