Full-Time

Lead Security Engineer

Vulnerability and Configuration Management

Deadline 6/11/27
U.S. Financial Technology

U.S. Financial Technology

201-500 employees

Fintech media platform and market-entry network

Compensation Overview

$156.5k - $181k/yr

+ Performance bonus + 401(k) match

No H1B Sponsorship

Remote in USA

Remote

Bachelor's, Master's

Category
IT & Security (1)
Required Skills
TCP/IP
Microsoft Windows
Computer Networking
Vulnerability Analysis
AWS
DevOps
Linux/Unix

Get referred to U.S. Financial Technology

See people who can refer or advise you

Requirements
  • A bachelor's degree or equivalent is required, specifically in Computer Science, Information Systems, Cyber Security, or a related technical field.
  • At least 7 years of experience in security engineering and operations, including managing and supporting large, complex, mission-critical systems and vulnerability management tools, patching processes and tools, VM operation/workflow, or configuration, baseline, and file-integrity monitoring applications and processes.
  • Applicants must be authorized to work in the United States without requiring employer sponsorship currently or in the future.
  • Subject-matter expertise in cloud-based critical infrastructure systems and security threats, with AWS cloud experience required.
  • Subject-matter expertise in cybersecurity within vulnerability and compliance management.
  • Familiarity with current security vulnerabilities, advisories, incidents, penetration techniques, attacks, and determining countermeasures.
  • Strong understanding of artificial intelligence models, technologies, attack paths, vulnerabilities, and securing artificial intelligence tools or technologies.
  • Experience leveraging artificial intelligence models to identify, research, or remediate vulnerabilities.
  • Subject-matter expertise in network and system vulnerabilities, malware, networking protocols, multi-tiered applications, and attack methods used to exploit vulnerabilities.
  • Experience in a senior technical security role covering network security, operating-system security, Internet or web security, and vulnerability testing.
  • Strong knowledge of networking fundamentals, including TCP/IP, basic packet analysis, network engineering, and local- and wide-area network technologies and topologies.
  • Experience conducting comprehensive vulnerability assessments using vulnerability-monitoring tools such as Wiz and Tenable.
  • General knowledge and experience with Windows and Linux operating systems, baseline security configurations, auditing, forensics, and patch management.
  • Experience developing standard operating procedures, job aids, and hands-on training materials.
  • Ability to work in a fast-paced environment with occasional on-call activities.
  • Ability to manage multiple priorities, including projects, deliverables, and stakeholders.
  • Ability to influence peers and management and work cross-functionally to achieve objectives.
Responsibilities
  • Act as a subject-matter expert for the Vulnerability and Configuration Management program, its processes, and tooling.
  • Configure, tune, and maintain vulnerability management tools.
  • Work with Security Architecture on new builds, businesses, technologies, and environments to ensure coverage of Vulnerability and Configuration Management programs, processes, and tooling.
  • Build new security baselines for CIS, DISA STIG, and custom baselines.
  • Correlate vulnerabilities with threat intelligence to assess exploitability and risk, and work with the Cyber Security Operations Center to ensure mitigations are in place during remediation.
  • Provide detailed risk assessments for discovered vulnerabilities.
  • Enforce remediation timelines in accordance with standard operating procedures.
  • Collaborate with Information Technology and DevOps teams to ensure timely remediation of vulnerabilities.
  • Conduct regular and ad hoc vulnerability scans using tools such as Wiz and Tenable.
  • Integrate tools with all cloud environments and ensure complete coverage of all Information Technology environments.
  • Ensure alignment with internal security policies, regulatory requirements such as NIST and SOC, and industry best practices.
  • Support audits and assessments by providing evidence and documentation.
  • Act as a liaison between security, Information Technology, development, and risk teams.
  • Provide clear, actionable recommendations tailored to technical and non-technical audiences.
  • Provide guidance and training to junior members of the Vulnerability and Configuration Management team.
  • Identify gaps in vulnerability or compliance management programs and propose improvements.
  • Develop and maintain standard operating procedures, frameworks, and job aids or how-to guides.
Desired Qualifications
  • A master's degree is a plus.
  • AWS Security or AWS Architect certifications are desired.
  • Active participation in the security industry and external networking relationships to maintain knowledge of best practices, tactics, strategies, and technologies.
U.S. Financial Technology

U.S. Financial Technology

View

US Financial Technology operates as a media and information platform for the US fintech sector and as a network to help international fintechs enter North America and US firms expand globally. Its services include authorization and registration support, regulatory advice, and introductions to professional advisers and venture capital firms. The platform hosts a directory of over 950 fintechs across all 50 states and offers news, insights, events, and individual company pages to showcase products and services. Founded in 2020 by Peter Oakes as part of the International FinTech network, its goal is to inform, connect, and facilitate market entry and growth in the US fintech ecosystem.

Company Size

201-500

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

2014

Get referred to U.S. Financial Technology

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • 2025 rebrand signaled expansion beyond legacy CSS and opened commercialization opportunities.
  • U.S. FinTech says issuance and administration continue with no market disruptions in 2026.
  • Cloud-native platform and $16 trillion-plus portfolio depth create sticky, long-duration customer dependence.

What critics are saying

  • FHFA conservatorship ties U.S. FinTech’s destiny to GSE politics and Treasury oversight.
  • Customer Services Agreement changed January 1, 2026, replacing capital contributions with fee pressure.
  • A CSP outage would freeze mortgage securitization, disrupt refinancing, and trigger immediate federal scrutiny.

What makes U.S. Financial Technology unique

  • Fannie Mae and Freddie Mac jointly own U.S. FinTech, anchoring its monopoly-like role.
  • Its cloud-based Common Securitization Platform processed over $18 trillion since 2019.
  • FHFA-regulated infrastructure handles UMBS issuance for $6.5 trillion and 30 million loans.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

401(k) Company Match

401(k) Retirement Plan

Remote Work Options

Paid Vacation

Performance Bonus