About the role
What will you do at bareinsights?
About the Role
This is a founding security engineering role at a fast-moving fintech startup, giving you end-to-end ownership of infrastructure, application, and identity security across the organization. You'll set the security posture from the ground up — building programs that make the secure path the easy path, not a bottleneck — at a company where security is central to earning client and partner trust.
What You'll Do
- Own infrastructure security across the full AWS environment, including VPC/VPN peering, network segmentation, IAM, and secrets management.
- Lead application security for web and desktop clients, embedding threat modeling, supply-chain controls, and secure code review into the development lifecycle.
- Design and implement identity and access controls (SSO, RBAC, least-privilege) for both human users and AI/agent systems.
- Build audit trails and access controls that make autonomous agent activity fully reconstructable — what happened, on whose behalf, with what data, and why.
- Partner with the IT managed service provider to secure endpoints, devices, and access for the in-office team.
- Stand up and run compliance, auditability, bug bounty, VDP, and pentest programs that demonstrate security posture to clients, partners, and auditors.
What We're Looking For
- 3+ years of hands-on security engineering or infrastructure security experience, with a strong track record in AWS (VPC, IAM, secrets management, network segmentation).
- Practical application security experience: threat modeling, dependency/supply-chain controls, and secure code review.
- Prior experience as a first or sole security hire at a startup, building programs from scratch with high autonomy.
- Identity and access management implementation across both human and non-human (e.g. service, agent) actors.
- Endpoint security and device management experience in an IT security context.
- Compliance and auditability program experience (SOC 2, vulnerability management, pentest coordination).
- Comfort operating in fast-moving environments with broad ownership and minimal established process.
- Familiarity with Kubernetes is a plus.
- Background in financial services or other regulated industries is a plus.
- Experience securing AI or autonomous agent systems is a plus.
Compensation
& Benefits
Base salary: $150,000 – $250,000 USD annually. Visa sponsorship is not available for this role.
Location
On-site in Los Angeles, CA. Candidates based in New York City, NY or San Francisco, CA may also be considered.
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
Cloud Security Engineer
Morgan & Morgan, P.A. · Tampa, Florida, United States
Salesforce Security Engineer
SDC · McLean, Virginia, United States
Senior Security Engineer
Credit Sesame · Mountain View, California, United States
IT & Security Engineer
Albedo · Broomfield, Colorado, United States
ML Security Engineer
Bright Vision Technologies · Kirkland, Washington, United States
Lead Engineer, Information Security (Application Security)
RXO, Inc. · United States
Role information can change. Confirm current details on the original application page.
