Security Engineer

Posted 14 Days Ago
Be an Early Applicant
Chicago, IL, USA
In-Office
145K-195K Annually
Mid level
Blockchain
The Role
Own Coinflow's defensive and offensive security posture: deploy and operate SIEM and SecOps dashboards, run continuous internal pentests, triage CVEs and manage dependency upgrades, integrate SAST/DAST/secret scanning into CI, define secure-by-default patterns, and produce audit-ready evidence for PCI DSS, SOC 2, ISO 27001, and DORA compliance.
Summary Generated by Built In

About Coinflow

Coinflow is the next-generation payment service provider revolutionizing global financial infrastructure with stablecoins, AI-driven fraud prevention, and instant settlement. Coinflow enables businesses to grow faster with instant settlement, fraud & chargeback indemnity, global pay-ins, multi-currency FX, and unified payouts. Founded in 2023, the company serves marketplaces, fintechs, remittance providers, gaming platforms, and ecommerce merchants worldwide.

Since our seed round in 2024, we’ve achieved 23x revenue growth and scaled to multi-billion-dollar annual transaction volume. In response to this growth, Coinflow announced a $25M Series A in October 2025—led by Pantera Capital, CMT Digital, Coinbase Ventures, Jump Crypto, and Reciprocal Ventures—accelerating our mission to power the world’s fastest-moving businesses with innovative, reliable global payments.

Coinflow is proudly headquartered in Chicago, IL. Learn more at coinflow.cash.

About The Role

We're hiring for a Security Engineer to own the day-to-day defensive and offensive security posture of Coinflow. You'll build the SecOps backbone, hunt for weaknesses in our own stack before anyone else does, and partner with engineering to keep our SDLC fast and secure. This role reports to the CTO and has a direct line into every part of the engineering org.

You'll be hands-on with modern AI-native security tooling — we use Claude Security and Claude Code as force multipliers for internal pentesting, code review, and remediation. If you're excited about being one of the first security engineers building this way, you'll fit in well here.

What You'll Own

  • SIEM & SecOps Dashboard: Stand up and operate our SIEM. Build out the SecOps dashboard that gives engineering, compliance, and leadership a real-time picture of our security posture — alerts, anomalies, auth events, infrastructure changes, and audit-ready evidence in one place.

  • Internal Penetration Testing: Run continuous internal pentests against Coinflow services, APIs, infrastructure, and embedded SDKs. Use Claude Security and Claude Code to scale your coverage — automate reconnaissance, fuzzing, code review, and exploit development. Document findings, drive remediation, and measure mean-time-to-fix.

  • Vulnerability & Dependency Management: Own the vulnerability lifecycle end-to-end. Triage CVEs across our npm, cargo, and other ecosystems. Build the automation that keeps packages patched without breaking production — including Dependabot tuning, lockfile hygiene, and gated auto-merge for low-risk upgrades.

  • Secure Development Lifecycle: Monitor and improve how we ship code. Define secure-by-default patterns for new services, review threat models for high-risk changes, integrate SAST/DAST/secret scanning into CI, and make the secure path the fast path for engineers.

  • Compliance Partnership: Work alongside our compliance function to produce the evidence, controls, and monitoring artifacts that PCI DSS, SOC 2, ISO 27001, and DORA auditors need — without turning engineering into a paperwork shop.

What We're Looking For

  • 4+ years in a security engineering, product security, or DevSecOps role, ideally at a fintech, payments company, or other regulated environment

  • Strong hands-on offensive skills — you've broken real systems, not just run scanners. Comfortable with web app, API, cloud, and infrastructure pentesting

  • Production experience operating a SIEM (Datadog, Splunk, Elastic, Panther, or similar) and building dashboards that engineers actually use

  • Fluency in TypeScript/Node and at least passing comfort with Rust, Go, or Python — enough to read our code, find bugs in it, and write the tooling to find more

  • Experience with vulnerability management at scale: CVE triage, SCA tooling, dependency upgrade automation

  • Comfort working with AI-native tooling (Claude Code, Claude Security, or similar) as a daily driver — or genuine excitement to start

  • A bias toward shipping. We'd rather have a working v1 of a control today than a perfect v3 next quarter.

The base salary range for this role is $145,000 to $195,000 USD. The actual base salary offered depends on a variety of factors, including but not limited to experience, education, skills, qualifications and business needs.

In addition, the employee who fills this role will be eligible for an equity grant, allowing you to share in the long-term success of the company. You will also have access to a wide array of benefits, including health and wellness benefits, 401(k) savings plan, and flexible time off.

Join the team rewriting how money moves worldwide—and become a driving force in the $194 trillion cross-border payments market.

Skills Required

  • 4+ years in a security engineering, product security, or DevSecOps role
  • Strong hands-on offensive skills (web app, API, cloud, infrastructure pentesting)
  • Production experience operating a SIEM (Datadog, Splunk, Elastic, Panther, or similar) and building usable dashboards
  • Fluency in TypeScript and Node.js
  • Familiarity/comfort reading and working with Rust, Go, or Python
  • Experience with vulnerability management at scale: CVE triage, SCA tooling, dependency upgrade automation (Dependabot, lockfile hygiene)
  • Comfort working with AI-native security tooling (Claude Code, Claude Security, or similar) or strong enthusiasm to adopt such tooling
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL

What We Do

Coinflow (fka Coinflow Labs) is the next-generation payment service provider revolutionizing global financial infrastructure with stablecoins, AI-driven fraud prevention, and instant settlement. Coinflow enables businesses to grow faster with instant settlement, fraud & chargeback indemnity, global pay-in, multi-currency FX, and unified payouts—all in one intuitive platform. We serve marketplaces, fintechs, remittance providers, gaming platforms, and e-commerce merchants worldwide. Coinflow is proudly headquartered in Chicago, Illinois.

Similar Jobs

Supernova Technology Logo Supernova Technology

Security Engineer

Cloud • Fintech • Payments • Software
Hybrid
Chicago, IL, USA
118 Employees
110K-140K Annually
Hybrid
4 Locations
289097 Employees

CrowdStrike Logo CrowdStrike

Security Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
120K-180K Annually

Applied Systems Logo Applied Systems

Security Engineer

Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Remote or Hybrid
United States
3116 Employees
80K-120K Annually

Similar Companies Hiring

Block Thumbnail
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
Oakland, CA
12000 Employees
Spiral Thumbnail
Software • Cryptocurrency • Blockchain
New York, NY
20 Employees
Rain Thumbnail
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3 • Infrastructure as a Service (IaaS)
New York, NY
100 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account