Full-Time

Security Engineer

Updated on 8/1/2026

Coinflow

Coinflow

51-200 employees

Web3 payment processor enabling fiat-to-stablecoin settlement

Compensation Overview

$145k - $195k/yr

+ Equity Grant

Chicago, IL, USA

In Person

Category
IT & Security (1)
Required Skills
Datadog
Rust
Python
TypeScript
Vulnerability Analysis
SOC 2
Go
Penetration Testing
Splunk

Get referred to Coinflow

See people who can refer or advise you

Requirements
  • The candidate must have at least 4 years of experience in a security engineering, product security, or DevSecOps role, ideally in fintech, payments, or another regulated environment.
  • The candidate must have strong hands-on offensive security skills, including web application, application programming interface, cloud, and infrastructure penetration testing.
  • The candidate must have production experience operating a security information and event management system and building dashboards used by engineers.
  • The candidate must be fluent in TypeScript and Node.js and have at least passing familiarity with Rust, Go, or Python.
  • The candidate must have experience with vulnerability management at scale, including CVE triage, software composition analysis tooling, and dependency upgrade automation.
  • The candidate must be comfortable working with artificial intelligence-native tooling such as Claude Code or Claude Security, or be genuinely motivated to learn it.
Responsibilities
  • Own the day-to-day defensive and offensive security posture of Coinflow.
  • Stand up and operate the security information and event management system.
  • Build and operate a SecOps dashboard showing alerts, anomalies, authentication events, infrastructure changes, and audit-ready evidence.
  • Run continuous internal penetration tests against Coinflow services, application programming interfaces, infrastructure, and embedded software development kits.
  • Use Claude Security and Claude Code to automate reconnaissance, fuzzing, code review, and exploit development.
  • Document penetration-testing findings, drive remediation, and measure mean time to fix.
  • Own the vulnerability lifecycle end to end.
  • Triage CVEs across npm, Cargo, and other ecosystems.
  • Build automation to keep packages patched without breaking production, including Dependabot tuning, lockfile hygiene, and gated automatic merging for low-risk upgrades.
  • Monitor and improve the secure development lifecycle.
  • Define secure-by-default patterns for new services.
  • Review threat models for high-risk changes.
  • Integrate static application security testing, dynamic application security testing, and secret scanning into continuous integration.
  • Partner with engineering to make the secure development path efficient for engineers.
  • Work with the compliance function to produce evidence, controls, and monitoring artifacts required by PCI DSS, SOC 2, ISO 27001, and DORA auditors.

Coinflow is a payment processor that helps Web3 businesses accept traditional payments like credit cards and mobile wallets, and settles those funds instantly into stablecoins to improve cash flow. For payouts, it uses real-time rails such as Visa Direct and the RTP Network to move funds from stablecoins to users’ bank accounts. It differentiates itself with instant fiat-to-stablecoin settlement, real-time payouts, and a focus on Web3 use cases such as gaming, NFTs, and digital wallets. Its goal is to provide fast, reliable payment infrastructure that bridges traditional finance and blockchain so developers and platforms can scale without delays in settlements.

Company Size

51-200

Company Stage

Series A

Total Funding

$27.2M

Headquarters

Chicago, Illinois

Founded

2022

Get referred to Coinflow

See people who can refer or advise you

Benefits

Health Insurance

Wellness Program

Flexible Work Hours

Growth & Insights

Headcount

6 month growth

0%

1 year growth

3%

2 year growth

1%