Remote
Staff Security Engineer
About this role
At Beyond Finance, we've made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care, a culture focused on compliance and ethics, supportive user-centric technology, and customized financial solutions, we've helped over 1 million clients on their path to a brighter future. While we're proud of what we've already accomplished, we're searching for new collaborators to help us get to the next level! If you're looking to join a forward-thinking, rapidly growing organization with helping people as its number one goal, we want to hear from you.
Role Overview As a Staff Security Engineer, you'll get involved early with Product and Software Engineering teams to embed security into our architecture and processes as they design, build, and ship. You'll also be someone the Security team can pull into any project, at any phase and regardless of domain, to make sure it lands on the right security outcome. This is a hands-on role, and you don't need to be an expert in all three areas: application security, cloud security, and security automation and tooling.
You should have strong, demonstrated depth in one of the three, along with enough working knowledge of the other two to contribute without hand-holding and to be a trusted voice on technical decisions outside the systems you personally own. What You'll Do Partner with Engineering, DevOps, and Product across projects, providing security input at any phase of design or build, regardless of domain. Guide secure design and code review for web and mobile applications, and help manage core AppSec tooling (SAST, SCA, secret scanning, DAST, ASM, and mobile security tooling).
Help triage and remediate application-level vulnerabilities with engineering teams. Contribute to cloud security posture across the AWS environment, including IAM, network segmentation, container security, secrets, and data exposure, using CNAPP and AWS-native tooling. Support cloud and application vulnerability management, and help tune WAF rules as needed. Build automation and internal tooling, primarily in Python, that reduces manual work for the security team.