Flex→
Senior Security Engineer at Flex in Remote
InternshipRemoteRemote$156k–$195k/yr
Skills
application securityproduct securitysecurity engineeringthreat modeling frameworksowasp top 10api securityauthentication designauthorization designsecure coding practicessecurity code reviewpenetration testingcloud security - awscompliance frameworks - soc 2compliance frameworks - pci dsscompliance frameworks - nydfssecurity automation toolssastdastsecurity project management
Job Description
Summary: Flex is a growth-stage FinTech company based in NYC that aims to revolutionize the rent payment experience. They are seeking a Senior Security Engineer to support product security across their platform, ensuring security is integrated from design through deployment while collaborating with product and engineering teams.
Responsibilities:
- Own product security reviews end-to-end: threat modeling, security architecture review, and design consultation for new features and services
- Lead security design reviews for Flex's payment processing, account management, and partner integration platforms
- Drive the secure development lifecycle (SDLC) across engineering teams — shifting security left through tooling, process, and education
- Perform application security assessments, code review, and penetration testing for critical product surfaces
- Respond to and investigate complex security incidents; lead post-incident analysis and remediation
- Build security automation and tooling to scale product security reviews (AI-assisted review tools, SAST/DAST pipeline integration)
- Translate complex security concepts for cross-functional stakeholders and drive security adoption across product and engineering
- Contribute to security standards, frameworks, and architectural patterns that guide organization-wide practices
Required Qualifications:
- 5+ years of experience in application security, product security, or security engineering
- Proven experience with threat modeling frameworks (STRIDE, DREAD, attack trees) applied to real production systems
- Strong application security skills: OWASP Top 10, API security, authentication/authorization design, secure coding practices
- Experience conducting security code reviews and penetration testing
- Proficiency with cloud security in AWS environments
- Strong understanding of compliance frameworks relevant to fintech (SOC 2, PCI DSS, NYDFS)
- Ability to own security projects from conception to completion with minimal oversight
- Excellent written and verbal communication — ability to translate security risk into business impact
Preferred Qualifications:
- Experience in fintech, payments, or financial services
- Experience building or operating security automation tools (SAST/DAST, security review tooling)
- Security Champions program development experience
- Relevant certifications (OSCP, GWAPT, CISSP, or equivalent)
- Experience with bug bounty program management
- Familiarity with AI/ML security considerations (prompt injection, agent identity, credential isolation)
Required Skills: Application security, Product security, Security engineering, Threat modeling frameworks, OWASP Top 10, API security, Authentication design, Authorization design, Secure coding practices, Security code review, Penetration testing, Cloud security - AWS, Compliance frameworks - SOC 2, Compliance frameworks - PCI DSS, Compliance frameworks - NYDFS, Security automation tools, SAST, DAST, Security project management
Benefits: Competitive medical, dental, and vision, Company equity, 401(k) plan with company match, Unlimited paid time off + 13 company paid holidays, Parental leave, Flex Cares Program: Non-profit company match + pet adoption coverage, Free Flex subscription
Benefits
Competitive medical, dental, and vision
Company equity
401(k) plan with company match
Unlimited paid time off + 13 company paid holidays
Parental leave
Flex Cares Program: Non-profit company match + pet adoption coverage
Free Flex subscription