Founding Application Security Engineer

Posted Yesterday
Be an Early Applicant
New York, NY, USA
Hybrid
180K-220K Annually
Senior level
Edtech • Information Technology • Software
On a mission to empower families by helping states administer education savings accounts and microgrant programs.
The Role
Own Odyssey's application security posture: perform code reviews, run SAST/DAST/SCA and vulnerability assessments, embed security in CI/CD and cloud infrastructure, mature SOC 2 Type II compliance, use AI-assisted tooling, translate findings into actionable remediation, and lead security projects end-to-end.
Summary Generated by Built In

About Odyssey:

K-12 education is one of the most consequential determinants of a child’s future — and many families have had limited ability to shape how and where their child learns. Education Savings Account (ESA) programs are changing that. One of the fastest-growing public education initiatives in the U.S., they give states the ability to put education funding directly in the hands of families, who can then choose the learning experiences that best fit their child — from schools and tutors to therapy, curriculum, and technology.

But once these policies are signed into law, states face an enormous operational challenge. They must stand up entirely new programs, manage the secure and compliant flow of public funds, approve and monitor thousands of vendors, support families at scale, and prevent fraud — all while delivering a high-quality user experience.

That’s where Odyssey comes in.

We partner with state agencies to design, launch, and operate ESA and grant programs on their behalf. We provide the technology, program operations, vendor ecosystem, and family experience that make these programs actually work in the real world. Today, we operate across 6 states, and our platform powers programs serving 200,000+ students and over $1B in education funding — and we’re just getting started.

Most recently, we launched the Texas Education Savings Account (EFA) program — the biggest day-one ESA launch in the country — which has already received nearly 200,000 applications. It’s the kind of moment that captures exactly what we’re building toward: programs that work at scale, from day one, when it matters most.

We’re backed by respected investors, including a16z and Tusk Venture Partners, and we’re building the team that will take us to the next stage.

Odyssey sits at the intersection of GovTech, EdTech, and FinTech. We are a public-sector operator, a technology company, and a program delivery partner all at once. The work we do is civic infrastructure — it determines whether families can access life-changing educational opportunities.

Why This Work Is Different

We’re in the weeds with state partners, internally with our product teams, and turning ambiguous policy into real systems that families depend on. This means building a platform that meets each state’s configuration needs while being flexible enough to support all customers. We are not building be-spoke software!

If you want a highly structured environment, this will feel uncomfortable. If you want ownership, speed, and problems that actually matter, you’ll feel right at home.

About The Role

As Odyssey's Founding Application Security Engineer, you'll have full ownership of our security posture — shaping strategy, building programs from the ground up, and driving best practices across our entire technology stack and product suite. This is a high-impact, high-visibility role where your decisions will directly influence how we protect our customers, vendors, and employees.

 

You'll partner closely with cross-functional teams to embed security into everything we build and ship, champion solutions to emerging security challenges, and ensure we stay ahead of an evolving threat landscape. You're someone who embraces AI tools to work smarter — whether that's accelerating threat detection, streamlining vulnerability analysis, or improving how we respond to incidents.

 

What You’ll Do

  • Collaborate closely with cross-functional teams to proactively identify, assess, and remediate security risks across Odyssey's products and infrastructure, proposing enhanced controls and process improvements where needed

  • Conduct in-depth code reviews to detect vulnerabilities within the Odyssey application and code base

  • Perform static and dynamic vulnerability assessments and drive remediation efforts through to resolution

  • Evaluate security risks in AI systems and data pipelines, and leverage AI-assisted tooling to enhance threat detection, vulnerability analysis, and security operations

  • Maintain and mature Odyssey's SOC 2 Type II program, ensuring a secure environment for vendors, customers, end-users, and employees

  • Design and implement security controls across Odyssey's full technology stack — from application layer to cloud infrastructure

  • Translate complex security findings into clear, actionable remediation steps for both technical and non-technical stakeholders

  • Continuously audit policies, controls, and procedures to keep security practices ahead of an evolving threat landscape

  • Embed security seamlessly into the developer workflow — including CI/CD pipelines, code review processes, and internal tooling — without compromising velocity

 

About You

  • 6+ years of Software Engineering experience with a focus on application security, cloud security, DevOps, network security, or similar domains

  • Solid understanding of industry standards and compliance frameworks (SOC 2, ISO 27001, etc.) with hands-on experience driving organizational adherence

  • Experience applying AI-assisted tooling to accelerate threat detection, code review, and vulnerability analysis

  • Experience deploying and operating SAST, DAST, and SCA tools across the software development lifecycle

  • Strong track record managing security projects end-to-end — from planning through delivery — within timelines and budgets

  • Experience with penetration testing tools, techniques, and methodologies, with a clear understanding of common vulnerabilities and remediation strategies

 

Additional Details:

  • This role is available as hybrid out of our NYC office in Tribeca. The full team comes together once a year for an offsite.

