Security Engineer

Current · Brooklyn NY

Company

Current

Location

Brooklyn NY

Type

Full Time

Job Description

SECURITY ENGINEER

At Current, we’re on a mission to enable our members to create better financial outcomes for themselves. Headquartered in NYC, we’re a leading U.S. fintech and one of the fastest growing companies with over 3 million members. No matter your title, we’re a team that collaborates on building great products and making an impact together.

Security Engineers are the core members of the security team bringing various specialities to bear on securing Current’s infrastructure and code. As a member of Current’s security operations team, you will help protect application and network boundaries, keeping Current’s systems hardened against attacks and providing security services to protect highly sensitive data. 

Successful Security Engineers will thrive in high-stress environments and can think like both an attacker and defender, engage with and work with other Security Engineers, as well as collaborating with cross-functional teams across Current to provide guidance on security best practices.

RESPONSIBILITIES:

  • Ownership of efforts related to the securing of Current's SaaS infrastructure
  • Collaborate with Current’s IT operations and core engineering teams to assure required controls are in place and documented within the context of Current’s security standards
  • Provide subject matter expertise on architecture, authentication, and system security
  • Assess security tools and integrate tools as needed, particularly open-source tools
  • Identify, investigate, and mitigate information security risks with a focus on data protection and fraud exposures 
  • Design infrastructure and drive its implementation to protect Current’s networks and systems
  • Conduct security reviews of core corporate and production infrastructure
  • Drive enterprise focused security improvements to Current products and services
  • Build security tools and processes for critical infrastructure protection, monitoring and remediation

ABOUT YOU:

  • B.S. Computer Science or equivalent experience
  • 5+ years work experience in information systems security
  • Experience with information systems security standards and practices (NIST 800-53, PCI-DSS, HIPAA, etc.)
  • Conversant with system and application security risks, threats and vulnerabilities
  • Demonstrated experience in cloud security delivered within the context of customer facing roles, preferably GCP
  • Coding experience in one or more general purpose languages, preferably JAVA
  • Experience with attacks and mitigation methods, working in two or more of the following: 
    • Network protocols and secure network design
    • Common security libraries, security controls, and common security flaws that could apply to Current’s applications.
    • Discovery and patching SQLi, XSS, CSRF, SSRF, authentication and authorization flaws, and other web-based security vulnerabilities (OWASP Top 10 and beyond)
    • Common authentication technologies including OAuth, SAML, CAs, OTP/TOTP
    • Browser-based security controls such as CSP, HSTS, XFO
    • Standard web application security tools such as Arachni, Brakeman, and BurpSuite.
    • Operating system internals and hardening (e.g. Windows, Linux, OS X, Android)
    • Security assessments and penetration testing
    • Authentication and access control
    • Applied cryptography and security protocols
    • Security monitoring and intrusion detection
    • Incident response and forensics
    • Development of security tools, automation or frameworks

BENEFITS:

  • Base salary range of $160,000 to $230,000. Compensation is based on experience, technical skills, and qualifications which are assessed during the interview process. Total compensations includes equity(options) and comprehensive benefits detailed below:
    • 401(k) plan with company matching
    • Medical, Dental and Vision premiums covered at 100% for you and your dependents 
    • Commuter benefits 
    • Healthcare and Dependent care FSA benefit 
  • Discretionary performance bonus program 
  • Biannual performance reviews
  • Flexible time off and paid holidays 
  • Generous parental leave policy
  • Employee Assistance Programs focused on mental health 
  • Healthcare advocacy program for all employees 
  • Access to mental health apps 
  • Team building activities
  • Our modern Chelsea-based office with open floor plan, stocked kitchen, and catered lunches
Apply Now

Date Posted

12/20/2022

Views

5

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Software Engineer - Python - Vatic Investments

Views in the last 30 days - 7

Vatic Investments is looking for a Python Software Engineer to work on algorithmic trading systems The role requires expertise in C Python and Linux a...

View Details

Senior DevOps Engineer - 3Red Partners

Views in the last 30 days - 0

3Red Partners LLC is seeking a Senior DevOps Engineer to join their team The company offers competitive benefits excellent worklife balance and opport...

View Details

Senior Mobile Engineer - Viam

Views in the last 30 days - 13

Viam is a robotics platform that makes it easy to turn great ideas into productionready robots The company is looking for a Mobile Engineer to build c...

View Details

Software Engineer - Viam

Views in the last 30 days - 14

Viam is a robotics platform that makes it easy to turn great ideas into productionready robots It offers a modern architecture easy developer APIs clo...

View Details

Software Engineer, SDK/NetCode - Viam

Views in the last 30 days - 11

Viam is a robotics platform that makes it easy to turn great ideas into productionready robots The company is looking for engineers to build software ...

View Details

Sr. Manager/Associate Director, Program Management - Volastra Therapeutics

Views in the last 30 days - 11

Volastra Therapeutics is a biotechnology company dedicated to discovering and developing treatments for patients with cancer They have raised funding ...

View Details