/roles — ROLE_369
Founding Security Lead
Series A fintech building AI agents that automate loan origination work for banks and lenders
The role
- COMP
- $190K - $250K
- EQUITY
- Competitive equity
- LOCATION
- San Francisco
- WORKPLACE
- On-site
- EXPERIENCE
- 4 - 8 years
- VISA
- None, Visa transfers
- STACK
- TypeScript, JavaScript, AWS, GCP
- INDUSTRY
- AI, Finance, Fintech, Financial Services
The company
AI-first lending software that takes most of the hand-processing out of small-business loan applications for banks and other lenders.
- STAGE
- growth-stage
- FUNDING
- $30M+ raised
- TEAM
- ~40 people
- FOUNDED
- 2023
- BACKING
- VC-backed
JD — the work
About the role
This is the first security leadership seat at a fast-growing AI lending startup that is scaling beyond its Series A. You would own and grow the appsec program as a strong individual contributor, taking on more technical leadership over time and building on a security foundation that already exists. A central challenge is protecting agent-based workflows in a banking setting with heavy regulation.
What you'll do
- Mature the appsec program through secure development practices, tooling, and processes that fit how engineers already ship
- Work with engineering on a secure architecture for the environment where AI agents run, guarding data privacy and AI-specific risks
- Automate detection pipelines and vulnerability management to cut down manual security toil
- Act as the lead during security incidents and convert each one into lasting structural fixes
- Support compliance work (ISO 27001, SOC 2, and security demands from partner banks) that builds customer trust
What they're looking for
- 4 to 8 years in security, grounded mainly in application security
- Hands-on skills paired with an appetite for growing into technical leadership
- Real interest in the security of AI agents and agent-driven systems
- Comfort working in a heavily regulated financial services environment
- Familiarity with TypeScript and JavaScript codebases running on AWS and GCP
Nice to have
- Compliance experience with ISO 27001, SOC 2, or bank-driven security reviews