Auf einen Blick
- Aufgaben: Leite die Sicherheitsstrategie und baue innovative Sicherheitslösungen mit KI.
- Unternehmen: Imprint, ein modernes FinTech-Unternehmen, das Marken beim Wachstum unterstützt.
- Vorteile: Wettbewerbsfähige Vergütung, flexible Arbeitszeiten und umfassende Gesundheitsversorgung.
- Weitere Informationen: Dynamisches Umfeld mit Möglichkeiten zur persönlichen und beruflichen Weiterentwicklung.
- Warum dieser Job: Gestalte die Sicherheitsarchitektur eines schnell wachsenden Unternehmens und nutze KI für echte Auswirkungen.
- Qualifikationen: Mindestens 8 Jahre Erfahrung in der Sicherheitsengineering und Kenntnisse in Go oder TypeScript.
Who We Are
Imprint helps the world's best brands grow the lifetime value of their customers.
We started with co-branded credit cards and rebuilt them to be smarter, more rewarding, and brand-first.
We partner with companies like Crate & Barrel, Rakuten, , H-E-B, Fetch, and Shell to launch modern credit programs that deepen loyalty, unlock savings, and drive growth.
But the card is just the beginning.
We combine advanced payments infrastructure, intelligent underwriting, and deep customer data to create delightful and personalized experiences for members as well as efficient and profitable relationships for our brand partners.
Our robust technology and world-class operations allow us and our brand partners to offer powerful financial products without becoming a bank.
In the U.
S., co-branded cards alone account for over $300 billion in annual spend, and most still run on decades-old legacy bank systems.
Imprint is the modern alternative: flexible, embeddable, and built for how people actually pay today.
Backed by Kleiner Perkins, Thrive Capital, Ribbit, and Khosla Ventures, we're building a world-class team to redefine how people pay and how brands grow.
If you want to move fast, solve hard problems, and own real outcomes, we want to meet you.
The Role
As Imprint's Senior Engineering Manager for Security, you will report to the Director of Engineering for Trust & Security.
You will own the entire security engineering foundation.
This includes AI security governance, application security, cloud infrastructure, detection and response, and identity management.
You'll build this with AI leverage from day one, scaling a small team's impact with modern tooling.
Imprint is deliberately small and talent-dense.
We use AI and tooling to give every person outsized leverage.
This is a role where you can stay hands-on for as long as it makes sense.
You set the strategic direction and do the work.
Whether that balance shifts over time depends on what the business needs and what you want to build.
We power co-branded credit card programs for 10+ enterprise partners, with AI embedded across the business: underwriting, servicing, and how we build software.
That AI leverage is core to how Imprint operates, and it creates a security challenge worth solving: how do you build an AI-forward security posture for an organization that moves this fast?
- Why This Role Is Special
- Stay Hands-On: Write detection rules, review PRs, file hardening commits, and threat-model features alongside engineering teams.
If you've been pushed into pure management and miss building, this role gives you permission to get back to it while still setting strategic direction.
- AI-Native
Security: Build security capabilities using AI agents for detection triage, compliance automation, and dependency management.
You'll secure AI products and use AI to multiply your own leverage.
This is how a small team operates at the standards of a company 10x its size.
- Full-Stack Ownership: Own the entire security domain: application security, cloud infrastructure, detection engineering and AI governance.
- Preventative, Not Reactive: Build security that scales with the business rather than firefighting inherited problems. Do it right from the start, before bad patterns harden.
- Series D Sweet
Spot: We have product-market fit and real traction, but we're still small enough for you to shape everything.
Your decisions will drive our security posture for years to come.
- High-Trust Domain: Co‑branded credit cards in regulated fintech (PCI, SOC2, ISO). Security isn't a tax here; it enables every partner launch and every customer interaction.
- What You Will Own
- AI security: threat-model Imprint's agent surfaces for prompt injection, tool misuse, and authorization boundaries.
- AI for security: build AI‑native capabilities that scale a small team's impact: AI-powered detection triage, automated compliance evidence collection, and threat-modeling assistance.
- Application security: threat modeling for new features, secure code review, SAST/SCA/DAST in CI, SDL design, dependency management, and secrets management.
You read Go and Type Script well enough to review PRs and catch the bugs that external audits should not have to find.
- Cloud and infrastructure security: IAM partitioning across multiple AWS accounts, least-privilege access, JIT elevation, cross-account trust hardening, KMS boundaries, SCP design, Kubernetes pod security, egress filtering, and Terraform security review.
