Senior Security Engineer
Job description
About the role
You will establish a new baseline for security within the consumer finance sector, where trust has historically been in short supply and technical debt often undermines defensive controls. In this role, you will own the design and execution of a security architecture that protects both the consumer-facing touchpoints and the backend systems that serve as the foundation for regulated financial operations. You will operate at the intersection of privacy, compliance, and product velocity, ensuring that security decisions unblock engineering rather than stall delivery. You will translate ambiguous risk into clear, actionable strategy while maintaining a deep focus on data protection across distributed environments and regulated jurisdictions. Your work will directly influence whether large financial institutions choose to extend their business through our platform and whether consumers feel safe engaging with our products. You will build the foundational controls that allow us to scale to millions of users without sacrificing rigor or responsiveness. Ultimately, your contributions will turn security from a perceived cost center into a core driver of institutional trust and market differentiation.
Key facts
What you'll do
- Embed security into the product lifecycle by partnering with product managers and engineering teams to identify, evaluate, and mitigate risks before features reach production.
- Design and implement data classification, encryption, and access control schemes that meet the stringent requirements of bank-grade systems and financial regulators.
- Architect and maintain privacy-preserving data flows that ensure sensitive consumer information never leaves authorized boundaries while still enabling effective decisioning.
- Develop secure-by-default patterns and reusable components for Flask services, frontend applications, and database layers to accelerate safe development.
- Drive adoption of infrastructure-as-code and CI/CD security practices across engineering teams using Terraform, AWS, and Snowflake environments.
- Lead incident response efforts during security events, coordinating with stakeholders to contain impact, communicate transparently, and execute rigorous post-mortems.
- Build and maintain automated systems for SOC 2, PCI-DSS, and other financial compliance frameworks, reducing manual overhead and audit friction.
- Translate complex technical risks and trade-offs into clear business language that executives and partners can act upon without sacrificing technical integrity.
- Mentor engineers and influence a security-first culture that values speed, clarity, and accountability in equal measure.
- Continuously evaluate emerging threats and defensive technologies, ensuring that January's security posture remains ahead of evolving attacker tactics in the financial sector.
Requirements
You must bring a minimum of 6 years of professional experience in cybersecurity, with at least 3 years focused on application and data security within security engineering roles. You have hands-on experience building application-level security controls in cloud environments, specifically using AWS infrastructure, Terraform for infrastructure-as-code, and Snowflake for data workloads. You have a track record of implementing security measures that accelerate product velocity rather than create unnecessary friction for engineering teams. You possess deep technical knowledge in secure coding practices for languages such as Python and JavaScript, along with strong skills in infrastructure-as-code and CI/CD security pipelines. You are able to influence stakeholders through partnership and clear reasoning, making rapid decisions even when information is incomplete or ambiguous. You can translate technical trade-offs and constraints into language that business leaders and financial partners understand and respect. You are highly proficient in common scripting and programming languages, including Python, JavaScript, and Bash, and you prefer to automate repetitive tasks wherever possible. You have direct experience with compliance frameworks relevant to finance, such as SOC 2, PCI-DSS, and established bank security standards, and you prefer environments where these requirements are baked into delivery workflows.
Nice to have
Only pursue preferred qualifications when they align with the core needs of building trust at scale in heavily regulated markets.
Practical notes
This role operates full_time from our base in New York City. No specific hours, travel requirements, visa sponsorship details, or application deadlines are provided in this posting.