Talent.com
Senior Security Engineer, Product Security

Senior Security Engineer, Product Security

EnboarderWashington, DC, United States
job_description.job_card.1_day_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Overview

Come build at the intersection of AI and fintech. At Ocrolus, we’re on a mission to help lenders automate workflows with confidence—streamlining how financial institutions evaluate borrowers and enabling faster, more accurate lending decisions.

Our AI-powered data and analytics platform is trusted at scale, processing nearly one million credit applications every month across small business, mortgage, and consumer lending. By integrating state-of-the-art open- and closed-source AI models with our human-in-the-loop verification engine, Ocrolus captures data from financial documents with over 99% accuracy. Thanks to our advanced fraud detection and comprehensive cash flow and income analytics, our customers achieve greater efficiency in risk management, and provide expanded access to credit—ultimately creating a more inclusive financial system.

Trusted by more than 400 customers—including industry leaders like Better Mortgage, Brex, Enova, Nova Credit, PayPal, Plaid, SoFi, and Square—Ocrolus stands at the forefront of AI innovation in fintech. Join us, and help redefine how the world’s most innovative lenders do business.

Summary

Ocrolus is a fast-growing financial technology SaaS (Software-as-a-Service) organization. We are building a world-class security program to secure Ocrolus and our customers' data. We are looking for diverse security practitioners to help us design, build, and scale product security at Ocrolus. We value critical thinking, creativity, data-driven and intelligence-driven approaches, and offensive experience. Security is a collaborative process, where security is a partner to help achieve business goals securely. We believe in saying “yes and;” instead of “no” when recommending security objectives. We don’t believe in using fear or penalty for the enforcement of security policies and processes, and we will always provide evidence and justification for security controls.

What you’ll do

  • Work closely with the CISO to build the product security strategy, roadmap, and metrics to measure and monitor product security posture.
  • Conduct design and architecture reviews for Ocrolus products and infrastructure.
  • Perform code reviews and application security assessments, including AI / LLMs.
  • Engage with the development teams to conduct secure design reviews / threat modeling exercises.
  • Identify vulnerabilities / threats that could affect Ocrolus products through independent research and work with the developers on workarounds / mitigation plans.
  • Be the go-to person for developers in solving critical issues relating to secure product development.
  • Run penetration testing targeting critical data, services, and environments. Report underlying security issues and propose enhanced security protections.
  • Write and disseminate security guidelines for common security issues, remediation, and security technology baselines.
  • Collaborate with stakeholders to ensure secure deployment of AI systems by staying updated on AI security best practices and executing adversarial testing strategies.
  • Guide engineering teams on secure coding and testing principles / practices.
  • Be a role model for the team and provide a healthy platform for learning and growth. Build relationships with stakeholders throughout the engineering and product organizations.
  • Spread security culture throughout the organization.

What you’ll bring

  • A passion for identifying vulnerabilities and remediations.
  • Ability to interpret and explain multiple classes of vulnerabilities, such as cross-site scripting, SQL Injection, CSRF, cryptographic-related weakness, and code injection, to various audiences, such as development and management teams.
  • Experience in designing and building a wide variety of technical security controls.
  • Experience in performing threat modeling, design reviews, code reviews, web application security, and enterprise cloud penetration testing.
  • Stellar understanding of secure software development lifecycle (SDLC) and ability to integrate security practices and threat modeling into development processes.
  • Ability to automate product security processes and optimize productivity with SAST & DAST tools.
  • Good proficiency with a programming language (e.g., Java, Python, Go, Bash).
  • Good Knowledge of authentication, authorization, and access control mechanisms, cryptographic algorithms, and secure network communication protocols
  • Experience in cloud security architecture and infrastructure.
  • Self-driven with excellent communication and prioritization skills.
  • A total of 5+ years of experience in product security (code, web application, API)
  • Good to have

  • Published CVEs / articles on application security
  • Contributions to open-source security software
  • Certified in application security, pen testing (e.g., OSCP)
  • Life at Ocrolus

    We’re a team of builders, thinkers, and problem solvers who care deeply about our mission — and each other. As a fast-growing, remote-first company, we offer an environment where you can grow your skills, take ownership of your work, and make a meaningful impact.

    Note : The original content includes company values; this refinement preserves the intent and wording closely while converting formatting to allowed HTML.

