Talent.com
Lead Security Engineer
Lead Security EngineerPylon • Menlo Park, CA, United States
Lead Security Engineer

Lead Security Engineer

Pylon • Menlo Park, CA, United States
18 days ago
Job type
  • Full-time
Job description

At Pylon, we're a small team building a very ambitious product in the mortgage space.

We're in search of people who find difficult problems invigorating and who fit well into a high-performing team built on mutual respect and reliance. If you like pushing yourself to learn a massive amount while shipping code that has a huge impact on the end product, Pylon Engineering could be a great place for you.

About the Job

The Role

You'll be our first dedicated security engineer, taking ownership of security across our mortgage infrastructure platform. As a regulated financial institution handling sensitive borrower data, security is foundational to everything we build.

This means :

  • Hands-on security engineering : You'll write code. Lots of it. This isn't a policy or compliance role. You'll build security infrastructure, implement controls, and integrate security into our development workflow.
  • Technical leadership : You'll work directly with the CTO and engineering team to make security decisions that affect our architecture. You need to argue convincingly for security priorities while understanding the trade-offs.
  • End-to-end ownership : From application security to infrastructure hardening to incident response. You'll assess what needs attention, prioritize ruthlessly, and execute.
  • Building for scale : The security infrastructure you build needs to work today and scale as we grow. You'll set patterns that other engineers follow.
  • Embedded engineering : You're not a separate security team. You're an engineer who happens to specialize in security, working alongside the rest of engineering to ship secure systems.

What We're Looking For

Experience : 6-10+ years in security engineering at high-growth tech companies, with significant time at companies known for strong security cultures. You've built security programs.

Technical : Strong systems and application security background. You can read and write code fluently across multiple languages. You understand distributed systems, APIs, databases, and cloud infrastructure well enough to secure them properly.

Basics

  • Job title : Lead Security Engineer
  • Stock options : own a piece of the company and we all win together
  • Health insurance, 401K, dental, etc.
  • Our technology stack :

    We don't require that you've worked with any of these technologies before, this is just our stack for your information :

  • TypeScript / Node.js (NestJS)
  • PostgreSQL
  • AWS infrastructure
  • Web components (Lit), React
  • GraphQL APIs
  • About you

    You :

    Are dangerous with a keyboard. You write production code regularly. You can implement security controls, build tooling, automate checks, and integrate security into CI / CD. This is not a policy or architecture-only role.

    Think like an attacker and a builder. You can identify vulnerabilities and threat vectors, and you understand how to build systems that are secure by default. You know what actually reduces risk versus what just looks good.

    Can make the case. Security decisions often require trade-offs. You can articulate why something matters, what the actual risks are (not FUD), and convince engineers to do the right thing without being dogmatic.

    Prioritize ruthlessly. Not everything can be perfect on day one. You can assess risk, determine what's urgent versus what can wait, and focus effort where it matters most. Perfect is the enemy of shipped.

    Understand the domain deeply. You've worked in regulated industries or with sensitive data. You understand compliance requirements and know that passing an audit requires actual security.

    Build for engineers. Security controls that engineers route around are useless. You design systems that make the secure path the easy path. You understand developer experience matters.

    Have strong opinions that you're willing to defend. We have a culture of vigorous discussion and debate on technical decisions. We'll push you to defend your choices, and we want you to push back.

    Don't settle. Challenge yourself to frequently and consistently deliver exceptional work. If something could be more secure, take the initiative to improve it.

    Have great ideas, and lots of them. You should see opportunities all around you to make our systems more secure. We'll give you an environment where you can act on those ideas.

    Are self-motivated. You can take a goal and drive towards it without needing extensive hand-holding. The team is supportive and loves to share knowledge and advice, but there's no time for micromanaging your work.

    Are comfortable with ambiguity. There's a million ways to secure a system; you should feel at ease making a decision under uncertainty while balancing competing constraints.

    Are confident you can learn quickly. Mortgage is complex, our platform is complex, good security engineering is complex. You've got to have an attitude that you can absorb it, get on top of it, and build something better than what came before.

    Love strong typing. We're a team full of people who love Haskell and Rust (and Idris!) and take pride in pushing Typescript to its limits. Type safety is security.

    About the Team

    What we're not :

    A compliance checkbox :

  • We're not looking for someone to run audits and fill out questionnaires. We need someone building actual security.
  • If you think security means following frameworks without understanding why, Pylon will be frustrating for you.
  • A separate security organization :

  • You won't have a team of security analysts reporting to you. You'll be embedded with engineering, influencing how we build, not reviewing after the fact.
  • If you need organizational authority to get things done rather than technical credibility, this isn't the role.
  • An easy job :

  • We're building a lot of things from the ground up for the first time. Working at Pylon is like a research project where you have to ship to intelligent, opinionated customers regularly.
  • It's basically guaranteed you'll be handed a task that is too difficult for you to do. You might fail sometimes. You might have no idea where to start. Our team leans heavily on each other, but there's no getting around the difficulties.
  • What we are : A small team :

  • We don't have an army of engineers. If you find a security gap, you are probably the best one to fix it.
  • All the code we write has to punch above its weight in maintainability and toil reduction.
  • If you have a good idea, you have much more ability to put it into action than at a large company.
  • Working in a regulated space :

  • Mortgage is regulated both federally and at the state level.
  • We handle extremely sensitive financial data. Security failures have real consequences.
  • We move fast, but breaking things isn't an option.
  • About Pylon

    The $13 trillion mortgage industry at the core of the American economy runs on broken assembly lines with human-powered workflows, stitched-together software, and a series of capital markets intermediates. The costs to originate are at an all time high despite foundational shifts in foundational technology.

