Prelim Logo

Prelim

Lead Security Engineer

Posted Yesterday
Remote
Hiring Remotely in US
240K-260K Annually
Senior level
Remote
Hiring Remotely in US
240K-260K Annually
Senior level
Lead Prelim’s security program across secure SDLC, application and cloud security, IAM, incident response, endpoint management, vendor risk, security reviews, and SOC 2 Type II compliance. Partner with DevOps and engineering, coordinate penetration testing, develop policies and risk roadmaps, manage audits and customer questionnaires, and improve detection and access controls. The role is the company’s first dedicated security hire and requires strong judgment, communication, and hands-on technical skills.
The summary above was generated by AI
About Prelim

Prelim builds digital account-opening infrastructure for community banks and credit unions. We've sustained over 100% ARR growth for four consecutive years on seed funding, and our platform sits in the critical path of how banks onboard their customers. When our system is down, a bank can't open accounts for its customers.

We're a small team. You'd be our first dedicated security hire and help define the security program for the next generation of banking.

What you'll own
  • Secure SDLC: dependency scanning, static analysis, security review of high-risk changes, and coordinating annual penetration tests. Teach engineers to catch issues before you have to.

  • Partner with DevOps on IAM, secrets management, network architecture, logging, and detection.

  • Policies, risk assessment, and roadmap. Decide what a company our size and risk profile actually needs, and defend that reasoning to auditors, bankers, and internally.

  • Own security questionnaires, vendor risk assessments, and customer security reviews. Banks conduct rigorous third-party risk management (often against FFIEC guidance).

  • Endpoint management, access reviews, phishing resistance, offboarding hygiene. The unglamorous stuff that questionnaires ask about first.

  • Own SOC 2 Type II end to end: control design, evidence collection, auditor management.

  • Owning incident responsne, from writing the plan, run the tabletops, and lead if it's ever real. Banks have breach-notification expectations in their contracts. You'll know them cold.

What we're looking for
  • 5+ years in security engineering, with breadth across appsec, cloud security, and compliance.

  • Hands-on: you can read code, write scripts, and configure cloud controls yourself

  • You've owned or heavily contributed to a SOC 2 audit (or ISO 27001 / equivalent)

  • Experience answering enterprise or financial-institution security reviews.

  • Strong written communication.

  • Judgment about proportionality: you know which risks matter at our scale and which controls are theater

Nice to have
  • Fintech or banking-vendor experience; familiarity with FFIEC, GLBA, or bank third-party risk management

  • Experience as a first or early security hire

  • Detection engineering / SIEM experience

  • Familiarity with core banking integrations or handling of PII/KYC data flows

About Prelim

Prelim is a San Francisco and New York City-based startup that operates with fully remote positions across the US, helping banks onboard their customers. Our platform is designed to streamline the account opening process for both consumers and businesses, accelerating speed-to-market and enhancing the customer experience for financial institutions. If you’re excited to help shape the future of the banking industry, we encourage you to apply and join our team at Prelim. We are seeking individuals who are driven, ambitious, and eager to make a real impact in a traditional industry ready for technological innovation.

We offer equity, a sponsored 401K, parental leave, and fully paid health, vision, and dental insurance. Additional benefits include unlimited PTO, a remote work stipend, a life-style stipend, and twice-yearly company retreats.

Prelim values diversity and inclusion; people of all backgrounds are welcome to join our mission to transform banking.

Similar Jobs

6 Days Ago
Remote or Hybrid
OH, USA
Senior level
Senior level
Financial Services
Lead cloud security architecture and threat hunting across enterprise cloud environments. Partner with engineering, product, and risk teams to embed secure-by-design controls, conduct threat models and risk assessments, review infrastructure-as-code, develop preventive and detective controls, and operationalize detections with cybersecurity teams. Analyze large datasets, improve alerting and incident-response playbooks, investigate cloud threats, and provide expertise on adversary tradecraft and emerging risks.
Top Skills: AWSAzureCloud Security Posture ManagementCloudFormationCrowdstrike FalconGCPInfrastructure-As-CodeKqlPrisma CloudSplunk SplSQLTerraformThreat ModelingWiz
28 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
140K-180K Annually
Senior level
140K-180K Annually
Senior level
AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Lead application security engineering across the SDLC using AI-assisted threat modeling, automated security testing, vulnerability prioritization, and secure-by-default controls. Partner with Engineering, Product, QA, DevOps, and AI platform teams to secure applications, APIs, cloud infrastructure, data, and AI/ML systems. Build security automation, CI/CD controls, policy-as-code guardrails, developer enablement, and proactive defenses against emerging threats such as prompt injection and data poisoning.
Top Skills: AIAi/MlAWSAzureBurp SuiteCi/CdContainer ScanningDastDjangoDockerFastapiGCPGithub Advanced SecurityIac ScanningInfrastructure-As-CodeJwtKubernetesNode.jsOauth2OidcOwasp ZapPolicy-As-CodeReactSastScaSemgrepSnykSonarqubeTrivy
Yesterday
Remote
USA
150K-180K Annually
Expert/Leader
150K-180K Annually
Expert/Leader
Healthtech
Leads OT network security engineering across manufacturing sites, translating enterprise architecture into segmentation, firewall, DMZ, access-control, and remote-access implementations. Coordinates production-sensitive cutovers with plant, IT, and safety teams while protecting manufacturing operations. Develops site-specific designs, compensating controls, implementation playbooks, and network documentation. Requires deep ICS expertise, knowledge of industrial protocols and security standards, and 10+ years of OT or industrial network security experience.
Top Skills: ArmisBacnetBmsCiscoClarotyDcsDmzDragosEthernet/IpFortinetHistorianHmiIcsIec 62443Industrial FirewallsIsa-99ModbusNist Sp 800-82Nozomi NetworksOpc-UaOtPalo AltoPlcProfinetScadaVlanZone-Based Access Controls

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account