SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 180,000 - 220,000 / annual
Odyssey partners with state agencies to design, launch, and operate Education Savings Account (ESA) and grant programs. The company operates across 6 states, powering programs serving 200,000+ students and over $1B in education funding. Recently launched the Texas EFA program, the largest day-one ESA launch in the country.
As Odyssey's first Security Engineer, you will own the company's security posture from the ground up. This is a high-impact, high-visibility role where your decisions directly influence how Odyssey protects customers, vendors, and employees.
Key responsibilities include:
- Collaborate with cross-functional teams to identify, assess, and remediate security risks across products and infrastructure
- Perform static and dynamic vulnerability assessments and drive remediation to completion
- Evaluate security risks in AI systems and data pipelines; leverage AI-assisted tooling for threat detection and vulnerability analysis
- Maintain and mature SOC 2 Type II compliance program
- Design and implement security controls across the full technology stack (application layer to cloud infrastructure)
- Translate complex security findings into actionable remediation steps for technical and non-technical stakeholders
- Continuously audit policies, controls, and procedures to stay ahead of evolving threats
- Embed security into developer workflows—CI/CD pipelines, code review processes, internal tooling—without compromising velocity
You bring 6+ years of software engineering experience with a focus on security, cloud security, DevOps, or network security. You have solid understanding of SOC 2, ISO 27001, and similar compliance frameworks with hands-on experience driving organizational adherence. You're experienced with SAST, DAST, and SCA tools across the SDLC, penetration testing methodologies, and AI-assisted security tooling. You have a strong track record managing security projects end-to-end within timelines and budgets.
The role is hybrid out of the NYC Tribeca office with the full team gathering once annually for an offsite. Candidates must be authorized to work in the US on a full-time basis.