Still hiring?
14 checksNo red flags
Browse
All Tech JobsThe whole board, newest first.Roles That Fit MeAnswer a few questions, see your matches.Early WindowFound before the big boards.Direct ApplyStraight to the manager, past the ATS.By specialty
Your materials
CV AnalyzerWhat an ATS sees, and what to fix.Tailor CVBrought in line with one posting.Cover LetterWritten from your CV and the role.You and the process
Hey, I’m Wayjo. I find roles before the big boards.
Free to browse. An account unlocks the rest.
Jobs
All Tech JobsThe whole board, newest first.Roles That Fit MeAnswer a few questions, see your matches.Early WindowFound before the big boards.Direct ApplyStraight to the manager, past the ATS.$163,000 - 206,000/ year
The whole posting in a few lines. Sign up to read it here and on every role you open.
Sign Up to ReadAlloy is where you belong!
Alloy is the AI-powered identity and fraud prevention platform that accelerates onboarding, stops fraud, and scales compliance across the customer lifecycle so financial organizations can grow without limits. More than 900 of the world's leading financial institutions and fintechs trust Alloy for smarter risk management that drives growth.
Through our values: Be Bold, Go Fast, Collaborate, and Celebrate Our Differences, we are creating a workplace where you can grow, thrive, and belong. See how we’ve been continuously recognized and named one of Inc. Magazine’s Best Workplaces , Forbes America’s Best Startup Employers , Best Fintech to Work for by American Banker , year after year.
Check out our investors and read more about us here .
Product Security covers application security and cloud security at Alloy. Our customers are banks and fintechs, so the state of our security program is not an internal matter. It shows up in client due diligence, in what we can sell, and in whether deals close. The team is small and the program is still being matured, which means the person in this seat shapes how engineering across the company designs and ships infrastructure rather than inheriting someone else's finished playbook.
Alloy operates in a hybrid-work environment. We look to foster collaboration and community by having our local employees onsite three days a week.
What you'll be doing
You'll own the security of Alloy's AWS environment and the tooling that keeps it visible. You will work closest with the Infrastructure team, but your reach will extend to every engineering team.
Partner with the Infrastructure team to build security into new cloud infrastructure as it is designed, and act as the security point of contact for new builds
Lead initiatives you scope yourself to reduce cloud infrastructure risk in ways that are repeatable and maintainable
Build alerts, detections, and dashboards in our CSPM and SIEM, and write the runbooks that make them actionable for the people who get paged
Own CSPM findings end to end, from triage through remediation, including the Terraform changes that fix the problem at its source
Drive AWS permissions and network design toward least privilege, and debug both without widening the attack surface in the process
Join the on-call rotation, investigate security incidents to root cause, and put controls in place so the same incident does not recur
Who we’re looking for
Hybrid, 3 days a week in the office
Alloy
Office in New York City, United States
1 of their 3 open roles is remote
We've checked whether it's still hiring and how crowded it is.
Still hiring?
14 checksNo red flags
How crowded?
7 checksNo red flags
How well does this role fit you?
Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.
Something wrong with this vacancy?