Security Engineer
Job description
About the role
Coinflow is building the next-generation payment service provider that revolutionizes global financial infrastructure with stablecoins, AI-driven fraud prevention, and instant settlement. The Security Engineer will own the day-to-day defensive and offensive security posture of the company and be responsible for hardening our platforms against emerging threats. You will build the SecOps backbone and partner closely with engineering to keep our software development lifecycle fast, secure, and resilient. This role reports directly to the CTO and provides a direct line into every part of the engineering organization. You will be expected to become one of the first security engineers to build and evolve our practices using modern, AI-native tooling.
Key facts
What you'll do
Establish and operate our SIEM and SecOps dashboard to provide engineering, compliance, and leadership with a real-time view of alerts, anomalies, auth events, infrastructure changes, and audit-ready evidence.
Conduct continuous internal penetration testing against Coinflow services, APIs, infrastructure, and embedded SDKs, leveraging AI-native tools to scale coverage and efficiency.
Automate reconnaissance, fuzzing, code review, and exploit development using tools such as Claude Security and Claude Code to accelerate discovery and remediation.
Own the vulnerability lifecycle end-to-end, including CVE triage across our npm, cargo, and other ecosystems, and build automation to keep packages patched without breaking production.
Tune Dependabot, enforce lockfile hygiene, and implement gated auto-merge workflows for low-risk dependency upgrades to reduce technical debt and exposure.
Design and enforce secure-by-default patterns for new services, ensuring that security controls do not become a bottleneck for fast engineering execution.
Review threat models for high-risk changes and integrate SAST, DAST, and secret scanning into CI so that the secure path is also the fastest path for developers.
Partner with compliance to produce the evidence, controls, and monitoring artifacts required for PCI DSS, SOC 2, ISO 27001, and DORA audits without turning engineering into a paperwork shop.
Run proactive internal pentests and continuously hunt for weaknesses in our own stack before adversaries can find them.
Measure and drive remediation effectiveness through metrics such as mean-time-to-fix, closing the loop between detection, investigation, and resolution.
Requirements
You have 4+ years of hands-on experience in security engineering, product security, or DevSecOps, ideally within a fintech, payments company, or other highly regulated environment.
You possess strong offensive security skills and have broken real systems, demonstrating capability with web applications, APIs, cloud environments, and infrastructure pentesting.
You have production experience operating a SIEM such as Datadog, Splunk, Elastic, Panther, or similar, and you have built dashboards that deliver actionable insight to engineers and stakeholders.
You are fluent in TypeScript/Node and have enough comfort with Rust, Go, or Python to read our codebase, identify potential bugs, and write tooling that automates security at scale.
You understand vulnerability management at scale, including CVE triage, SCA tooling, and dependency upgrade automation, and you have tuned these workflows in a production setting.
You are comfortable working with AI-native security tooling such as Claude Code and Claude Security, or you show a genuine excitement to adopt these tools as daily drivers.
You have a bias for action and shipping; you prefer delivering a working v1 control today over waiting to perfect a v3 solution next quarter.
You are meticulous, inquisitive, and rigorous in your approach to detecting, analyzing, and remediating security risks across people, processes, and technology.
Nice to have
Experience contributing to open source security tooling or publishing meaningful research on vulnerabilities is preferred.
Familiarity with regulatory frameworks such as PCI DSS, SOC 2, ISO 27001, and DORA is preferred.
Background in high-throughput payment systems, marketplaces, or fintech infrastructure is preferred.
Practical notes
This is a full-time role based in Chicago, IL.
The compensation range provided reflects the base salary only and does not include equity or benefits, which are outlined separately.
No specific visa sponsorship or travel requirements are stated in this posting.
There are no published deadlines for applications in the provided source text.