Flex logo
Flex

Flex splits your bills into smaller, stress-free payments throughout the month. Start today with your rent bill!

Senior Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 201-500Since 2019H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

1 day ago

Salary

$132K - $195K / year

Seniority

Senior

Application SecurityThreat ModelingOWASP Top 10API SecurityAWSSASTDASTPenetration TestingIncident ResponseSDLCSecure CodingAuthenticationAuthorizationSOC 2PCI DSSNYDFSCode Review

Job Description

Flex is a growth-stage, NYC headquartered FinTech company that is creating the best rent payment experience. It’s hard to believe that it’s 2026 and paying rent on time is expensive, inflexible, and difficult. We’re here to change that! Flex enables our users to pay rent throughout the month on a schedule that better fits their finances and budget. Our mission is to empower as many renters as possible with flexibility over their most significant recurring expense. After deliberately keeping a stealth profile as we built up unprecedented investor support and an enthusiastic user base, we are looking for motivated individuals to help us keep our mission growing. Will you be a part of the team?

About the Role

Flex is looking for a Senior Security Engineer to support product security across our fintech platform. You'll be part of our product security focus on a lean, high-impact security team — partnering directly with product and engineering teams across Housing, Control Center, and Platform to ensure security is built in from design through deployment. This role reports to the Head of Security.

What You'll Do

- Own product security reviews end-to-end: threat modeling, security architecture review, and design consultation for new features and services
- Lead security design reviews for Flex's payment processing, account management, and partner integration platforms
- Drive the secure development lifecycle (SDLC) across engineering teams — shifting security left through tooling, process, and education
- Perform application security assessments, code review, and penetration testing for critical product surfaces
- Respond to and investigate complex security incidents; lead post-incident analysis and remediation
- Build security automation and tooling to scale product security reviews (AI-assisted review tools, SAST/DAST pipeline integration)
- Translate complex security concepts for cross-functional stakeholders and drive security adoption across product and engineering
- Contribute to security standards, frameworks, and architectural patterns that guide organization-wide practices

What You'll Bring

Must Have:

- 5+ years of experience in application security, product security, or security engineering
- Proven experience with threat modeling frameworks (STRIDE, DREAD, attack trees) applied to real production systems
- Strong application security skills: OWASP Top 10, API security, authentication/authorization design, secure coding practices
- Experience conducting security code reviews and penetration testing
- Proficiency with cloud security in AWS environments
- Strong understanding of compliance frameworks relevant to fintech (SOC 2, PCI DSS, NYDFS)
- Ability to own security projects from conception to completion with minimal oversight
- Excellent written and verbal communication — ability to translate security risk into business impact

Nice to Have:

- Experience in fintech, payments, or financial services
- Experience building or operating security automation tools (SAST/DAST, security review tooling)
- Security Champions program development experience
- Relevant certifications (OSCP, GWAPT, CISSP, or equivalent)
- Experience with bug bounty program management
- Familiarity with AI/ML security considerations (prompt injection, agent identity, credential isolation)

Why This Role

- Dedicated product security engineer — excellent opportunity to define how product security works at Flex
- Direct executive visibility: this role's work is a CTO/CRO priority
- Small team, outsized impact: 4-person security team supporting 100+ engineers
- Strong AI-forward culture: team has shipped AI-powered security review tools and embraces engineering tooling innovation
- Distributed team with async-first culture

Flex takes a market-based approach to pay, and compensation may vary depending on your primary work location. Work locations are categorized into one of three tiers based on a cost of labor index for that geographic area. The successful candidate’s starting pay will be commensurate with their experience, qualifications, and Flex’s internal leveling guidelines and benchmarks.
  • Tier A (NYC/SF): $156,000—$195,000 USD
  • Tier B: $140,400—$175,500 USD
  • Tier C: $132,600—$165,750 USD

#LI-Remote

Life at Flex:

We understand that it takes a diverse team of highly intelligent, curious, determined, empathetic, and self aware people to grow a successful company. Our HQ is located in New York City, but we have employees located throughout the US, Australia, Canada and South America. We are growing quickly, but deliberately, with a focus on building an inclusive culture. Our dynamic team has incredible perspectives to share, just as we know you do, and we take great pride in being an equal opportunity workplace.

We offer many employee benefits & perks. For full-time U.S based positions we offer:

  • Competitive medical, dental, and vision available from Day 1
  • Company equity
  • 401(k) plan with company match (our company match kicks off at the beginning of 2026)
  • Unlimited paid time off + 13 company paid holidays
  • Parental leave 
  • Flex Cares Program
  • Free Flex subscription

 For full time non-US employees, we offer

  • Competitive compensation + company equity
  • Unlimited PTO

Job Requirements

  • 5+ years of experience in application security, product security, or security engineering
  • Proven experience with threat modeling frameworks (STRIDE, DREAD, attack trees) applied to real production systems
  • Strong application security skills: OWASP Top 10, API security, authentication/authorization design, secure coding practices
  • Experience conducting security code reviews and penetration testing
  • Proficiency with cloud security in AWS environments
  • Strong understanding of compliance frameworks relevant to fintech (SOC 2, PCI DSS, NYDFS)
  • Ability to own security projects from conception to completion with minimal oversight
  • Excellent written and verbal communication — ability to translate security risk into business impact
  • Experience in fintech, payments, or financial services
  • Experience building or operating security automation tools (SAST/DAST, security review tooling)
  • Security Champions program development experience
  • Relevant certifications (OSCP, GWAPT, CISSP, or equivalent)
  • Experience with bug bounty program management
  • Familiarity with AI/ML security considerations (prompt injection, agent identity, credential isolation)

Benefits

  • Competitive medical, dental, and vision available from Day 1
  • Company equity
  • 401(k) plan with company match (our company match kicks off at the beginning of 2026)
  • Unlimited paid time off + 13 company paid holidays
  • Parental leave
  • Flex Cares Program
  • Free Flex subscription

Related Categories

Related Job Pages

More Security Engineer Jobs

Security Engineer1 day ago
Full TimeRemoteTeam 10,001+Since 1888H1B Sponsor

Cybersecurity Specialist managing security risks for Abbott's diabetes management technologies

AWSCloudCyber SecurityKubernetesLinux
United States
$78K - $156K / year
Tebra logo

Security Architect

Tebra

We empower independent practices to bring modernized care to patients everywhere.

Security Engineer1 day ago
Full TimeRemoteTeam 501-1,000H1B Sponsor

Security Architect designing security for hybrid and cloud environments at Tebra

BigQueryCloudCyber SecurityGoogle Cloud PlatformKubernetesPython
United States
$178.5K - $203.5K / year
Full TimeRemoteTeam 10,001+Since 2020H1B No Sponsor

Senior Manager overseeing security for Raytheon’s international operations

Massachusetts
$132.4K - $251.6K / year
Ping Identity logo

Manager, Sales Engineering

Ping Identity

Identity Security for the Global Enterprise

Security Engineer1 day ago
Full TimeRemoteTeam 1,001-5,000Since 2002H1B No Sponsor

The role involves interacting professionally with top-tier customers to identify and resolve technical issues, taking end-to-end ownership of assigned problems from initial troubleshooting to root cause resolution. Responsibilities also include regular communication via online tools, audio, and video calls, and collaborating cross-functionally with Support, Engineering, and Product Management teams.

REST APISSL/TLSIPv4JSONLDAPProxiesLinuxVirtualizationAWSAzureGoogle Cloud PlatformDockerKubernetesIdentity Access Management
United States