You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Be the first to open itNo views yet
Valon

Senior Security Engineer, Threat & Offensive Security

  • Remote
  • 6+ years

Salary

$180,000 - 230,000/ year

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing.

We're a Series C company backed by a16z, transforming industries that others have written off as too complex to innovate.

Rather than build on top of broken legacy systems, we took a different approach: we built and operate our own mortgage servicing business managing $110+ billion in loans. This wasn't the end goal, it was how we deeply understood the complexity needed to build software that actually works in regulated industries.

The results speak for themselves. We've transformed mortgage servicing from a 0% margin business into 60%+ margins while dramatically improving customer experience. Major enterprise contracts are now deploying across the industry.

ValonOS is our unified platform that makes every process structured and programmable and it is perfectly positioned for the AI era. When everything flows through one system with rich data, AI agents don't just automate tasks, they continuously improve entire operations. Mortgage servicing is just the beginning of our vision to transform regulated industries and beyond.

Security at Valon

Our customers entrust us with some of their most sensitive and personal financial information, and it is the ultimate mission of Valon’s Security team to ensure we have sound programs, processes, and automation in place to safeguard our customers’ data. The Security team protects the infrastructure and data for processing billions of dollars of mortgage loans.

In addition to protecting Valon’s internal systems, the Security team partners closely with Product and Engineering to design and deliver secure, scalable, and trustworthy capabilities for ValonOS. We work cross-functionally across all teams at Valon to enable security throughout the organization. We engage with external security auditors, pentesting firms, and partners to continuously evaluate Valon’s security posture.

Valon offices are located in New York City and San Francisco, but we fully support remote work!

About the Role

We are seeking an experienced and skilled Senior Security Engineer, Threat & Offensive Security to join our growing team! As a key security member at Valon, you will help scale and strengthen our offensive security and threat operations, proactively identifying weaknesses in our systems, networks, and applications as the company continues to grow.

This position requires a deep understanding of adversarial techniques, security testing methodologies, threat intelligence, and incident response, along with the ability to collaborate with cross-functional teams. Importantly, this role requires an AI and automation-first approach to security work, using modern tools to scale testing, threat management, and response. You will help ensure security is embedded across our environment and that we continue to safeguard our most critical assets and maintain the trust of our customers and stakeholders.

Responsibilities

  • Drive and conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities
  • Manage and implement security testing tools and frameworks to simulate real-world attacks and validate the effectiveness of existing security controls
  • Design and implement AI-enabled workflows to scale security testing and threat related operations.
  • Manage and operationalize threat intelligence to anticipate emerging threats and adjust defenses proactively
  • Partner with external pentesting firms for periodic, independent reviews
  • Perform security reviews of new systems, features, architectures, and third-party integrations, providing actionable risk-based recommendations
  • Collaborate with Engineering, IT, Product and other teams to remediate identified vulnerabilities and strengthen security controls
  • Develop and refine playbooks, procedures, and standards for offensive security testing, threat monitoring, and incident response
  • Monitor and manage security alerts and incidents, analyze data, and respond to security events
  • Support operational activities including general security reviews, security monitoring, vendor security, issue remediation, security awareness, audit/compliance, and other processes
  • Ideal Background
  • Proven experience in security engineering, red team, or threat management role, with a focus on penetration testing, security testing, threat intelligence, and/or incident response
  • Hands-on experience with security testing tools and frameworks (e.g., Burp Suite, Metasploit, Nmap, Cobalt Strike, or similar)
  • Demonstrated experience leveraging AI and automation to improve the efficiency and scalability of threat detection, testing, and response operations
  • Proficient in both manual and automated testing techniques, understanding when manual analysis is needed versus pure automated testing
  • Strong understanding of common attack techniques, exploitation methods, and MITRE ATT&CK or related
  • Experience with SIEM, EDR, and other detection/monitoring platforms
  • Experience with cloud security and environments (GCP, AWS)
  • Ability to work autonomously, lead projects, and navigate complex, ambiguous security investigations
  • Ability to foster strong relationships and partner with stakeholders to drive remediation and results
  • Excellent communication and collaboration skills, with the ability to explain technical findings and risk to both technical and non-technical stakeholders
  • Applied knowledge of industry security and testing frameworks (OWASP, NIST, MITRE ATT&CK, CIS, SOC 2/ISO 27001 concepts)
  • Experience or exposure to startup environments is a plus
  • Minimum Qualifications
  • Minimum of 5 years in a security engineering, penetration testing, threat intelligence, or similar roles with relevant responsibilities and background
  • Bachelor's degree in Computer Science, Information Security, Technology, or a related field
  • Relevant security certifications (e.g., CISSP, CEH, OSCP, GPEN, GCIH or similar)
  • Knowledge of cloud environments
  • Experience with security testing, monitoring, and response technologies (threat intelligence platforms, vulnerability scanners, SIEM, EDR, or similar)

Benefits

  • Base Compensation Band: $180K - 230K. Base salary offered is determined by a number of factors including the candidate’s experience, qualifications, and skills
  • This Base Compensation pay range applies to our New York City located staff and may differ according to location.
  • Compensation: Competitive salary with a meaningful stake in the company via equity, and 401k plan
  • Health & well-being: We’ll invest in your physical and mental well-being with comprehensive medical, dental, & vision benefits
  • Commuter benefits: We offer pre-tax deductions for public transportation, rideshare services, and parking expenses to make your commute more affordable and convenient
  • Grow together: Company wide orientation for you to successfully onboard and other learning & development opportunities including regular review cycles that feature 360 degree feedback
  • Play together: Quarterly budgets for team and company outings. Use it for team swag, cooking classes, or team dinners!
  • Generous time off: Flexible paid time off, sick days, and 11 company holidays
  • Baby bonding time: 12 weeks off for both birthing and non-birthing parents - fully paid so you can focus your energy on your newest addition
  • Throughout the interview process, please remember that emails will only be from valon.com email addresses. We will never ask for any personally identifiable information during the interview process itself. Please reach out to talent@valon.com if you have any requests to verify the authenticity of an outreach.
  • Valon is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws. Valon makes hiring decisions based solely on qualifications, merit, and business needs at the time.

Where you’d work

Fully remote

You can work from

  • United States

About the company

Valon

  • Industry: FinTech

Also hiring in New York, United States and San Francisco, United States

3 of their 9 open roles are remote

Your chances

Worth a look before you spend an evening tailoring a CV for it.

  • 21 checks run
  • 3 red flags

Still hiring?

14 checks

2 red flags

How crowded?

7 checks

1 red flag

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details13 facts · Role, Location, Compensation, Employment, Company
Tech stack
  • AWS
Seniority
Senior
Type
Full-time
Equity
Equity offered
Industry
FinTech
Specialty
Security
Show 7 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Seniority
Senior
Experience
5+ years
Tech stack
  • AWS

Location

Work model
Remote
Region
United States
Remote from
  • United States

Compensation

Salary
$180,000 - 230,000 / year
Pay period
Annual
Equity
Equity offered

Employment

Type
Full-time

Company

Industry
FinTech

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason