Senior Software Engineer, Security - R12269
ABOUT OPORTUN
Oportun (Nasdaq: OPRT) is a mission-driven fintech that puts its 2.0 million members' financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $16.6 billion in responsible and affordable credit, saved its members more than $2.4 billion in interest and fees, and helped its members save an average of more than $1,800 annually. Oportun has been certified as a Community Development Financial Institution (CDFI) since 2009.
WORKING AT OPORTUN
Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization's performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups.
POSITION OVERVIEW
The mission for the Engineering Ecosystem Org at Oportun is to be the force-multiplicative Org that empowers engineers to deliver member value with high-speed and high-quality. The Security Engineering Team plays a vital role in designing, developing, and maintaining cutting-edge software solutions that power our mission and advance our business. We strike a balance between leveraging leading tools and developing in-house solutions to create member experiences that empower their financial independence. The engineers in this group are strong Backend Developers, well versed with Security technologies and lead from the front to improve the security posture of the company.
As a Senior Software Engineer, Security at Oportun, you will be a key member of our Security Engineering team, responsible for designing, developing, and maintaining large-scale, high-throughput foundational security services and libraries such as Authentication, Authorization, Encryption, Tokenization etc. You will also own automating Security Pipelines that bring improved observability into the security posture of the company. In addition, you will own driving down Security Vulnerabilities and subsequently keeping that number low. You will innovate and think out of the box to help improve the security posture of the company. You will conduct Threat Modeling reviews - both Application and Operational to identify threats that we can then mitigate.
RESPONSIBILITIES
- (re)Design, Build and maintain large-scale, high-throughput foundational security services and libraries such as Authentication, Authorization, Encryption, Tokenization, Entitlements
- Perform Application and Operational threat modeling.
- Security code review.
- Improve observability into the Security Posture of the company.
- Use the improved observability to improve the Security Posture of the company.
- Drive and Mitigate Security Vulnerabilities in code and infrastructure.
- Be the voice of Security as a first principle in the Software Development Lifecycle.
- Partner with engineering teams to integrate mitigation controls into continuous integration, delivery and deployment processes.
- Implement security architecture, methods, and controls required to meet security, compliance, and audit requirements.
REQUIREMENTS
- Master’s degree in Computer Science, Information Assurance/Security, Cyber Security, Computer Engineering, Electrical Engineering, a related field, or a foreign equivalent.
- 6 years of experience in the job offered or related occupation.
- 4+ years of experience building large scale distributed services.
- 2+ years of experience in software security architecture and design review, Threat Modeling, Security Code Review, SDLC, best practices and mitigations for application security.
We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.
California applicants can find a copy of Oportun's CCPA Notice here: https://oportun.com/privacy/california-privacy-notice/.
We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI’s Internet Crime Complaint Center (IC3).
Apply for this job
*
indicates a required field