- Detection and response: build the SIEM/SOAR pipeline from log sources through triage, write correlation rules, enable AI-powered triage, stand up on‑call rotation, and create incident response runbooks.
- Identity and access: drive SSO coverage, access reviews, and JIT elevation in partnership with IT.
- Compliance partnership: design and implement the controls that satisfy SOC2, PCI, and ISO evidence requirements.
GRC runs the audit cycle.
You own the underlying controls and make sure they actually hold up, not just pass sampling.
- Partner and customer trust: lead technical responses to third‑party questionnaires and partner security reviews alongside GRC.
- What We Look for
- 8+ years in security engineering, with experience building a security function from early stages
- Someone who builds and ships controls, not just identifies problems for others to fix
- Reads and reviews code in production languages (Go, Type Script, Python, or similar)
- Detection engineering experience: has built a SIEM or SOAR pipeline from log sources through triage at least once
- Deep AWS security knowledge: IAM policy design, multi‑account strategies, and how cloud privilege escalation works
- Has operated inside PCI DSS scope and shipped controls that survived a real audit
- Good judgment on scope: knows when to fix something directly versus set an SLA and hand it to the responsible team
- Comfortable using AI tools to scale a small security team while working within existing architecture and review processes
- Nice to Have
- Experience as the first or early security hire at a high‑growth fintech or marketplace
- Background at companies like Ramp, Mercury, Stripe, Whatnot, or similar fast‑scaling environments
- Experience securing AI and ML systems, model pipelines, or AI‑assisted development workflows
- Familiarity with card issuing, payment processing, or financial services infrastructure
- Terraform and Helm fluency with hands‑on CI/CD security integration experience
- Open source contributions, security research, or conference speaking
If you've built something real in security and want to do it again, we want to talk.
Perks & Benefits
- Competitive compensation and equity packages
- Leading configured work computers of your choice
- Flexible paid time off
- Fully covered, high-quality healthcare, including fully covered dependent coverage
- Additional health coverage includes access to One Medical and the option to enroll in an FSA
- 20 weeks of paid parental leave for the primary caregiver and 8 weeks for all new parents
- Access to industry‑leading technology across all of our business units, stemming from our philosophy that we should invest in resources for our team that foster innovation, optimization, and productivity
Imprint is committed to a diverse and inclusive workplace.
Imprint is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.
Imprint welcomes talented individuals from all backgrounds who want to build the future of payments and rewards.
If you are passionate about Fin Tech and eager to grow, let’s move the world forward, together.
Compensation Range: $220K - $235K
#J-18808-Ljbffr
Senior Engineering Manager, Security Arbeitgeber: Embedded Shishya
Jitterbit ist ein hervorragender Arbeitgeber, der Ihnen die Möglichkeit bietet, in einem dynamischen und wachsenden Umfeld zu arbeiten, das sich auf die Integration von Plattformen als Dienstleistung (iPaaS) spezialisiert hat. Mit einem flexiblen, remote-freundlichen Arbeitsmodell und einer Unternehmenskultur, die auf Zusammenarbeit und persönlichem Wachstum basiert, fördern wir Ihre Karriere durch Mentorship und kontinuierliche Entwicklung. Hier haben Sie die Chance, bedeutende Partnerschaften zu entwickeln und die Zukunft der API-Nutzung in geschäftskritischen Prozessen mitzugestalten.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Senior Engineering Manager, Security erhalten könntest
✨Werde sichtbar in der IT-Sicherheits-Community
In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Embedded Shishya kennenzulernen!
✨Kollaboriere an Open-Source-Projekten
Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.
✨Nutze spezielle Jobportale für IT-Sicherheit
Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Embedded Shishya zu bewerben!
✨Halte deine Skills up-to-date
In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Embedded Shishya.
Wir glauben, dass du diese Fähigkeiten brauchst, um Senior Engineering Manager, Security mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.
Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.
Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!
Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!
Wie man sich auf ein Vorstellungsgespräch bei Embedded Shishya vorbereitet
✨Sicherheitsprotokolle dominiert!
Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Embedded Shishya könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!
✨Praktische Erfahrung zählt!
Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Embedded Shishya sucht nach jemandem, der die Theorie auch anwenden kann!
✨Teamarbeit nicht vergessen!
IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!
✨Motivation und Lernbereitschaft zeigen!
Da es sich um eine Vollzeitstelle handelt, wird Embedded Shishya auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!