NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in United States of America
4 days ago
Apply with autofill
Apply with autofill
Casca·4 days ago
4 days ago

Founding Security Engineer

San Francisco, United States of AmericaFull-timeOn-siteMid · 2-5 years₹1.5Cr – ₹1.9Cr/yr · est.Security Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at casca

How you compare FREE

?
Your scoreYour score: not yet known
→
49
Top 10%Top 10%: 49 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in United States.

Must-have skills for this role

  • appsec
  • authorization
  • typescript
  • node.js

PDF or DOCX · no account needed

Apply faster with autofill FREEcasca uses Ashby - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Software. Detections, libraries, policy-as-code, automation, CI/CD checks — reviewed, tested, and deployed like any other service.
  • Design reviews and threat models on what actually matters: auth, tenant isolation, data handling, anything touching borrower PII.
  • The AI attack surface. Prompt injection, tool-use abuse, exfiltration paths through agents, and the evals that tell you whether your controls hold.
  • Incidents, end to end, including the write-up and the fixes that follow.
  • Bank security reviews and audits, turned into engineering work that improves the system rather than paperwork that describes it.

What they're looking for

  • Several years of experience in AppSec, with specifics you can walk us through: bugs you found, incidents you ran, systems you hardened, tooling you shipped.
  • You write production code. We work primarily in TypeScript/Node.js and Python.
  • You know where security boundaries break in multi-tenant systems, and why it's usually authorization.
  • You can explain risk to an engineer in engineering terms and get the fix shipped without escalating.
  • You can sit across from a bank's security team, take hard questions honestly, and leave them more confident than when you walked in.
  • Steady during incidents. Honest afterward.
  • You'd rather build leverage than become a bottleneck.

Nice to have

  • Securing LLM or agentic products in production.
  • Standing up a security function at a fast-growing company.
  • Working inside or selling into regulated financial institutions: SOC 2, GLBA, FFIEC guidance, third-party risk, exam support.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Why Casca?

Casca is building AGI for banking. We’re replacing decades-old legacy systems with AI-native technology that automates 90% of the manual work humans once had to do.

Why this role exists

Our customers are FDIC-insured banks. Every one of them puts us through security review, control questionnaires, pen test results, and third-party risk assessment before we touch production. Then they hand us borrower tax returns, bank statements, and the data behind credit decisions on their own balance sheet.

So security isn't a compliance checkbox here. It's a precondition for the company existing. Every deal we win depends on it, and one bad breach ends the business.

The surface area is large and getting larger: a multi-tenant AI platform, a cloud estate under bank data-handling requirements, agents that read and act on customer data, and an engineering team shipping into all of it every day. Nobody can review their way across that. You build the guardrails, defaults, and tooling that scale past you.

What you'll own

  • Software. Detections, libraries, policy-as-code, automation, CI/CD checks — reviewed, tested, and deployed like any other service.

  • Design reviews and threat models on what actually matters: auth, tenant isolation, data handling, anything touching borrower PII.

  • The AI attack surface. Prompt injection, tool-use abuse, exfiltration paths through agents, and the evals that tell you whether your controls hold.

  • Incidents, end to end, including the write-up and the fixes that follow.

  • Bank security reviews and audits, turned into engineering work that improves the system rather than paperwork that describes it.

What we look for

  • Several years of experience in AppSec, with specifics you can walk us through: bugs you found, incidents you ran, systems you hardened, tooling you shipped.

  • You write production code. We work primarily in TypeScript/Node.js and Python.

  • You know where security boundaries break in multi-tenant systems, and why it's usually authorization.

  • You can explain risk to an engineer in engineering terms and get the fix shipped without escalating.

  • You can sit across from a bank's security team, take hard questions honestly, and leave them more confident than when you walked in.

  • Steady during incidents. Honest afterward.

  • You'd rather build leverage than become a bottleneck.

Helpful, not required

  • Securing LLM or agentic products in production.

  • Standing up a security function at a fast-growing company.

  • Working inside or selling into regulated financial institutions: SOC 2, GLBA, FFIEC guidance, third-party risk, exam support.

What you'll get:

  • Impact & Ownership: A unique opportunity to shape the future of banking through AI, owning end-to-end product initiatives.

  • Collaborative Environment: Work alongside a talented and passionate team that values continuous improvement and knowledge sharing.

  • Competitive Compensation: Includes salary, benefits, and potential equity in a fast-growing startup.

  • Professional Growth: Access to resources and mentorship to expand your skill set, influence strategy, and accelerate your career.

  • Culture of Innovation: We encourage risk-taking, learning from failures, and pushing the boundaries of what’s possible in fintech.

As an early-stage company building at the frontier of AI, we work with high intensity and commitment. While schedules can vary by role/team, many weeks will demand extra focus, flexibility and time particularly during major launches and high impact sprints. We're seeking those who are aligned to and able to commit to that expectation.

Company

Casca
San Francisco, United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Casca's careers site·first seen 16 Sept 2026·last verified 16 Sept 2026·How we source jobs

Similar jobs

  • Staff Security Engineer at robotsandpencilsUS - Remote–match not yet calculated
  • IT Security Engineer at zollChelmsford, United States of America–match not yet calculated
  • Cybersecurity Summer 2027 Intern (Undergraduate) at centeneRemote-MO–match not yet calculated
  • AI Security Engineer at trimbleUS - Remote, CO–match not yet calculated
  • Medical Device Cybersecurity Co-Op at Johnson & JohnsonDanvers, United States of America–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United States
  • Security Analyst jobs in United States
  • Cloud Security Engineer jobs in United States
  • Penetration Tester jobs in United States
  • Security Engineer jobs in India
  • Security Engineer jobs in United Kingdom