Cardless
Security Engineer - Product
San Francisco
Sponsorship not specified$190k-$260kDetected 28 days ago
PythonJavaCode ReviewAWSSparkDetection EngineeringIncident ResponseComplianceSupply ChainUnderwriting
About the role
- We power programs for Coinbase, Bilt, Qatar Airways, Alibaba, and others.
- We've raised $170M to date, most recently a $60M Series C led by Spark Capital.
- The role is hands-on and deeply cross-functional, working with Engineering, Risk, Compliance, Legal, and Data.
Responsibilities
- Own the security model for our partner-facing APIs: authentication, authorization, tenant isolation, abuse prevention, signing, and audit logging.
- Drive a coherent auth strategy across services and surfaces, including step-up auth for sensitive actions and a strong-auth roadmap (passkeys and beyond).
- Build the device telemetry, behavioral signals, and velocity primitives that fraud and risk functions depend on.
- Be the secure-by-design partner with Engineering - sit in on architecture reviews before features ship, write the threat models, own the tradeoffs.
- Own secure SDLC: SAST/DAST, dependency scanning, secret detection, and the security tooling engineers interact with daily.
- Lead incident response on security events (containment, forensics, comms, blameless postmortems) and drive vulnerability remediation across services.
- Own the relationship with our external security architecture partner: set priorities, scope engagements, integrate findings into our roadmap.
- Excellent written communication. You'll write threat models, postmortems, and partner-facing security responses.
- Cardless is the infrastructure that lets consumer brands put credit cards directly in their own product.
- The work spans authentication, authorization, anti-abuse controls, in-product fraud primitives, and the secure-by-design practices that come with running credit infrastructure for partners of this caliber.
Requirements
- Comfort with modern AI tooling (Claude, Copilot, and similar) as a daily force multiplier across code review, threat modeling, detection engineering, and security tooling.
Nice to have
- Fintech, payments, or other regulated environment experience.
- Experience operating a bug bounty or vulnerability disclosure program.
- The work moves real dollars and real trust from the moment you ship.
Skills
- Experience designing or operating secure platform / B2B APIs at scale, especially in multi-tenant environments.
- Background in anti-ATO, anti-fraud, or authentication systems at scale (consumer fintech, marketplace, or large consumer platform).
Compensation
- This role has an annual starting salary range of $190,000-$260,000 + equity + benefits (see above).
- Actual compensation is influenced by a wide array of factors including but not limited to skills, experience, and specific work location.
- San Francisco, CA - our office is in the Jackson Square district.
- This role is 5 days a week in office.
Benefits
- ๐ธ Meaningful start-up equity
- ๐ฅ 100% health, vision & dental primary coverage
- โ 75% health, vision & dental dependent coverage
- ๐ $250/month commuter benefit
- ๐ถ Parental leave
- ๐ด Flexible PTO with a minimum of 15 days off per year
- This role has an annual starting salary range of $190,000-$260,000 + equity + benefits (see above).
Company info
- Instead of sending customers off to a bank's website to manage their card, our platform handles the credit program end-to-end (applications, underwriting, servicing, rewards, compliance), so brands can build the card experience inside their own ecosystem.
- We're hiring a Product Security Lead to drive how we build security into the platform.
Apply directly at Cardless โCreate a free account for alerts like thisView Cardless immigration profile
This listing is sourced directly from Cardless's careers page and normalized into a canonical job model.