
Software Engineer, Security
Job description
Software Engineer, Security at Slash Financial.
About the role
Slash is building the future of business banking, one industry at a time. We believe businesses deserve financial infrastructure tailored to how they actually operate. That's why we're creating a new category of business banking. We combine the reliability of traditional banking (high yields, competitive rewards, and comprehensive security) with industry-specific features that make businesses more efficient, more competitive, and more profitable. Started in 2021, Slash is one of the fastest growing fintechs in the world and we power over ten billion dollars a year in business purchasing across numerous industries. We recently raised a $100M Series C led by Ribbit Capital with participation from Khosla Ventures, Goodwater Capital, NEA, and Y Combinator, accelerating our expansion into new markets and products. Slash is headquartered in San Francisco, and has a strong in-person culture. You will own the security strategy and execution for our platform, identifying and closing gaps before they can be exploited. You will be the primary driver of our security program, making key architectural decisions that protect our systems and data. You will ensure that security scales with our rapid growth without becoming a bottleneck for product teams. You will take ownership of critical controls across the entire technology stack, from cloud infrastructure to application code. You will establish the standards and processes that allow engineers to build securely by default. You will act as the central point of contact for security inquiries and assurance efforts across the company. You will represent Slash in external discussions with partners, customers, and vendors on security matters.
Key facts
What you'll do
- Own Slash's security program end-to-end, discovering systemic gaps and driving independent, high-impact remediation.
- Architect and manage network security for our Cloudflare implementation, AWS WAF rules, VPC networking, and overall infrastructure posture.
- Lead application security initiatives, shipping features such as passkey authentication and SMS rate limiting to harden product surfaces.
- Manage recurring penetration tests and our bug bounty program, coordinating remediation efforts across engineering teams.
- Partner with cross-functional groups to advance compliance efforts for PCI and SOC 2 frameworks.
- Define and deploy security patterns, tooling, and guardrails that empower the broader engineering team to move quickly and safely.
- Secure corporate IT infrastructure, ensuring endpoints and company devices remain resilient against evolving threats.
- Serve as the trusted security advisor to customers, internal stakeholders, and key vendors, providing clarity on our security practices.
- Prioritize security risks based on business impact, regulatory requirements, and threat intelligence signals.
- Design and implement scalable security controls that integrate seamlessly into CI/CD and deployment workflows.
- Monitor security metrics and key indicators, escalating anomalies and driving rapid response procedures.
- Collaborate with product and infrastructure teams to embed security into roadmaps from inception to launch.
- Evaluate emerging threats and technologies, translating findings into actionable security enhancements.
- Document security policies, incident response procedures, and architectural decisions for audit and operational continuity.
Requirements
- You are a security generalist with broad knowledge spanning infrastructure, cloud, and application security domains.
- You can think through, understand, reason about, and work on systems like Kubernetes/EKS, CockroachDB, Kafka, Terraform/Pulumi, and AWS.
- You are organized enough to coordinate pen tests, audits, and competing security priorities across multiple teams.
- You possess proficiency in TypeScript or another object-oriented language, enabling you to review code and design secure implementations.
- You can independently identify security gaps and drive high-impact changes without needing constant direction.
- You have a strong sense of ownership and are comfortable making decisions that balance security with delivery velocity.
- You are capable of working within a fast-paced, high-growth environment where responsibilities evolve quickly.
- You communicate clearly and professionally with both technical and non-technical audiences, including executives and external partners.
Nice to have
Only items explicitly indicated as preferred by the source are included; no additional preferences are added.
Practical notes
Working hours are full_time during standard business hours. Travel is not required for this role. This position is open to candidates who are authorized to work in the United States, and sponsorship is not indicated in the source information. The role is based in the San Francisco office with an expectation of in-person collaboration.