Prelim Logo

Prelim

Lead Security Engineer

Posted Yesterday
Remote
Hiring Remotely in US
240K-260K Annually
Senior level
Remote
Hiring Remotely in US
240K-260K Annually
Senior level
Lead Prelim’s security program across secure SDLC, application and cloud security, IAM, incident response, endpoint management, vendor risk, security reviews, and SOC 2 Type II compliance. Partner with DevOps and engineering, coordinate penetration testing, develop policies and risk roadmaps, manage audits and customer questionnaires, and improve detection and access controls. The role is the company’s first dedicated security hire and requires strong judgment, communication, and hands-on technical skills.
The summary above was generated by AI
About Prelim

Prelim builds digital account-opening infrastructure for community banks and credit unions. We've sustained over 100% ARR growth for four consecutive years on seed funding, and our platform sits in the critical path of how banks onboard their customers. When our system is down, a bank can't open accounts for its customers.

We're a small team. You'd be our first dedicated security hire and help define the security program for the next generation of banking.

What you'll own
  • Secure SDLC: dependency scanning, static analysis, security review of high-risk changes, and coordinating annual penetration tests. Teach engineers to catch issues before you have to.

  • Partner with DevOps on IAM, secrets management, network architecture, logging, and detection.

  • Policies, risk assessment, and roadmap. Decide what a company our size and risk profile actually needs, and defend that reasoning to auditors, bankers, and internally.

  • Own security questionnaires, vendor risk assessments, and customer security reviews. Banks conduct rigorous third-party risk management (often against FFIEC guidance).

  • Endpoint management, access reviews, phishing resistance, offboarding hygiene. The unglamorous stuff that questionnaires ask about first.

  • Own SOC 2 Type II end to end: control design, evidence collection, auditor management.

  • Owning incident responsne, from writing the plan, run the tabletops, and lead if it's ever real. Banks have breach-notification expectations in their contracts. You'll know them cold.

What we're looking for
  • 5+ years in security engineering, with breadth across appsec, cloud security, and compliance.

  • Hands-on: you can read code, write scripts, and configure cloud controls yourself

  • You've owned or heavily contributed to a SOC 2 audit (or ISO 27001 / equivalent)

  • Experience answering enterprise or financial-institution security reviews.

  • Strong written communication.

  • Judgment about proportionality: you know which risks matter at our scale and which controls are theater

Nice to have
  • Fintech or banking-vendor experience; familiarity with FFIEC, GLBA, or bank third-party risk management

  • Experience as a first or early security hire

  • Detection engineering / SIEM experience

  • Familiarity with core banking integrations or handling of PII/KYC data flows

About Prelim

Prelim is a San Francisco and New York City-based startup that operates with fully remote positions across the US, helping banks onboard their customers. Our platform is designed to streamline the account opening process for both consumers and businesses, accelerating speed-to-market and enhancing the customer experience for financial institutions. If you’re excited to help shape the future of the banking industry, we encourage you to apply and join our team at Prelim. We are seeking individuals who are driven, ambitious, and eager to make a real impact in a traditional industry ready for technological innovation.

We offer equity, a sponsored 401K, parental leave, and fully paid health, vision, and dental insurance. Additional benefits include unlimited PTO, a remote work stipend, a life-style stipend, and twice-yearly company retreats.

Prelim values diversity and inclusion; people of all backgrounds are welcome to join our mission to transform banking.

Similar Jobs

6 Days Ago
Remote or Hybrid
OH, USA
Senior level
Senior level
Financial Services
Lead cloud security architecture and threat hunting across enterprise cloud environments. Partner with engineering, product, and risk teams to embed secure-by-design controls, conduct threat models and risk assessments, review infrastructure-as-code, develop preventive and detective controls, and operationalize detections with cybersecurity teams. Analyze large datasets, improve alerting and incident-response playbooks, investigate cloud threats, and provide expertise on adversary tradecraft and emerging risks.
Top Skills: AWSAzureCloud Security Posture ManagementCloudFormationCrowdstrike FalconGCPInfrastructure-As-CodeKqlPrisma CloudSplunk SplSQLTerraformThreat ModelingWiz
28 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
140K-180K Annually
Senior level
140K-180K Annually
Senior level
AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Lead application security engineering across the SDLC using AI-assisted threat modeling, automated security testing, vulnerability prioritization, and secure-by-default controls. Partner with Engineering, Product, QA, DevOps, and AI platform teams to secure applications, APIs, cloud infrastructure, data, and AI/ML systems. Build security automation, CI/CD controls, policy-as-code guardrails, developer enablement, and proactive defenses against emerging threats such as prompt injection and data poisoning.
Top Skills: AIAi/MlAWSAzureBurp SuiteCi/CdContainer ScanningDastDjangoDockerFastapiGCPGithub Advanced SecurityIac ScanningInfrastructure-As-CodeJwtKubernetesNode.jsOauth2OidcOwasp ZapPolicy-As-CodeReactSastScaSemgrepSnykSonarqubeTrivy
Yesterday
Remote
USA
150K-180K Annually
Expert/Leader
150K-180K Annually
Expert/Leader
Healthtech
Leads OT network security engineering across manufacturing sites, translating enterprise architecture into segmentation, firewall, DMZ, access-control, and remote-access implementations. Coordinates production-sensitive cutovers with plant, IT, and safety teams while protecting manufacturing operations. Develops site-specific designs, compensating controls, implementation playbooks, and network documentation. Requires deep ICS expertise, knowledge of industrial protocols and security standards, and 10+ years of OT or industrial network security experience.
Top Skills: ArmisBacnetBmsCiscoClarotyDcsDmzDragosEthernet/IpFortinetHistorianHmiIcsIec 62443Industrial FirewallsIsa-99ModbusNist Sp 800-82Nozomi NetworksOpc-UaOtPalo AltoPlcProfinetScadaVlanZone-Based Access Controls

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account