Principal Software Engineer, Product Security
Boost your chances before you apply.
SentiLink
US
Summary
Lead and elevate security across infrastructure, applications, and internal systems by building scalable security foundations and internal tooling. Partner with cross-functional teams to improve detection, response, and cloud security posture while reducing organizational risk.
Job Description
SentiLink stops more than 150,000 fraud attempts and verifies more than 3 million identities every day to protect both institutions and consumers. The problems we work on are challenging, and solving them takes deep domain expertise, rigorous analysis, and a willingness to dig into the details.
At SentiLink, you'll work alongside smart, highly collaborative colleagues who respect each other's time and judgment, take ownership, and follow through on their commitments. Together, we do truly meaningful work protecting the identities of innocent consumers and flagging the fraudsters attempting to exploit them.
We're well capitalized and growing quickly. We already serve 13 of the top 15 U.S. banks, we're expanding into new markets, and we're backed by Craft Ventures, Andreessen Horowitz, NYCA, and Max Levchin. We've been named to the Forbes Fintech 50 and as a 2026 FICO Industry Vanguard Decision Award Winner. We were also the first company to go live with the electronic Consent Based Social Security Number Verification (eCBSV) service, and we've testified before the U.S. Congress on the future of identity.
We want SentiLink to be the best place you've ever worked. We offer generous benefits and support a range of working arrangements, from fully remote to in-office. We are a digital-first company with strong collaboration across the U.S. and India, and we meet in person regularly to build relationships. We have offices in Austin, San Francisco, New York City, Seattle (Bellevue), Los Angeles, and Chicago in the U.S., and in Gurugram (Delhi) and Bengaluru in India.
Role:
We’re looking for a Principal Software Engineer, Product Security to lead and elevate security across SentiLink’s infrastructure, applications, and internal systems. This is a highly technical, hands-on role focused on building scalable security foundations while enabling the business to move quickly and safely.
You will partner closely with Engineering, Infrastructure, Product, Legal, and Compliance teams to design secure systems, improve detection and response capabilities, strengthen cloud security posture, and reduce organizational risk. You’ll help shape long-term security strategy while remaining deeply involved in technical implementation and operational execution.
This role is best suited for someone who combines strong technical depth with practical judgment and thrives in fast-moving, high-ownership environments.
Responsibilities:
-
Design and build internal security tooling from scratch, including agent-based security tooling, code analysis tooling, dynamic scanning, and security assessment tools
-
Identify vulnerabilities across SentiLink's AWS-based stack, including application code, cloud service configurations, and integrations between the two
-
Develop AI-assisted and agent-based tooling to scale offensive security testing beyond what a small team can do manually
-
Build and maintain security automation that improves detection, response, and remediation across the organization
-
Conduct hands-on penetration testing and vulnerability research against SentiLink's infrastructure and applications
-
Partner with engineering teams to remediate findings and embed security into the development process without slowing them down
-
Participate in the security on-call rotation, including incident response and regular response testing
-
Contribute to threat modeling and security design reviews for new systems, with a focus on cloud integrations and identity flows
-
Stay current on offensive security techniques, AI-assisted security tooling, and emerging attack patterns relevant to fintech and identity verification
Requirements:
-
8+ years of experience in security engineering, software engineering with a security focus, or closely related roles
-
Proficient in at least one systems language (Go, Rust, C++) and at least one higher-level language (Python, TypeScript)
-
Proven ability to design and ship production software end-to-end
-
Deep AWS infrastructure expertise, including IAM, EKS, RDS, networking, and managed services
-
Demonstrated ability to identify security misconfigurations and vulnerabilities across cloud architectures, application code, and the integrations between them
-
Experience conducting or building tooling for penetration testing, vulnerability assessment, or red team activities
-
Track record of building security automation and tooling from scratch
-
Comfortable operating independently on ambiguous problems without heavy process or oversight
-
Strong communication skills and the ability to partner with engineers who are not security specialists
Nice to have:
-
Experience building or deploying LLM-based agents or AI-assisted security tooling
-
Prior experience at a security product company (Wiz, Snyk, Datadog, etc.) or other security-forward engineering org
-
Prior fintech, identity, or fraud detection experience
-
Industry certifications (OSCP, OSCE, GPEN, GXPN)
-
Experience with detection engineering or SIEM platforms
-
Published security research, CVEs, or open source security tooling contributions
-
Experience supporting compliance frameworks (FedRAMP, SOC 2, PCI DSS) without it being their primary focus
Compensation:
$220k-280k/year + equity + benefits
Perks:
-
Employer paid group health insurance for you and your dependents
-
401(k) plan with employer match (or equivalent for non US-based roles)
-
Flexible paid time off
-
Regular company-wide in-person events
-
Home office stipend, and more!
Corporate Values:
-
Follow Through
-
Deep Understanding
-
Whatever It Takes
-
Do Something Smart
SentiLink, the leading provider of innovative identity and risk solutions, empowers institutions and individuals to transact confidently with one another by preventing synthetic fraud, identity theft, and emerging forms of first party fraud at the point of account application. Its solutions enable these secure transactions by leveraging a deep understanding of identity and risk, and are informed by machine learning models and insights from a team of top risk analysts. SentiLink proudly serves a broad array of financial institutions, from the largest U.S. banks to leading credit unions and fintech unicorns to help stop fraud at account opening and beyond. Headquartered in San Francisco, the company was founded in 2017 by Naftali Harris and Max Blumenfeld and it has raised $85M to date from investors including Andreessen Horowitz, Craft Ventures, and NYCA Partners, among others.
Founded
2017
Company size
51-200 employees
Industry
Software Development
Org type
Privately Held
Headquarters
San Francisco, California
SentiLink, the leading provider of innovative identity and risk solutions, empowers institutions and individuals to transact confidently with one another by preventing synthetic fraud, identity theft, and emerging forms of first party fraud at the point of account application. Its solutions enable these secure transactions by leveraging a deep understanding of identity and risk, and are informed by machine learning models and insights from a team of top risk analysts. SentiLink proudly serves a broad array of financial institutions, from the largest U.S. banks to leading credit unions and fintech unicorns to help stop fraud at account opening and beyond. Headquartered in San Francisco, the company was founded in 2017 by Naftali Harris and Max Blumenfeld and it has raised $85M to date from investors including Andreessen Horowitz, Craft Ventures, and NYCA Partners, among others.
Founded
2017
Company size
51-200 employees
Industry
Software Development
Org type
Privately Held
Headquarters
San Francisco, California