layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
Thunes
San Francisco, California, United States
Source: Thunes careers · View original posting
From Thunes's posting. “We” and “our” refer to the employer.
Security Engineer Overview
Thunes Financial Services is hiring a Security Engineer to be the architect of trust for our fintech platform. We are looking for a hybrid specialist who can bridge the gap between Infrastructure Security and Application Security, ensuring our systems are as resilient as they are compliant. This role will play a critical part in maintaining our regulatory compliance posture while building automated, scalable security guardrails. This role reports to the VP of Engineering.
As a Security Engineer, you will be responsible for security across the full lifecycle of our fintech platform. This hybrid specialist role requires deep engagement with both infrastructure and application security, focusing heavily on automation and regulatory compliance within a high-stakes, regulated environment.
Design, build, and maintain automation to integrate security testing (SAST/DAST/SCA) directly into our deployment pipelines. You'll ensure that security is a "paved road" for developers, not a bottleneck.
Own security across the lifecycle—from securing our cloud infrastructure (AWS/GCP) to performing code reviews and architectural risk assessments.
Manage our detection stack using modern vulnerability scanning and dependency management tools to identify, prioritize, and track risks across the environment.
Build and maintain automated workflows for vulnerability reporting, triage, and remediation. We want someone who leverages AI-powered agentic coding tools or similar automation to eliminate manual toil and accelerate response times.
Monitor our technical security controls to ensure that they are operating effectively throughout the year to meet the rigorous cybersecurity compliance requirements to support regulatory exams as well as SOC-2 and PCI audits.
Serve as a key member of our security response team, helping to investigate and mitigate potential threats.
Product, data engineering, front-end engineering, tech ops, compliance, and legal
Cloud (AWS/GCP, K8s), CI/CD tools (GitHub Actions, GitLab CI, or Jenkins), Python, Go, or Bash, SAST/DAST/SCA, enterprise vulnerability management platforms, automated dependency scanning solutions.
Ensuring systems are resilient and compliant.
Maintaining our regulatory compliance posture.
Building automated, scalable security guardrails.
Having a direct impact on the security strategy.
Some travel required for periodic team offsites.
Knowledge Required
Hands-on experience building security guardrails within CI/CD tools (e.g., GitHub Actions, GitLab CI, or Jenkins).
Deep experience in both Infrastructure Security (Cloud/K8s) and AppSec (OWASP Top 10, Secure SDLC).
Proven proficiency with enterprise vulnerability management platforms and automated dependency scanning solutions.
You don’t just find bugs; you write code (Python, Go, or Bash) to handle them. Experience using AI-driven automation or agentic tools to streamline security workflows is required.
You understand the high-stakes nature of working in a regulated environment and can translate compliance requirements into technical reality.
Clear, effective communication of trade-offs to non-technical stakeholders
History of collaboration with engineers and others
Certifications such as CISSP
Prior experience in startups, especially Fintech
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: