Senior Security Engineer at Loancrate
Los Angeles, California, United States -
Full Time


Start Date

Immediate

Expiry Date

30 May, 26

Salary

300000.0

Posted On

01 Mar, 26

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Application Security, Infrastructure Security, Compliance, Cloud Security, AWS, IAM, Secrets Management, Threat Modeling, CI/CD Integration, SAST, Dependency Scanning, SOC 2 Type II, Incident Response, Secure SDLC, Terraform, Pulumi

Industry

Software Development

Description
What is Loancrate? We started Loancrate to make home-buying simpler and less expensive for lenders and borrowers (us!). Today, mortgage lenders are stuck running their companies on software products built 20 years ago. These products are slow, unstable, and don't lead to material improvements in efficiency. When using these systems, the average human cost to originate a loan is still over $11,000. Loancrate builds AI-native tooling to automate mortgage workflows. Our ultimate goal is fully automated origination, which has the potential to save lenders over $16B in operating expense per year. Since starting in 2020, our remote team has enabled our customers to power >$85 billion in new home loans. We are a group of people excited to tackle the complexity of the home-lending industry. We care about collaboration, very open communication covering the good & the bad so that we learn from our decisions quickly, and ultimately having fun while we’re building. You’ll fit in well if you like diving deep quickly! The Opportunity Our dreams are big and we have much to build! We’re looking for a Senior Security Engineer who makes Loancrate more secure - without making it harder to build here. You’ll build systems, guardrails, and tooling that catch issues early, make secure defaults easy, and help engineers move fast and sleep at night. We handle some of the most sensitive personal and financial data in the country, and we take that responsibility seriously - security is an enabler here, not a gatekeeper. This is an IC role with broad scope - you’ll work across application security, infrastructure security, compliance, and internal tooling. If you’ve been in fintech or another regulated industry and gotten frustrated watching security slow engineering down, this is your chance to do it differently. You’ll write code, ship tooling, and improve our defaults - not just write policies. What To Expect As a Senior Security Engineer at Loancrate, you’ll get into the codebase and infrastructure quickly. Within your first month, you’ll be contributing to work such as... Conducting a comprehensive threat model of our application and infrastructure layers, identifying the highest-leverage gaps and building a pragmatic remediation roadmap. Hardening our AWS infrastructure - IAM least-privilege, secrets management, network segmentation, CloudTrail audit coverage, and GuardDuty alerting - while keeping developer workflows frictionless. Integrating security tooling into our CI/CD pipeline: SAST, dependency scanning, container image scanning, and secret detection that catches issues before they ship. Partnering with engineering on our SOC 2 Type II posture - working across evidence collection, control design, and vendor risk so that compliance is a byproduct of doing good security, not a separate workstream. Building secure-by-default patterns and libraries (authn/authz helpers, input validation, secure logging/redaction) so teams don’t have to reinvent security per service. Core Responsibilities Lead and drive Loancrate’s security posture across application security, cloud security, identity, and compliance - partnering closely with engineering and leadership. Perform regular threat modeling, vulnerability assessments, and penetration testing - and work directly with engineering to remediate findings fast. Build and maintain security tooling and automation: SAST/DAST, dependency scanning, container scanning, SBOM management, and secret detection integrated into CI/CD. Harden our AWS environment: IAM, VPC boundaries, secrets management (AWS Secrets Manager), audit logging, GuardDuty, Security Hub, KMS key management, and DDoS protection. Own our SOC 2 Type II program - design practical controls, automate evidence collection where possible, manage the auditor relationship, and drive continuous improvement. Lead or coordinate incident response for security events - runbooks, postmortems, and clear communication to customers and leadership when needed. Establish and maintain a secure SDLC - lightweight design reviews, threat modeling in planning, and developer enablement (training, docs, examples) that scales. Maintain a risk register - tracking identified threats, ownership, and remediation status so nothing falls through the cracks. Partner with Operations on endpoint and device security: laptop hardening, MDM policy, hardware key rollout, and offboarding access revocation. Manage third-party and vendor security risk, including due diligence for new integrations and annual reviews of existing vendors. Own identity and access infrastructure: SSO, MFA enforcement (including hardware key policies), SCIM provisioning, and access reviews. Contribute to security documentation, internal runbooks, and team education - you make the secure path the easy path. Tech Stack Our infrastructure runs on AWS and is managed 100% with Terraform and Pulumi Cloud. Application services run in Docker on ECS EC2 or Fargate. Key services include Aurora PostgreSQL, ElastiCache (Redis), MSK (Kafka), and OpenSearch. Our CI/CD runs on Buildkite with TypeScript pipeline-as-code. Observability is powered by Datadog, CloudWatch, and Sentry. DNS and CDN are handled by Cloudflare. Application code is a TypeScript monorepo running Node/Express with a React frontend and GraphQL/Apollo API layer. We use GitHub for source control. Preferred Skills and Background (It’s okay not to have all of these things - these are just some skills we are excited about!) 🔒 Deep application security experience: threat modeling, OWASP Top 10 (and beyond), secure code review, SAST/DAST tooling, and working directly with engineers to fix what you find. ⚡ Strong AWS security experience across IAM, VPC, GuardDuty, Security Hub, CloudTrail, KMS, Secrets Manager, and WAF. 🏠 Terraform and/or Pulumi proficiency - you can read and contribute to infrastructure-as-code, and you understand the security implications of what you’re reviewing. 📋 Hands-on SOC 2 experience: you’ve designed controls, collected evidence, and managed an auditor relationship - not just checked boxes. 🚀 CI/CD security experience: integrating security tooling into developer pipelines in a way engineers actually appreciate. 🏦 Fintech or regulated industry experience - you understand the intersection of security, compliance, and data privacy in a lending or financial services context. 🤝 Collaborative mindset - you build relationships with engineering rather than operating as an external reviewer or blocker. You measure success by how secure the product is, not how many policies you’ve issued. 🔑 Identity and access experience: SSO/SAML, SCIM, MFA enforcement, hardware security keys, and access review programs. 🛡️Familiarity with data security for sensitive personal and financial data - encryption at rest and in transit, data classification, and minimization. 📝 Strong written communication - you document decisions, write clear runbooks, and communicate security risks to non-security audiences without FUD. 🧮 Scripting and automation chops (Python, Bash, or similar) - you build tools to make security scalable, not just write policies. Loancrate is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other legally protected characteristic.
Responsibilities
The Senior Security Engineer will lead and drive Loancrate’s security posture across application security, cloud security, identity, and compliance, partnering closely with engineering and leadership. Key duties include performing threat modeling, building and maintaining security tooling integrated into CI/CD, hardening the AWS environment, and owning the SOC 2 Type II program.
Loading...