  • Candidates will be asked to come in person for at least one of the interviews in the process.

  • Applicants must be currently authorized to work in the United States on a full-time basis.

  • We believe that everyone at Odyssey should be compensated fairly. We set our salary bands based on compensation data from hundreds of companies at our stage. The salary range for this role is $180,000 - $220,000 + generous equity depending on experience and location.

  • Odyssey benefits include Medical/Dental/Vision plan(s), health services, short term disability, unlimited PTO and more.

Our Commitment to Equal Opportunity Employment:

Odyssey is an equal opportunity employer. Reasonable accommodations are available upon request.

Skills Required

  • 6+ years of Software Engineering experience focused on application security, cloud security, DevOps, or network security
  • Hands-on experience with SOC 2 and ISO 27001 compliance and driving organizational adherence
  • Experience applying AI-assisted tooling to accelerate threat detection, code review, and vulnerability analysis
  • Experience deploying and operating SAST, DAST, and SCA tools across the software development lifecycle
  • Strong track record managing security projects end-to-end within timelines and budgets
  • Experience with penetration testing tools, techniques, and methodologies and familiarity with common vulnerabilities and remediation strategies
  • Experience conducting in-depth code reviews to detect vulnerabilities in application codebases
  • Experience designing and implementing security controls across application layer, CI/CD pipelines, and cloud infrastructure
  • Must be currently authorized to work in the United States on a full-time basis (no sponsorship)
  • Hybrid role based out of NYC (Tribeca) and candidates must attend at least one in-person interview

Odyssey (withodyssey) Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Odyssey (withodyssey) and has not been reviewed or approved by Odyssey (withodyssey).

  • Fair & Transparent Compensation Pay is presented with explicit, benchmarked salary bands in public postings, reducing ambiguity around offers. Technical role ranges are portrayed as competitive for a small, remote‑first gov/edtech company.
  • Healthcare Strength Healthcare is described as generous medical, dental, and vision coverage across hiring materials. This framing suggests employer-subsidized plans and is echoed in third‑party listings.
  • Wellbeing & Lifestyle Benefits Wellbeing support includes a one‑time $3,000 work‑from‑home/technology stipend and a recurring $150/month education stipend. The remote‑friendly setup complements these perks to support productivity and continuous learning.

Odyssey (withodyssey) Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Indianapolis, IN
53 Employees
Year Founded: 2021

What We Do

Odyssey is a mission driven company that helps families easily access state funding so that they can attend the school of their choice. We do this by partnering with state agencies to administer school choice programs, such as education savings accounts (ESAs), that enable parents to pay for approved educational expenses like school tuition, tutors, technology, software, and curriculum. At Odyssey, our technology powers ESA programs that enroll more than 80,000 students and help them access more than $600 million in state funding. In the 2026-2027 school year, Odyssey will enable 235,000 students to receive more than $2 billion in school choice funding. Sitting at the intersection of tech, government, and education, Odyssey offers potential employees an immediate and substantive impact for students and families. Supported by well known investors and advisors (Katherine Boyle/A16Z/Tusk Venture Partners) Odyssey is gaining traction quickly with ample opportunity for growth. As our team expands, we are looking for top-tier talent to join our mission in driving the future of education forward.

Similar Jobs

Odyssey (withodyssey) Logo Odyssey (withodyssey)

Application Security Engineer

Edtech • Information Technology • Software
In-Office or Remote
New York, NY, USA
53 Employees
180K-220K Annually

Datadog Logo Datadog

Technical Support

Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Easy Apply
Hybrid
3 Locations
6500 Employees
66K-88K Annually

Uniphore Logo Uniphore

Vice President, Global System Integrators

Artificial Intelligence • Machine Learning
In-Office
2 Locations
465 Employees
234K-500K Annually

BlackLine Logo BlackLine

Artificial Intelligence Engineer

Cloud • Fintech • Information Technology • Machine Learning • Software • App development • Generative AI
Remote or Hybrid
USA
1810 Employees
128K-160K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account