Loancrate

We started Loancrate to make home-buying simpler and less expensive for lenders and borrowers. Today, mortgage lenders are stuck running their companies on software products built 20 years ago. These products are slow, unstable, and don't lead to material improvements in efficiency. When using these systems, the average human cost to originate a loan is still over $11,000. Loancrate builds AI-native tooling to automate mortgage workflows. Our ultimate goal is fully automated origination, which has the potential to save lenders over $16B in operating expense per year. Since starting in 2020, our remote team has enabled our customers to power >$85 billion in new home loans. We are a group of people excited to tackle the complexity of the home-lending industry. We care about collaboration, very open communication covering the good & the bad so that we learn from our decisions quickly, and ultimately having fun while we're building. You'll fit in well if you like diving deep quickly!

Senior Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

14 days ago

Salary

$0 - $300K / year

Bachelor Degree5 yrs expEnglishAWSCloudPythonSDLCTerraform

Job Description

• Lead and drive Loancrate’s security posture across application security, cloud security, identity, and compliance • Perform regular threat modeling, vulnerability assessments, and penetration testing • Build and maintain security tooling and automation: SAST/DAST, dependency scanning, container scanning, SBOM management, and secret detection • Harden our AWS environment: IAM, VPC boundaries, secrets management, audit logging, GuardDuty, Security Hub, KMS key management, and DDoS protection • Own our SOC 2 Type II program • Lead or coordinate incident response for security events • Establish and maintain a secure SDLC • Maintain a risk register • Partner with Operations on endpoint and device security • Manage third-party and vendor security risk • Own identity and access infrastructure • Contribute to security documentation, internal runbooks, and team education

Job Requirements

  • 5+ years of experience in security engineering or related field
  • Deep application security experience: threat modeling, OWASP Top 10 (and beyond), secure code review, SAST/DAST tooling
  • Strong AWS security experience across IAM, VPC, GuardDuty, Security Hub, CloudTrail, KMS, Secrets Manager, and WAF
  • Terraform and/or Pulumi proficiency
  • Hands-on SOC 2 experience
  • CI/CD security experience
  • Fintech or regulated industry experience
  • Collaborative mindset
  • Identity and access experience
  • Familiarity with data security for sensitive personal and financial data
  • Strong written communication
  • Scripting and automation skills (Python, Bash, or similar)

Benefits

  • Health insurance
  • Professional development opportunities

Related Categories

Related Job Pages

More Security Engineer Jobs

Lead Security DevOps Engineer

Zoom

Zoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars. We’re problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Find room to grow with opportunities to stretch your skills and advance your career in a collaborative, growth-focused environment.

Security Engineer15 days ago
Full TimeRemoteTeam 11,053Since 2013

As a DevOps Engineer, you will deploy and operate data center and cloud software infrastructure. This senior role within the Security DevOps team oversees critical production systems, including: Secrets management Deployment pipelines PKI Responsibilities include: Defining and im...

United States

Director - Product Security

LivaNova

Improving Quality of Life Through Innovation. Every Patient, Every Day

Security Engineer15 days ago
Full TimeRemoteTeam 1,001-5,000H1B Sponsor

As a global medtech company, we are driven by our Vision of changing the trajectory of lives for a new day and our Mission to create ingenious solutions that ignite patient turnarounds. Our relentless commitment to patients and strong legacy of innovation in healthcare are the fo...

United States

Legal Intern, Corporate Governance and Transactions

Circle

The all-in-one community platform for creators and brands. https://circle.so/

Security Engineer15 days ago
Full TimeRemoteTeam 51-200Since 2019H1B Sponsor

This role involves contributing to live, high-impact matters across Circle’s core growth areas, including: M&A and strategic transactions Corporate governance Capital markets initiatives Commercial transactions You will work closely with Circle’s Transactions and Corporate Govern...

United States
Full TimeRemote

Located in Boston’s historic Fenway area, Simmons University has a strong tradition of empowering women and challenging traditional gender roles. Simmons was founded for equality 125 years ago as one of the first higher education institutions dedicated to helping women become lea...

United States