    #J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Senior Security Engineer • Washington, DC, United States

    Job_description.internal_linking.related_jobs
    Senior Security Engineer

    Senior Security Engineer

    DirectViz Solutions, LLCRemote, VA, USA
    serp_jobs.filters.remote
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    DirectViz Solutions, (DVS) is a rapidly growing government contractor that provides strategic services that meet mission IT needs for government customers. DVS provides innovative information techno...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Security Engineer, Connected Warfare

    Senior Security Engineer, Connected Warfare

    Anduril IndustriesWashington, DC, United States
    serp_jobs.job_card.full_time
    Security Engineer, Connected Warfare.Anduril is a defense technology company transforming U.Lattice OS, AI, autonomy, computer vision, sensor fusion, and networking. About The Team : Anduril’s Missio...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Senior Security Engineer

    Senior Security Engineer

    NetImpact Strategies Inc.Bethesda, MD, United States
    serp_jobs.job_card.full_time
    Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.We are seeking a highly skilled Security Engineer to join our team, specializing in implementing secur...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Senior Security Engineer, Connected Warfare

    Senior Security Engineer, Connected Warfare

    Aduril IndustriesWashington, DC, United States
    serp_jobs.job_card.full_time
    Anduril Industries is a defense technology company with a mission to transform U.By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the def...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Security Engineer

    Security Engineer

    LeidosBethesda, MD, United States
    serp_jobs.job_card.full_time
    Leidos is seeking a Security Engineer to support the National Media Exploitation Center (NMEC).This role will be responsible for analyzing and assessing computer / network architecture security requi...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    StevenDouglasWashington, DC, United States
    serp_jobs.job_card.full_time
    Senior Security Engineer to design and deploy an advanced confidential computing environment.In this role, you will develop cryptographic frameworks, implement hardware attestation processes, and e...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Systems Security Engineer

    Senior Systems Security Engineer

    AnaVation LLCWashington, DC, United States
    serp_jobs.job_card.full_time
    Senior Systems Security Engineer.Be Challenged and Make a DifferenceIn a world of technology, people make the difference. We believe if we invest in great people, then great things will happen.At An...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Zero Trust Security Engineer - Senior

    Zero Trust Security Engineer - Senior

    DecisionPoint CorporationWashington, DC, United States
    serp_jobs.job_card.full_time
    The Government Publishing Office (GPO) SecDevOps program provides advanced security, development, and operations support to safeguard federal information systems and infrastructure.This initiative ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Electronic Systems Security Senior Engineer

    Electronic Systems Security Senior Engineer

    Versar Global SolutionsWashington, DC, United States
    serp_jobs.job_card.full_time
    Electronic Systems Security Senior Engineer.Be among the first 25 applicants.Versar Global Solutions provided pay range.This range is provided by Versar Global Solutions. Your actual pay will be bas...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Blue Team Security Engineer

    Blue Team Security Engineer

    HugoNetWashington, DC, United States
    serp_jobs.job_card.full_time
    SECURITY CLEARANCE REQUIREMENT : TS, WITH SCI ELIGIBILITY.REMOTE OPPORTUNITY : This position requires onsite work.However, due to COVID-19, remote work on a rotational schedule is temporarily availab...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Senior Security Engineer

    Senior Security Engineer

    St. George Tanaq CorporationWashington, DC, United States
    serp_jobs.job_card.full_time
    Tanaq Technical Services (TTS), a division of St.George Tanaq (SGT) Corporation, is an 8(a) Alaskan Native Small Business that specializes in delivering Enterprise Integrated Technology Solutions a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    Senior Security Engineer

    Senior Security Engineer

    TCG, Inc.Washington, DC, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    At TCG, we aim to prove that businesses can be good to their employees and responsible to their community while being profitable. We're an award-winning IT solutions provider to the Federal governme...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    Tanaq Technical ServicesWashington, DC, United States
    serp_jobs.job_card.full_time
    Tanaq Technical Services (TTS), a division of St.George Tanaq (SGT) Corporation, is an 8(a) Alaskan Native Small Business that specializes in delivering Enterprise Integrated Technology Solutions a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Security Engineer, Connected Warfare

    Senior Security Engineer, Connected Warfare

    SlopeWashington, DC, United States
    serp_jobs.job_card.full_time
    Anduril’s Mission Command group deploys world class products to bespoke environments to multiply warfighter efficacy and give decision makers informational power. Our products solve problems no one ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Cyber Security Engineer

    Senior Cyber Security Engineer

    hackajobWashington, DC, United States
    serp_jobs.job_card.full_time
    Senior Cyber Security Engineer role at hackajob, in collaboration with ManTech to connect them with exceptional tech professionals. The position is in the DC, Maryland, and Virginia (DMV) area.The r...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Security Engineer [17697]

    Senior Security Engineer [17697]

    ATR Arena Technical ResourcesFalls Church, VA, US
    serp_jobs.job_card.full_time
    Job Description Job Title : Sr Security Engineer (Managerial Role) Job Location : Falls Church, VA (Hybrid) Eligibility / Clearance : US Citizen or Green Card (Permanent Resident) with the ability to ob...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Security Engineer - 3632013

    Senior Security Engineer - 3632013

    EmergencyMDWashington, DC, United States
    serp_jobs.job_card.full_time
    At TCG, we aim to prove that businesses can be good to their employees and responsible to their community while being profitable. We're an award-winning IT solutions provider to the Federal governme...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Systems Security Engineer

    Senior Systems Security Engineer

    AnaVation, LLCWashington, DC, United States
    serp_jobs.job_card.full_time
    Be Challenged and Make a Difference.In a world of technology, people make the difference.We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched va...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day