Flex logo

Senior Software Engineer, Security (Remote)

Flex
Remote
Remote$170k–$230k· about 1 hour ago

Straight from Flex’s careers page. Apply on the company site — no recruiter, no middleman.

Explore more remote Software Engineer jobs — salaries, top companies, and the latest openings.See all →

Senior Software Engineer, Security

Team: Engineering

Location: Remote / USA

Commitment: Full-time

Workplace Type: remote

Flex is building the AI-native private bank for business owners.

We’re re-architecting the entire financial system for entrepreneurs—from the first dollar a business earns to how that value compounds, moves, and is ultimately spent in real life. Banking, credit, payments, personal finance, and financial operations—rebuilt from the ground up as a single, intelligent system. Flex is the full financial home for ambitious owners.

Since launching publicly in September 2023, Flex has scaled from zero to nine-figure annualized revenue, with a clear path to profitability by late 2026. We move fast, ship relentlessly, and operate with extreme ownership.

Our customers are affluent business owners ($3–$200M in revenue)—the backbone of the economy and one of the most underserved segments in finance. They’re stuck with outdated banks and fragmented tools. We’re replacing all of it. The opportunity is massive: a ~$1T+ revenue market hiding in plain sight. Our ambition is to build a $100B+ company by delivering a product that is fundamentally better—not incrementally improved.

Flex has raised $100M+ in equity and $300M+ in debt.

- Mission-critical problems: We build software that directly controls how money moves at scale.
- High bar, low ego: Small teams, exceptional people, real ownership.
- Speed over comfort: We prioritize execution, quality, clarity, and results.
- Enduring impact: What we’re building will define how a generation of owners runs their businesses.

Team & Locations

We hire exceptional people who want to build hard things and see their work matter immediately. Roles are available in: San Francisco, Miami, New York, and fully remote.

Flex Fuels Ambition.

About the Role

Were hiring our first security engineers. Both report directly to the CTO.

We want software engineers with security as their superpower, not security specialists who occasionally write code. The distinction matters here. At our size, the only way one person covers a surface this large is to build things that keep working after they move on. A findings queue you work through by hand grows faster than you can close it. A guardrail in the deployment pipeline doesnt.

The work is product and infrastructure security: making the paths that move money hard to attack, and making the secure way to build something also the easy way. The ledger and its write path, card issuing, payouts, and our stablecoin work are the systems that matter most. The job runs in both directions. Youll be in design review early on anything new, and youll be continuously assessing what weve already shipped, because most of Flexs risk lives in code that exists today. We dont expect you to read the codebase by hand or to keep a findings queue. We expect you to build the automation and repeatable checks that keep assessing it for you, and to spend the time you get back on the golden paths that stop whole classes of problem from arriving again.

Theres no security team above you and no CISO. Youd set the standard here, and own the risk decisions that come with it. Day to day, what gets fixed now, what gets mitigated, and what we knowingly accept is your call. The large ones come to the CTO, who you report to directly and wholl back you when the answer is no. Corporate security posture, endpoints, and identity sit with our IT and Corporate Engineering function, and those decisions are theirs to make.

At a company shipping this fast, a security engineer who blocks everything is worse than no security engineer. The answer isnt to wave things through. Its to understand the system, the business context, and the actual risk well enough to find the mitigation that keeps the velocity. Sometimes the answer is still no, and wed want that to come from a real read of the risk rather than a standard applied by default. Getting engineers to adopt something matters here as much as finding the problem in the first place. The version of this job that works has Security and Engineering solving the problem together.

Compensation: $170,000 - $230,000 a year, depending on experience, plus equity.

What Youll Do

  • Threat model the paths that move money: the ledger and write path, card issuing, payouts, and the stablecoin work. Do it inside design review on anything that touches money, continuously, not as a quarterly exercise.

  • Build secure-by-default infrastructure. Infrastructure as Code (IaC) guardrails, CI/CD supply chain integrity, secrets handling, service isolation, and workload IAM.

  • Build a just-in-time, least-privilege access system for cloud access that makes engineers faster while narrowing what any one credential can do.

  • Own application security across both new and existing systems. Continuously assess the highest-risk parts of what weve already shipped, and build automated checks and secure defaults into the development lifecycle so the same problems stop arriving. Code review on high-risk paths, dependency and SBOM hygiene, and static and dynamic analysis where it earns its keep. Eliminate whole vulnerability classes; leave the instance-by-instance work to the machines.

  • Build a golden path that keeps sensitive data out of logs, and the tooling that proves it stayed out.

  • Run our vulnerability disclosure program end to end, and grow it into a bug bounty when we can triage at that volume. Youd take this over from an engineering leader whos carrying it today.

