Senior Software Engineer, Security

Flex
$170,000 - $230,000Remote

About The Position

Flex is building the AI-native private bank for business owners, re-architecting the entire financial system for entrepreneurs. Banking, credit, payments, personal finance, and financial operations are being rebuilt from the ground up as a single, intelligent system. Flex is the full financial home for ambitious owners. Since launching publicly in September 2023, Flex has scaled from zero to nine-figure annualized revenue, with a clear path to profitability by late 2026. The company moves fast, ships relentlessly, and operates with extreme ownership. Customers are affluent business owners ($3–$200M in revenue), who are underserved by outdated banks and fragmented tools. The opportunity is massive: a ~$1T+ revenue market. The ambition is to build a $100B+ company by delivering a product that is fundamentally better. Flex has raised $100M+ in equity and $300M+ in debt. The company focuses on mission-critical problems, building software that directly controls how money moves at scale. They operate with a high bar, low ego culture in small teams with exceptional people and real ownership. Speed is prioritized over comfort, with a focus on execution, quality, clarity, and results. The work is intended to have enduring impact, defining how a generation of owners runs their businesses.

Requirements

  • Strong software engineer first, comfortable in a normal engineering interview loop.
  • Think like a builder and an attacker at the same time, and prefer to remove a class of vulnerability rather than file fifty tickets about it.
  • Care about developer experience. Have shipped a security tool or control that engineers actually adopted, and can explain why they adopted it.
  • Can tell a senior colleague that what they built isn't safe, explain why in plain language, and work alongside them to build a better alternative.
  • Comfortable owning problems end to end with limited guidance, and comfortable saying what you need rather than quietly absorbing it.
  • Make risk-based calls. Have strong opinions about secure defaults, can tell a real risk from a theoretical one, and are comfortable deciding something isn't worth fixing right now.
  • Understand that you won't personally touch every security problem here, and don't want to. Build the defaults and the habits that let engineers make good security decisions without you in the room.
  • Can read a system diagram and find the trust boundary nobody drew.
  • Write clearly. Much of this job is convincing people in writing, across time zones.
  • Substantial hands-on experience building or securing systems in a fast-moving environment, including a stretch where you were the most senior person doing this work. We care about what you've built, not the year count.
  • Real software engineering ability in a language we'd ship (Python, Go, TypeScript, or similar). Not scripting alone.
  • Hands-on cloud infrastructure experience: AWS or GCP, Terraform or equivalent IaC, containers, and CI/CD pipelines you've changed, not only used.
  • Practical threat modeling on systems with real consequences, and the judgment to know which findings matter.
  • Experience with secrets management, workload identity, and service-to-service authorization.
  • Experience handling inbound vulnerability reports, including at least one difficult reporter.
  • Clear written communication and a bias toward writing things down.

Nice To Haves

  • A platform, infrastructure, or DevOps background where you moved toward security by choice. A great infrastructure engineer who wants to do this work will beat a traditional security hire who wants to write policy, every time.
  • Experience at a small company, or as a founder, where you were the only person who could do this and had to decide what to skip.
  • Experience running a VDP or bug bounty program, including the triage.
  • Fintech, payments, or another regulated environment, on the building side.
  • Experience applying AI or LLM tooling to security work in a way that held up in production.
  • Certifications like OSCP or OSWE are a signal we'll happily read, but they don't substitute for an engineering track record.

Responsibilities

  • Threat model the paths that move money: the ledger and write path, card issuing, payouts, and the stablecoin work. Do it inside design review on anything that touches money, continuously, not as a quarterly exercise.
  • Build secure-by-default infrastructure. Infrastructure as Code (IaC) guardrails, CI/CD supply chain integrity, secrets handling, service isolation, and workload IAM.
  • Build a just-in-time, least-privilege access system for cloud access that makes engineers faster while narrowing what any one credential can do.
  • Own application security across both new and existing systems. Continuously assess the highest-risk parts of what we've already shipped, and build automated checks and secure defaults into the development lifecycle so the same problems stop arriving. Code review on high-risk paths, dependency and SBOM hygiene, and static and dynamic analysis where it earns its keep. Eliminate whole vulnerability classes; leave the instance-by-instance work to the machines.
  • Build a golden path that keeps sensitive data out of logs, and the tooling that proves it stayed out.
  • Run our vulnerability disclosure program end to end, and grow it into a bug bounty when we can triage at that volume. You'd take this over from an engineering leader who's carrying it today.
  • Scope and manage external penetration tests, and drive the remediation afterwards. We buy offensive testing; you decide what to point it at.
  • Build security automation, including AI-assisted triage and review, so that two people can cover a surface that usually takes a larger team.
  • Partner with Engineering, IT and Corporate Engineering, Risk, and Compliance. You'll be technical input on partner security reviews and audits without owning the paperwork.

Benefits

  • Equity
  • Compensation: $170,000 - $230,000 a year, depending on experience
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service