Coinflow Logo

Coinflow

Security Engineer

Posted 5 Days Ago
Be an Early Applicant
In-Office
Chicago, IL, USA
145K-195K Annually
Mid level
In-Office
Chicago, IL, USA
145K-195K Annually
Mid level
Own Coinflow's defensive and offensive security posture: deploy and operate SIEM and SecOps dashboards, run continuous internal pentests, triage CVEs and manage dependency upgrades, integrate SAST/DAST/secret scanning into CI, define secure-by-default patterns, and produce audit-ready evidence for PCI DSS, SOC 2, ISO 27001, and DORA compliance.
The summary above was generated by AI

About Coinflow

Coinflow is the next-generation payment service provider revolutionizing global financial infrastructure with stablecoins, AI-driven fraud prevention, and instant settlement. Coinflow enables businesses to grow faster with instant settlement, fraud & chargeback indemnity, global pay-ins, multi-currency FX, and unified payouts. Founded in 2023, the company serves marketplaces, fintechs, remittance providers, gaming platforms, and ecommerce merchants worldwide.

Since our seed round in 2024, we’ve achieved 23x revenue growth and scaled to multi-billion-dollar annual transaction volume. In response to this growth, Coinflow announced a $25M Series A in October 2025—led by Pantera Capital, CMT Digital, Coinbase Ventures, Jump Crypto, and Reciprocal Ventures—accelerating our mission to power the world’s fastest-moving businesses with innovative, reliable global payments.

Coinflow is proudly headquartered in Chicago, IL. Learn more at coinflow.cash.

About The Role

We're hiring for a Security Engineer to own the day-to-day defensive and offensive security posture of Coinflow. You'll build the SecOps backbone, hunt for weaknesses in our own stack before anyone else does, and partner with engineering to keep our SDLC fast and secure. This role reports to the CTO and has a direct line into every part of the engineering org.

You'll be hands-on with modern AI-native security tooling — we use Claude Security and Claude Code as force multipliers for internal pentesting, code review, and remediation. If you're excited about being one of the first security engineers building this way, you'll fit in well here.

What You'll Own

  • SIEM & SecOps Dashboard: Stand up and operate our SIEM. Build out the SecOps dashboard that gives engineering, compliance, and leadership a real-time picture of our security posture — alerts, anomalies, auth events, infrastructure changes, and audit-ready evidence in one place.

  • Internal Penetration Testing: Run continuous internal pentests against Coinflow services, APIs, infrastructure, and embedded SDKs. Use Claude Security and Claude Code to scale your coverage — automate reconnaissance, fuzzing, code review, and exploit development. Document findings, drive remediation, and measure mean-time-to-fix.

  • Vulnerability & Dependency Management: Own the vulnerability lifecycle end-to-end. Triage CVEs across our npm, cargo, and other ecosystems. Build the automation that keeps packages patched without breaking production — including Dependabot tuning, lockfile hygiene, and gated auto-merge for low-risk upgrades.

  • Secure Development Lifecycle: Monitor and improve how we ship code. Define secure-by-default patterns for new services, review threat models for high-risk changes, integrate SAST/DAST/secret scanning into CI, and make the secure path the fast path for engineers.

  • Compliance Partnership: Work alongside our compliance function to produce the evidence, controls, and monitoring artifacts that PCI DSS, SOC 2, ISO 27001, and DORA auditors need — without turning engineering into a paperwork shop.

What We're Looking For

  • 4+ years in a security engineering, product security, or DevSecOps role, ideally at a fintech, payments company, or other regulated environment

  • Strong hands-on offensive skills — you've broken real systems, not just run scanners. Comfortable with web app, API, cloud, and infrastructure pentesting

  • Production experience operating a SIEM (Datadog, Splunk, Elastic, Panther, or similar) and building dashboards that engineers actually use

  • Fluency in TypeScript/Node and at least passing comfort with Rust, Go, or Python — enough to read our code, find bugs in it, and write the tooling to find more

  • Experience with vulnerability management at scale: CVE triage, SCA tooling, dependency upgrade automation

  • Comfort working with AI-native tooling (Claude Code, Claude Security, or similar) as a daily driver — or genuine excitement to start

  • A bias toward shipping. We'd rather have a working v1 of a control today than a perfect v3 next quarter.

The base salary range for this role is $145,000 to $195,000 USD. The actual base salary offered depends on a variety of factors, including but not limited to experience, education, skills, qualifications and business needs.

In addition, the employee who fills this role will be eligible for an equity grant, allowing you to share in the long-term success of the company. You will also have access to a wide array of benefits, including health and wellness benefits, 401(k) savings plan, and flexible time off.

Join the team rewriting how money moves worldwide—and become a driving force in the $194 trillion cross-border payments market.

HQ

Coinflow Chicago, Illinois, USA Office

Chicago, IL, United States

Similar Jobs

2 Days Ago
Remote or Hybrid
United States
80K-120K Annually
Mid level
80K-120K Annually
Mid level
Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Secure LLMs, generative AI systems, ML infrastructure, training pipelines, and AI applications. Responsibilities include threat modeling, architecture reviews, security controls, hardening, vulnerability remediation, data privacy, incident response runbooks, vendor reviews, governance, policy development, and AI security training. The role also supports proof-of-concept security solutions and monitors emerging AI threats.
Top Skills: AnsibleBashETLGdprGenerative AiGoInfrastructure As CodeKubernetesLarge Language ModelsPythonPyTorchScikit-LearnSoc 2TensorFlowTerraform
2 Days Ago
Hybrid
Chicago, IL, USA
110K-140K Annually
Senior level
110K-140K Annually
Senior level
Agency • Gaming • Marketing Tech • Mobile • Analytics
Evaluates and secures AI tools, SaaS applications, marketing technology platforms, integrations, and third-party plugins. Conducts secure code reviews, SAST/DAST testing, threat modeling, architecture assessments, and vendor risk reviews. Develops AI security standards, reference architectures, policies, and playbooks while partnering with engineering, procurement, legal, marketing, and digital teams. Supports compliance with security and privacy requirements and coordinates risk, compliance, and audit initiatives.
Top Skills: Adobe Experience CloudArcherAWSAzureBurp SuiteCheckmarxCi/CdDastGCPGoHubspotJavaScriptOauth 2.0OnetrustPythonRapid7SalesforceSAMLSastScaSemgrepSnykTypescriptZengrc
2 Days Ago
In-Office or Remote
United States
150K-190K Annually
Expert/Leader
150K-190K Annually
Expert/Leader
Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
Serves as the senior technical authority for enterprise browser data protection and security. Owns architecture, roadmap, standards, lifecycle, browser-based DLP controls, integrations, automation, and operational support. Leads complex troubleshooting, major incident response, root-cause analysis, runbook development, and continuous improvement. Partners across cybersecurity, identity, endpoint, network, cloud, risk, compliance, and vendor teams while mentoring engineers and influencing enterprise security design.
Top Skills: Active DirectoryAzure DevopsCasbChrome Enterprise PremiumCisco Secure AccessCloud PlatformsCrowdstrikeCyberarkDigital GuardianDnsEntra IdForcepoint DlpGitGitIslandJAMFMecm/SccmMenlo SecurityMicrosoft Defender XdrMicrosoft Edge For BusinessMicrosoft GraphMicrosoft IntuneMicrosoft Purview DlpMicrosoft SentinelNetskope DlpOktaPalo AltoPalo Alto Prisma BrowserPing IdentityPowershellPythonRest ApisSaseSplunkSwgSymantec DlpTaniumTerraformTls/HttpsVpnZscalerZtna

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account