  • Scope and manage external penetration tests, and drive the remediation afterwards. We buy offensive testing; you decide what to point it at.

  • Build security automation, including AI-assisted triage and review, so that two people can cover a surface that usually takes a larger team.

  • Partner with Engineering, IT and Corporate Engineering, Risk, and Compliance. Youll be technical input on partner security reviews and audits without owning the paperwork.

What Makes You a Great Fit

  • Youre a strong software engineer first. Youd be comfortable in our normal engineering interview loop.

  • You think like a builder and an attacker at the same time, and youd rather remove a class of vulnerability than file fifty tickets about it.

  • You care about developer experience. Youve shipped a security tool or control that engineers actually adopted, and you can explain why they adopted it.

  • You can tell a senior colleague that what they built isnt safe, explain why in plain language, and work alongside them to build a better alternative.

  • Youre comfortable owning problems end to end with limited guidance, and comfortable saying what you need rather than quietly absorbing it.

  • You make risk-based calls. You have strong opinions about secure defaults, you can tell a real risk from a theoretical one, and youre comfortable deciding something isnt worth fixing right now.

  • You know you wont personally touch every security problem here, and you dont want to. You build the defaults and the habits that let engineers make good security decisions without you in the room.

  • You can read a system diagram and find the trust boundary nobody drew.

  • You write clearly. Much of this job is convincing people in writing, across time zones.

What Were Looking For

  • Substantial hands-on experience building or securing systems in a fast-moving environment, including a stretch where you were the most senior person doing this work. We care about what youve built, not the year count.

  • Real software engineering ability in a language wed ship (Python, Go, TypeScript, or similar). Not scripting alone.

  • Hands-on cloud infrastructure experience: AWS or GCP, Terraform or equivalent IaC, containers, and CI/CD pipelines youve changed, not only used.

  • Practical threat modeling on systems with real consequences, and the judgment to know which findings matter.

  • Experience with secrets management, workload identity, and service-to-service authorization.

  • Experience handling inbound vulnerability reports, including at least one difficult reporter.

  • Clear written communication and a bias toward writing things down.

Strongly Preferred

  • A platform, infrastructure, or DevOps background where you moved toward security by choice. A great infrastructure engineer who wants to do this work will beat a traditional security hire who wants to write policy, every time.

  • Experience at a small company, or as a founder, where you were the only person who could do this and had to decide what to skip.

  • Experience running a VDP or bug bounty program, including the triage.

  • Fintech, payments, or another regulated environment, on the building side.

  • Experience applying AI or LLM tooling to security work in a way that held up in production.

  • Certifications like OSCP or OSWE are a signal well happily read, but they dont substitute for an engineering track record.

Why Join Us

Build something generational — Capture the full lifecycle of money for ambitious business owners.
Work on real money, real risk — Payments, credit, and banking at serious scale.
Solve hard problems — AI, underwriting, compliance, and global finance from first principles.
True ownership — Small teams, high trust, real accountability.
Founder-level exposure — Direct access to leadership, customers, and investors.
High bar, high taste — Move fast without cutting corners.
Elite peers — People here are builders, not tourists.
Real upside — Meaningful equity if you help build something big.
PlayStation logo

PlayStation

Staff Software Engineer, Data

Remote
San Mateo, CA$198k–$297k
✓ From careers page· about 1 hour ago
PlayStation logo

PlayStation

Senior Software Quality Engineer

Remote
San Mateo, CA$183k–$275k
✓ From careers page· about 1 hour ago
PlayStation logo

PlayStation

Lead Character Tools Engineer

Remote
$144k–$216k
✓ From careers page· about 1 hour ago
Carbon Direct logo

Carbon Direct

Staff Full Stack Engineer (Remote)

Remote
$184k–$225k
✓ From careers page· about 1 hour ago

Discover More than 100,000 Hidden Remote Jobs Before Everyone Else

Unlock All Remote Jobs Today

Simple pricing. Big savings on Quarterly and Yearly.

Monthly Access

$19/month
  • Instant access to fresh remote jobs from 500+ companies
  • New opportunities added hourly, often 3-7 days before anywhere else
  • Advanced filtering by role type, stack, pay, and location
  • Priority customer support
Start 7-day trial — $2.95
Most Popular

Yearly Access

$59/year
  • Everything in Monthly
  • Save $169 (~74%) vs paying monthly
  • Average job search takes ~6 months - get covered for the whole journey
  • Less than the cost of one lunch per month for competitive advantage
  • Equivalent to just ~$4.92/month
Start 7-day trial — $2.95