Base Career helps you apply smarter for this job.
We're hiring our first security engineers.
Both report directly to the CTO.
We want software engineers with security as their superpower, not security specialists who occasionally write code.
The distinction matters here.
At our size, the only way one person covers a surface this large is to build things that keep working after they move on.
A findings queue you work through by hand grows faster than you can close it.
A guardrail in the deployment pipeline doesn't.
The work is product and infrastructure security: making the paths that move money hard to attack, and making the secure way to build something also the easy way.
The ledger and its write path, card issuing, payouts, and our stablecoin work are the systems that matter most.
The job runs in both directions.
You'll be in design review early on anything new, and you'll be continuously assessing what we've already shipped, because most of Flex's risk lives in code that exists today.
We don't expect you to read the codebase by hand or to keep a findings queue.
We expect you to build the automation and repeatable checks that keep assessing it for you, and to spend the time you get back on the golden paths that stop whole classes of problem from arriving again.
There's no security team above you and no CISO.
You'd set the standard here, and own the risk decisions that come with it.
Day to day, what gets fixed now, what gets mitigated, and what we knowingly accept is your call.
The large ones come to the CTO, who you report to directly and who'll back you when the answer is no.
Corporate security posture, endpoints, and identity sit with our IT and Corporate Engineering function, and those decisions are theirs to make.
At a company shipping this fast, a security engineer who blocks everything is worse than no security engineer.
The answer isn't to wave things through.
It's to understand the system, the business context, and the actual risk well enough to find the mitigation that keeps the velocity.
Sometimes the answer is still no, and we'd want that to come from a real read of the risk rather than a standard applied by default.
Getting engineers to adopt something matters here as much as finding the problem in the first place.
The version of this job that works has Security and Engineering solving the problem together.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, USA
Flex is building the AI-native private bank for business owners. We’re re-architecting the entire financial system for entrepreneurs—from the first dollar a business earns to how that value compounds, moves, and is ultim
, USA
Flex is building the AI-native private bank for business owners. We’re re-architecting the entire financial system for entrepreneurs—from the first dollar a business earns to how that value compounds, moves, and is ultim
, IND
Flex is the diversified manufacturing partner of choice that helps market-leading brands design, build and deliver innovative products that improve the world. A career at Flex offers the opportunity to make a difference
Chennai, IND
Coimbatore, IND
Coimbatore, IND
, USA
, USA
, IND
Chennai, IND
, GBR
Compensation: $170,000 - $230,000 a year, depending on experience, plus equity.
We're hiring our first security engineers.
Both report directly to the CTO.
We want software engineers with security as their superpower, not security specialists who occasionally write code.
The distinction matters here.
At our size, the only way one person covers a surface this large is to build things that keep working after they move on.
A findings queue you work through by hand grows faster than you can close it.
A guardrail in the deployment pipeline doesn't.
The work is product and infrastructure security: making the paths that move money hard to attack, and making the secure way to build something also the easy way.
The ledger and its write path, card issuing, payouts, and our stablecoin work are the systems that matter most.
The job runs in both directions.
You'll be in design review early on anything new, and you'll be continuously assessing what we've already shipped, because most of Flex's risk lives in code that exists today.
We don't expect you to read the codebase by hand or to keep a findings queue.
We expect you to build the automation and repeatable checks that keep assessing it for you, and to spend the time you get back on the golden paths that stop whole classes of problem from arriving again.
There's no security team above you and no CISO.
You'd set the standard here, and own the risk decisions that come with it.
Day to day, what gets fixed now, what gets mitigated, and what we knowingly accept is your call.
The large ones come to the CTO, who you report to directly and who'll back you when the answer is no.
Corporate security posture, endpoints, and identity sit with our IT and Corporate Engineering function, and those decisions are theirs to make.
At a company shipping this fast, a security engineer who blocks everything is worse than no security engineer.
The answer isn't to wave things through.
It's to understand the system, the business context, and the actual risk well enough to find the mitigation that keeps the velocity.
Sometimes the answer is still no, and we'd want that to come from a real read of the risk rather than a standard applied by default.
Getting engineers to adopt something matters here as much as finding the problem in the first place.
The version of this job that works has Security and Engineering solving the problem together.
Compensation: $170,000 - $230,000 a year, depending on experience, plus equity.
AI-native private banking platform for business owners.
Visit company websiteJobs and hiring trendsUSD 170000-230000 yearly
Full-time
Senior Level
Remote
Apply faster on company sites with our extension.