Founding Security Engineer

Casca•San Francisco, CA
•$180,000 - $230,000

About The Position

Casca is building AGI for banking, replacing legacy systems with AI-native technology. This role is critical because Casca's customers are FDIC-insured banks, requiring rigorous security reviews, control questionnaires, pen tests, and third-party risk assessments before handling sensitive borrower data. Security is a fundamental requirement for the company's existence, with every deal dependent on it. The company's expanding surface area includes a multi-tenant AI platform, a cloud estate adhering to bank data-handling requirements, agents that process customer data, and a daily engineering deployment pipeline. To manage this, the role involves building scalable guardrails, defaults, and tooling.

Requirements

  • Several years of experience in AppSec, with specific examples of bugs found, incidents handled, systems hardened, and tooling developed.
  • Proficiency in writing production code, primarily in TypeScript/Node.js and Python.
  • Understanding of security boundaries in multi-tenant systems, particularly authorization issues.
  • Ability to explain security risks to engineers in technical terms and facilitate the implementation of fixes without escalation.
  • Capability to engage with bank security teams, answer questions honestly, and build confidence.
  • Ability to remain steady during incidents and honest afterward.
  • A preference for building leverage over becoming a bottleneck.

Nice To Haves

  • Experience securing LLM or agentic products in production.
  • Experience establishing a security function in a fast-growing company.
  • Experience working within or selling into regulated financial institutions, including knowledge of SOC 2, GLBA, FFIEC guidance, third-party risk, and exam support.

Responsibilities

  • Develop and deploy software including detections, libraries, policy-as-code, and automation within CI/CD checks.
  • Conduct design reviews and threat models focusing on critical areas like authentication, tenant isolation, data handling, and Personally Identifiable Information (PII).
  • Address the AI attack surface, including prompt injection, tool-use abuse, exfiltration paths through agents, and implementing evaluation mechanisms for controls.
  • Manage security incidents end-to-end, including post-incident analysis and implementing corrective actions.
  • Translate bank security reviews and audits into actionable engineering work to improve the system.
  • Build leverage rather than becoming a bottleneck.

Benefits

  • Impact & Ownership: Opportunity to shape the future of banking through AI and own end-to-end product initiatives.
  • Collaborative Environment: Work with a talented and passionate team focused on continuous improvement and knowledge sharing.
  • Competitive Compensation: Includes salary, benefits, and potential equity.
  • Professional Growth: Access to resources and mentorship for skill expansion, strategy influence, and career acceleration.
  • Culture of Innovation: Encouragement of risk-taking, learning from failures, and pushing boundaries in fintech.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service