    Pylon is rewiring mortgages from the ground up. We are building the only API-first, programmatic infrastructure that fully automates credit, compliance, capital, and operations. For the first time, originators can build and scale mortgage businesses entirely through software, not people. Our team comes from Stripe, Better, and Affirm, and we are backed by Conversion Capital, QED, Citi, Fifth Wall, Peter Thiel, and the founders of Ramp, Mercury, Blend, and others.

    Create a job alert for this search

    Lead Security Engineer • Menlo Park, CA, United States

    Related jobs
    Security Engineer

    Security Engineer

    Figma • San Francisco, CA, United States
    Full-time
    Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all.Figma's platform helps teams bring ideas to life-whether you're brainstorming, creating ...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    Console Systems, Inc • San Francisco, CA, United States
    Full-time
    Console is an AI platform that automates IT and internal support.We help companies scale without scaling headcount, and give employees instant resolution to their issues. Our agents understand the f...Show more
    Last updated: 14 days ago • Promoted
    Security Engineer

    Security Engineer

    Mercor, Inc. • San Francisco, CA, United States
    Full-time
    Mercor is training models that predict how well someone will perform on a job better than a human can.We use our platform to source, vet, and onboard expert contractors who help train AI models in ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Qualified • San Francisco, CA, United States
    Full-time
    Qualified is the Agentic Marketing Platform for B2B companies.With Piper the AI SDR Agent, Qualified offers a whole new way to grow inbound pipeline. Piper operates across both the website and email...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    META • Menlo Park, CA, United States
    Full-time
    Meta), formerly known as Facebook Inc.When Facebook launched in 2004, it changed the way people connect.Apps and services like Messenger, Instagram, and WhatsApp further empowered billions around t...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Loft Orbital, Inc. • San Francisco, CA, United States
    Full-time
    Loft Orbital is revolutionizing access to space by building reliable, shareable satellites that drastically reduce the time and complexity traditionally required to get to orbit.We operate satellit...Show more
    Last updated: 27 days ago • Promoted
    Offensive Security Engineer

    Offensive Security Engineer

    Electronic Arts • Redwood City, CA, United States
    Full-time
    The EA Security team protects EA by reducing our exposure to security risks by raising awareness and providing a measured, proportionate set of security and risk management controls, services and s...Show more
    Last updated: 15 days ago • Promoted
    Security Engineer - Hybrid

    Security Engineer - Hybrid

    Workers' Compensation Insurance Rating Bureau of California • San Francisco, CA, United States
    Full-time
    For over a century, the Workers' Compensation Insurance Rating Bureau of California (WCIRB) has been California's trusted, objective provider of actuarially based information and research, advisory...Show more
    Last updated: 18 days ago • Promoted
    Senior Security Engineer, Detection and Response

    Senior Security Engineer, Detection and Response

    Grow Therapy • San Francisco, California, USA
    Full-time
    Grow Therapy is on a mission to serve as the trusted partner for therapists growing their practice and patients accessing high-quality care. Powered by technology we are a three-sided marketplace th...Show more
    Last updated: 17 days ago • Promoted
    Lead Security Engineer

    Lead Security Engineer

    Anyscale, Inc • San Francisco, CA, United States
    Full-time
    At Anyscale, we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We're commercializing Ray, a popular open-source project that'...Show more
    Last updated: 18 days ago • Promoted
    Enterprise Security Lead

    Enterprise Security Lead

    OpenAI • San Francisco, CA, United States
    Full-time
    OpenAI's Security organization supports the mission of deploying AGI for the benefit of all by ensuring the confidentiality, availability, and integrity of OpenAI's technology, people, and products...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    Magic AI Corp. • San Francisco, CA, United States
    Full-time
    Magic's mission is to build safe AGI that accelerates humanity's progress on the world's most important problems.We believe the most promising path to safe AGI lies in automating research and code ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    GoodLeap • San Francisco, CA, United States
    Full-time
    GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, w...Show more
    Last updated: 14 days ago • Promoted
    Security Engineer

    Security Engineer

    Mercor Inc • San Francisco, CA, United States
    Full-time
    Mercor is at the intersection of labor markets and AI research.We partner with leading AI labs and enterprises to provide the human intelligence essential to AI development.Our vast talent network ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Offensive Security Engineer

    Senior Offensive Security Engineer

    CHYM • San Francisco, CA, United States
    Full-time
    We are seeking a Senior Security Engineer to build and lead our Offensive Security program.In this role, you will attack Chime's services, applications, and infrastructure to discover security issu...Show more
    Last updated: 18 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Hayden AI • San Francisco, CA, United States
    Full-time
    At Hayden AI, we are on a mission to harness the power of computer vision to transform the way transit systems and other government agencies address real-world challenges.From bus lane and bus stop...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    Recruiting from Scratch • San Francisco, CA, United States
    Full-time
    Who is Recruiting from Scratch : .Recruiting from Scratch is a specialized talent firm dedicated to helping companies build exceptional teams. We partner closely with our clients to deeply understand ...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    Meta • Menlo Park, CA, United States
    Full-time
    Security EngineerSecurity Engineer Responsibilities • Build tools that enable connectivity to our infrastructure only from Meta owned and managed devices. Build machine attestation and secure certifi...Show more
    Last updated: 17 hours ago • Promoted • New!