Thunes

Thunes

Security Engineer

San Francisco, California, United States

Sponsorship not specifiedDetected 22 days ago
PythonGoBashFull-Stack DevelopmentCode ReviewGitAWSGCPCloud PlatformsKubernetesCI/CDGitHub ActionsJenkinsData EngineeringCybersecurityIncident ResponseComplianceLeadershipCommunicationCollaboration

About the role

  • As a Security Engineer, you will be responsible for security across the full lifecycle of our fintech platform.
  • This hybrid specialist role requires deep engagement with both infrastructure and application security, focusing heavily on automation and regulatory compliance within a high-stakes, regulated environment.
  • You'll ensure that security is a "paved road" for developers, not a bottleneck.

Responsibilities

  • Building automated, scalable security guardrails.
  • Design, build, and maintain automation to integrate security testing (SAST/DAST/SCA) directly into our deployment pipelines.
  • Monitor our technical security controls to ensure that they are operating effectively throughout the year to meet the rigorous cybersecurity compliance requirements to support regulatory exams as well as SOC-2 and PCI audits.
  • CI/CD Security Integration: Design, build, and maintain automation to integrate security testing (SAST/DAST/SCA) directly into our deployment pipelines. You'll ensure that security is a "paved road" for developers, not a bottleneck.

Requirements

  • A Bachelor's degree in Computer Science or a related field, but similar professional experience is equally valued.
  • A proven track record of deep experience in both Infrastructure Security and Application Security is required.
  • Some travel required for periodic team offsites.
  • Proven proficiency with enterprise vulnerability management platforms and automated dependency scanning solutions.
  • Experience using AI-driven automation or agentic tools to streamline security workflows is required.

Skills

  • Hybrid Expertise: Deep experience in both Infrastructure Security (Cloud/K8s) and AppSec (OWASP Top 10, Secure SDLC).
  • Tooling Experience: Proven proficiency with enterprise vulnerability management platforms and automated dependency scanning solutions.
  • Automation Mindset: You don't just find bugs
  • Leadership and collaboration:
  • Clear, effective communication of trade-offs to non-technical stakeholders
  • History of collaboration with engineers and others
  • Nice to have but in no way required:
  • Certifications such as CISSP
  • Prior experience in startups, especially Fintech

Company info

  • Security Engineer Overview
  • Thunes Financial Services is hiring a Security Engineer to be the architect of trust for our fintech platform.
  • We are looking for a hybrid specialist who can bridge the gap between Infrastructure Security and Application Security, ensuring our systems are as resilient as they are compliant.
  • This role will play a critical part in maintaining our regulatory compliance posture while building automated, scalable security guardrails.
  • This role reports to the VP of Engineering.

This listing is sourced directly from Thunes's careers page and normalized into a canonical job model.