Back to Jobs

[Remote] Lead Security Engineer

Remote, USA Full-time Posted 2026-06-16

Note: The job is a remote job and is open to candidates in USA. Benepass is a fintech company focused on making benefits easy for organizations by allowing them to tailor offerings to their workforce's unique needs. As a Lead Security Engineer, you will build and scale security practices to protect sensitive data while collaborating with various teams to implement effective security measures.

Responsibilities

  • Build, operationalize, and scale the security engineering practices that protect our benefits platform and the sensitive employee, benefits, and financial data it processes
  • Work across application security, cloud security, security architecture, supply chain security, detection engineering, and vulnerability management
  • Partner deeply with the teams building our web and mobile applications, backend services, system integrations, card and banking workflows, infrastructure as code, and data platforms to turn risk reduction into scalable guardrails, automated controls, and clear engineering guidance
  • Set direction and mature security capabilities
  • Introduce strong standards, ship incremental improvements, and ensure secure paths for engineers without creating a centralized approval queue

Skills

  • 7+ years in security engineering, application security, cloud security, product security, platform security, or closely related technical security roles, ideally in a high-growth SaaS or technology company
  • Proven ability to lead broad security engineering initiatives as a senior IC, influence cross-functional technical decisions, and move work from strategy to production implementation
  • Strong working knowledge of secure SDLC practices, secure design review, threat modeling, API security, code scanning, SAST, CI/CD security integrations, security testing, defect management, and vulnerability remediation workflows
  • Hands-on experience with AWS-native security patterns and services, including IAM, KMS, CloudTrail, GuardDuty, Security Hub, VPC segmentation, WAF, Secrets Manager, S3/RDS encryption, infrastructure-as-code security, container orchestration security, and cloud posture management
  • Ability to guide secure system builds involving access control, encryption standards, key and certificate management, vaulting, secrets management, and managed HSM/KMS-backed cryptographic services
  • Experience hardening build, test, and deployment workflows through dependency scanning, SBOMs, artifact signing, secret scanning, CI/CD guardrails, least-privilege automation, and container security controls
  • Ability to use frameworks such as NIST CSF 2.0 and OWASP SAMM pragmatically to assess current state, sequence improvements, define metrics, and mature security practices iteratively
  • Clear communicator who can partner with engineering, product, platform, compliance, and business teams; write practical guidance; teach developers; and create durable security champions programs
  • Strong judgment in prioritizing technical risk reduction, managing ambiguity, documenting decisions, and building lightweight processes that scale with the company
  • Experience securing fintech, benefits, payroll, payments, or other regulated SaaS platforms that process PII, financial data, HRIS data, transaction data, or customer administrative workflows
  • Familiarity with SOC 2, HITRUST, PCI, or similar compliance and audit programs, with the ability to support evidence and control design while staying focused on technical risk reduction
  • Experience with AWS serverless and managed-service architectures, including API Gateway, Cognito, Lambda, ECS/EKS, RDS, S3, Transfer Family, CloudFront, and event-driven security monitoring patterns
  • Background with mobile application security for iOS and Android, including secure token handling, platform keychain/keystore patterns, OTA update risk, and mobile API abuse prevention
  • Experience with detection-as-code, SIEM/SOAR workflows, security data pipelines, incident response automation, or measurable improvements to alert quality and response readiness
  • Hands-on experience with Terraform, CloudFormation, CDK, policy-as-code, CSPM/CWPP tools, container image scanning, runtime security, or Kubernetes/ECS hardening
  • Experience designing developer education, secure coding workshops, security champions programs, or other scalable practices that improve security outcomes without slowing delivery
  • Experience defining practical governance for LLMs, AI coding assistants, prompt/data handling, model/tool approval, and sensitive data protection in AI-enabled software development workflows

Benefits

  • 95% coverage of medical, dental, and vision
  • $250 WFH setup (one time)
  • $500/year Learning & Development Benefit
  • $150/month cell phone + internet
  • $100/month Wellness
  • $100/month Co-working and Commuter Benefit
  • We offer several team onsites a year
  • Flexible PTO

Company Overview

  • Benepass is a benefits administration platform that helps companies manage and distribute employee perks and benefits. It was founded in 2019, and is headquartered in New York, New York, USA, with a workforce of 51-200 employees. Its website is http://www.getbenepass.com.
  • Apply To This Job

    Similar Jobs

    [Remote] Sr. Data Engineer, Data Platform

    Remote, USA Full-time

    [Remote] BIM Consultant - Electrical

    Remote, USA Full-time

    [Remote] Litigation Administrative Assistant

    Remote, USA Full-time

    [Remote] Customer Success Manager (Northeast)

    Remote, USA Full-time

    [Remote] Designer/Social Media Creative

    Remote, USA Full-time

    [Remote] Locums Recruiter

    Remote, USA Full-time

    [Remote] Machine Learning Engineer, Personalization, Minesweeper

    Remote, USA Full-time

    [Remote] Senior Salesforce Consultant

    Remote, USA Full-time

    [Remote] Software Engineer

    Remote, USA Full-time

    [Remote] Software Engineer

    Remote, USA Full-time

    Assistant Controller - REMOTE

    Remote, USA Full-time

    PB Denial Specialist - EPIC

    Remote, USA Full-time

    Tutor di Roblox Italy

    Remote, USA Full-time

    Senior Software Engineer - Tax Platform

    Remote, USA Full-time

    Experienced Part-time Remote Customer Retention Specialist – Life Insurance Policyholder Engagement and Upselling

    Remote, USA Full-time

    Experienced Data Entry Clerk I/II – Remote Opportunity for a Dynamic Team at arenaflex

    Remote, USA Full-time

    Remote Brokerage Customer Care Supervisor – arenaflex SMB Experience & Revenue Optimization

    Remote, USA Full-time

    Dynamic Field Customer Support Specialist – Collections & Account Recovery – On‑Site Service – Columbus, OH – arenaflex

    Remote, USA Full-time

    Cloud Account Executive, Marketing Technologies: Higher Education

    Remote, USA Full-time

    Experienced Part-time Remote Data Entry Clerk / Administrative Assistant – Flexible Work Schedule

    Remote, USA Full-time