Startups

Lead Security Engineer

Prelim · Remote | US · Remote

← All jobs
About Prelim

Prelim helps financial institutions open accounts faster with digital onboarding, account maintenance, and 50+ banking integrations. Trusted by banks and credit unions. Backed by Y Combinator.

About the role

Secure SDLC: dependency scanning, static analysis, security review of high-risk changes, and coordinating annual penetration tests. Teach engineers to catch issues before you have to. Owning incident response, from writing the plan, to running the tabletops, and leading if it's ever real. Banks have breach-notification expectations in their contracts. You'll know them cold.

What they're looking for

  • 5+ years in security engineering, with breadth across appsec, cloud security, and compliance
  • Hands-on: you can read code, write scripts, and configure cloud controls yourself
  • You've owned or heavily contributed to a SOC 2 audit (or ISO 27001 / equivalent)
  • Experience answering enterprise or financial-institution security reviews
  • Strong written communication
  • Judgment about proportionality: you know which risks matter at our scale and which controls are theater
More about this role

Prelim builds digital account-opening infrastructure for community banks and credit unions. We've sustained over 100% ARR growth for four consecutive years on seed funding, and our platform sits in the critical path of how banks onboard their customers. When our system is down, a bank can't open accounts for its customers.

We're a small team. You'd be our first dedicated security hire and help define the security program for the next generation of banking.

Secure SDLC: dependency scanning, static analysis, security review of high-risk changes, and coordinating annual penetration tests. Teach engineers to catch issues before you have to.

Partner with DevOps on IAM, secrets management, network architecture, logging, and detection.

Policies, risk assessment, and roadmap. Decide what a company our size and risk profile actually needs, and defend that reasoning to auditors, bankers, and internally.

Own security questionnaires, vendor risk assessments, and customer security reviews. Banks conduct rigorous third-party risk management (often against FFIEC guidance).

Endpoint management, access reviews, phishing resistance, offboarding hygiene. The unglamorous stuff that questionnaires ask...

Read the full posting on Prelim's site ↗

Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.