Backed by Bessemer and Insight.
About the role
Thunes Financial Services is hiring a Security Engineer to be the architect of trust for our fintech platform. We are looking for a hybrid specialist who can bridge the gap between Infrastructure Security and Application Security, ensuring our systems are as resilient as they are compliant. This role will play a critical part in maintaining our regulatory compliance posture while building automated, scalable security guardrails. This role reports to the VP of Engineering.
What they're looking for
- Pipeline Proficiency: Hands-on experience building security guardrails within CI/CD tools (e.g., GitHub Actions, GitLab CI, or Jenkins)
- Hybrid Expertise: Deep experience in both Infrastructure Security (Cloud/K8s) and AppSec (OWASP Top 10, Secure SDLC)
- Tooling Experience: Proven proficiency with enterprise vulnerability management platforms and automated dependency scanning solutions
- Automation Mindset: You don’t just find bugs, you write code (Python, Go, or Bash) to handle them. Experience using AI-driven automation or agentic tools to streamline security workflows is required
- Fintech Fluency: You understand the high-stakes nature of working in a regulated environment and can translate compliance requirements into technical reality
More about this role
Thunes Financial Services is hiring a Security Engineer to be the architect of trust for our fintech platform. We are looking for a hybrid specialist who can bridge the gap between Infrastructure Security and Application Security, ensuring our systems are as resilient as they are compliant. This role will play a critical part in maintaining our regulatory compliance posture while building automated, scalable security guardrails. This role reports to the VP of Engineering.
As a Security Engineer, you will be responsible for security across the full lifecycle of our fintech platform. This hybrid specialist role requires deep engagement with both infrastructure and application security, focusing heavily on automation and regulatory compliance within a high-stakes, regulated environment.
- CI/CD Security Integration: Design, build, and maintain automation to integrate security testing (SAST/DAST/SCA) directly into our deployment pipelines. You'll ensure that security is a "paved road" for developers, not a bottleneck.
- Full-Stack Security: Own security across the lifecycle—from securing our cloud infrastructure (AWS/GCP) to performing code reviews and architectural risk...
Browse similar: Startup jobs · San Francisco Bay Area