Greenlight

Greenlight

Greenlight is a financial technology company offering a debit card and money app for families, empowering parents to raise financially smart kids through smart spending and investing.

Capital Markets
251-1K
Founded 2014
$556M raised

Description

  • Lead security architecture and design reviews and threat modeling sessions with product and engineering teams.
  • Translate identified threats into prioritized engineering remediations based on risk and severity.
  • Conduct hands-on penetration testing and security assessments across the full product stack.
  • Red-team AI-powered products and development tools to identify prompt injection, data exfiltration, MCP exploitation, and tool misuse.
  • Drive PSIRT operations, including vulnerability triage, technical investigation, severity scoring, and coordinated disclosure.
  • Manage zero-day findings and work with engineering to patch or mitigate issues using compensating controls.
  • Define and enforce security guardrails for AI-assisted development environments and enterprise policies for AI tools.
  • Partner with architects, product managers, engineers, legal, compliance, and executives on security and compliance decisions.
  • Mentor junior security engineers and help build a strong security culture through training and evangelism.
  • Collaborate with the AI team to secure machine learning pipelines and related workflows.

Requirements

  • 10+ years of product security experience across application security, cloud security, and secure SDLC.
  • Full SDLC experience from design through development, deployment, and incident response.
  • Expert-level threat modeling experience using STRIDE, PASTA, or equivalent methodologies.
  • Hands-on penetration testing experience across applications, APIs, cloud infrastructure, and hardware/firmware.
  • Published research, CVE discoveries, bug bounty results, or red-team engagement experience is preferred.
  • PSIRT operational experience with vulnerability intake, triage, CVE, CVSS, and FIRST PSIRT frameworks.
  • Deep AI security expertise, including OWASP Top 10 for LLMs, APIs, web, and mobile, plus practical MITRE experience.
  • Strong hands-on experience with SAST, DAST, SCA, and securing AI development tools such as Claude and Cursor.
  • Experience defining enterprise guardrails for MCP security, AI-generated code, secrets scanning, and DLP for outbound AI traffic.
  • Strong programming ability to review code, build security tools, and automate workflows.
  • Deep technical knowledge of CI/CD pipelines for web and mobile applications.
  • Experience with Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI, AWS, GCP, Kubernetes, Ambassador, Helm, MySQL, DynamoDB, and Redis.
  • Ability to influence without authority, mentor without managing, and communicate complex risks to technical and non-technical stakeholders.
  • Hardware and embedded security experience, including secure boot, firmware integrity, hardware root of trust, and IoT threat modeling, is preferred.
  • Financial industry experience and knowledge of PCI DSS or COPPA are preferred.

Benefits

  • Medical, dental, vision, and HSA match.
  • Paid life insurance, AD&D, and disability benefits.
  • Traditional 401(k) with company match.
  • Unlimited PTO.
  • Paid company holidays and pop-up bonus holidays.
  • Professional development stipends.
  • Mental health resources.
  • 1:1 financial planners.
  • Fertility healthcare.
  • 100% paid parental and caregiving leave, plus cleaning service and meals during leave.
  • Flexible work-from-home options with both remote and in-office opportunities.
  • Fully stocked kitchen, catered lunches, and occasional in-office happy hours.
  • Employee resource groups.
  • Competitive compensation with market-based pay.
  • Discretionary performance bonus and equity rewards.
  • Estimated base pay range: $165,000-$200,000 in NY/CA/WA and $165,000-$185,000 in CO.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Application Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is seeking an Application Security Engineer to triage and validate vulnerability submissions across client bug bounty programs, communicate with researchers and customers, and escalate critical security incidents.

Burp Suite Nmap
2 hours, 46 minutes ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is seeking a Senior Product Security Engineer to secure its AI-native market intelligence platform by embedding AI/ML security, secure architecture, and assurance practices throughout product development.

CI/CD DevSecOps Java JavaScript Kubernetes OpenID Connect Python SAML Secrets Management TLS
3 hours, 31 minutes ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is seeking a Senior Product Security Engineer to secure its AI-native platform by embedding AI, application, cloud, and customer assurance controls throughout the product lifecycle.

CI/CD DevSecOps Encryption Java JavaScript Kubernetes OpenID Connect Python SAML Secrets Management TLS
3 hours, 46 minutes ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is seeking a Senior Product Security Engineer to secure its AI-native market intelligence platform by embedding AI, application, cloud, and customer assurance security throughout the product lifecycle.

CI/CD DevSecOps Encryption Java JavaScript Kubernetes OpenID Connect Python SAML Secrets Management TLS
3 hours, 46 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers