Software Engineer Security
Modern Treasury is a payment operations platform that provides a unified API for businesses to move money via ACH, wire, RTP, FedNow, and stablecoins with built-in compliance and ledgering.
Projects
About Modern Treasury
Modern Treasury provides infrastructure for companies building payment products, offering a unified API across ACH, wire, RTP, FedNow, and stablecoin rails. Users can initiate and track payments, maintain accurate balances through a real-time double-entry ledger, and automate reconciliation. The platform supports both an integrated PSP model for rapid onboarding and direct bank partnerships as companies grow to larger transaction volumes.
Skills
About the Role
You will lead application, product, and infrastructure security for payment systems. You will review code, conduct threat modeling, design security architecture, and automate security controls across CI/CD and infrastructure. You will manage vulnerabilities, support compliance controls and audits, improve monitoring and remediation, and help secure APIs, authentication, encryption, payment rails, and third-party integrations.
Requirements
- 6+ years of security engineering experience, including 3+ years focused on application and product security.
- Experience with full-stack application security across frontend, backend, and APIs.
- Experience with authentication, authorization, and identity management.
- Experience with AWS, Docker, CI/CD pipelines, and security-related infrastructure automation.
- Experience with fraud detection, prevention, and abuse mitigation in payment or financial products.
- Knowledge of secure SDLC practices and developer security tooling.
- Experience with incident response and security monitoring.
- Knowledge of application security for Ruby on Rails, GraphQL, JavaScript, React, and containerized environments.
- Payments engineering experience, ideally involving fraud prevention and risk controls in money-movement systems.
Responsibilities
- Lead application security, including secure code review, threat modeling, and security architecture for new products.
- Own product security for new payment rails, including FBO account structures, stablecoin integration, and compliance features.
- Design and implement DevSecOps tooling and automation across CI/CD and infrastructure.
- Partner with engineering teams to embed security into the development lifecycle.
- Drive security architecture decisions for APIs, authentication systems, and data-protection controls.
- Build monitoring and detection capabilities for application-layer threats, API abuse, and fraud patterns.
- Design infrastructure monitoring, automation, and remediation practices.
- Own and operate SOC 2 controls and supporting evidence.
- Serve as technical owner for security controls and automated tests in Vanta.
- Coordinate external penetration testing and drive remediation findings to closure.
- Own vulnerability management across applications and infrastructure.
- Design and operate encryption and key-management practices, including key lifecycle and rotation.
- Evaluate and secure enterprise integrations, AI capabilities, and third-party tools.
- Influence technical strategy on security and risk management.
Benefits
- Equity
- Generous benefits
