Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Product Security Engineer image - Rise Careers
Job details

Product Security Engineer

About OnePay

OnePay is a consumer financial services app with an exceedingly simple mission: to help people achieve financial progress.

Tens of millions of Americans today are unbanked or underbanked, meaning they don’t have enough money in savings to cover a minor emergency. They pay too much in fees, don’t have access to credit at affordable rates, and have little ability to grow their wealth. OnePay’s vision is to create a single app for consumers to save, spend, borrow, and grow their money, bringing our mission to life with simple and accessible banking, credit, and payments products that deliver a best-in-class experience to millions of customers. Our products include:

  • Checking and high-yield savings accounts

  • Domestic and international peer-to-peer payments

  • Credit Builder and credit score monitoring

  • Digital wallet / contactless payment solutions

  • Buy-now-pay-later installment loans at Walmart

Why do we have a right to win? We have the backing of Walmart (a Fortune 1) and Ribbit Capital (a preeminent fintech investor), are deeply embedded with the distribution of the world’s largest omnichannel retailer, and have an industry-leading multi-product value proposition — all in addition to having some of the best people and talent in the industry.

There’s never been a better time to build a category-defining business and there has rarely been a team better positioned for the opportunity. Join us!

The role

As a Product Security Engineer, you'll be responsible for ensuring that OnePay delivers secure and reliable applications at scale. By partnering with engineers to build security into the product from the ground up, you’ll be creating engineering tools and workflows that test and validate artifacts and actively developing security frameworks.   You’ll provide subject-matter expertise to product teams regarding security best practices, optimize our secure coding practices, and use offensive security techniques to harden our environment and help improve our overall security posture. Come be the champion of modern Product Security Engineering at OnePay and have a direct impact on the security of all of our products!

This role is responsible for:

  • Architecting and implementing secure AWS configurations, including IAM policies, encryption, and network segmentation.

  • Securing CI/CD pipelines and code repositories, integrating policy-as-code tools to enforce security standards.

  • Enhancing container and orchestration security (Docker, Kubernetes, EKS) to ensure safe and reliable production environments.

  • Conducting threat modeling exercises to identify and addressing risks in early stages of development.

  • Performing secure code reviews, leveraging SAST/SCA tools, and guiding remediation with development teams.

  • Automating routine security tasks using scripting languages, improving efficiency and accuracy.

  • Developing, maintaining, and extending our in-house application security and penetration testing automated testing framework.

  • Working with the Security and other engineering teams to maintain a security architecture that provides security controls throughout all platforms to mitigate risk, and to meet goals and regulatory requirements.

You bring

  • 10+ years of experience in security engineering, DevSecOps, and application development.

  • Excellent knowledge of the CVSS, MITRE ATT&CK, and OWASP Top 10.

  • Practical understanding of AWS and its core services (VPC, EC2, RDS).

  • Hands-on experience securing IaC and CI/CD pipelines, including code scanning and policy enforcement tools.

  • Strong knowledge of container security best practices and orchestration platforms.

  • Practical experience in application security, including threat modeling, secure code review, and penetration testing.

  • Familiarity with detection engineer, SIEM tuning, and scripting automation.

  • Demonstrated experience in modern application architecture and deployment practices.

  • Expertise in verifying and measuring common security vulnerabilities, and demonstrated ability to communicate these concepts to technical and non-technical partners.

  • Experience defining security architecture patterns and standards.

  • Preferably, understanding of regulatory compliance concerns (GLBA, CCPA, PCI).

  • The Triple H Factor: Humble, Hungry and Honest.

What We Offer

  • Competitive base salary, stock options, and health benefits from Day 1

  • 401(k) plan with company match

  • Remote-friendly (US), flexible time off (FTO), and opportunities for growth

  • A high-growth, mission-driven, inclusive culture where your work has real impact

Pay Transparency

The estimated annual base salary for this position ranges from $170,000 to $210,000. Pay is generally based upon the level, complexity, responsibility, location and job duties / requirements of the specific position. We then source candidates with the requisite skills, expertise, education, training, and experience.  If you are selected for an interview, please feel welcome to speak to a Talent Partner about our compensation philosophy and other available benefits.

Standard Interview Process

  • Initial Interview with Talent Partner

  • Technical or Hiring Manager Interview

  • Team Interview

  • Executive Interview

  • Offer!

Equal Employment Opportunity

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.

Average salary estimate

$190000 / YEARLY (est.)
min
max
$170000K
$210000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Product Security Engineer, OnePay

Join OnePay as a Product Security Engineer, where you'll make a difference in the financial lives of millions. At OnePay, we're on a mission to help people achieve financial progress by creating a seamless consumer financial services app. In this role, you'll be at the forefront of our security efforts, ensuring that our product is not just user-friendly but also secure and reliable. By collaborating with our talented engineering team, you'll be designing tools and workflows that enforce security measures right from the start. You’ll also play a critical part in enhancing our AWS configurations and securing CI/CD pipelines to uphold our commitment to safety. Your expertise in security best practices will guide our product teams as we innovate in areas like peer-to-peer payments and sustainable credit solutions. Furthermore, you'll take the lead on creating automated security testing frameworks and conducting thorough secure code reviews. The challenges are exciting, and your contributions will directly impact our security posture and the user experience of our diverse array of financial products. If you’re passionate about integrating security with product development, OnePay is the place for you. Join us in transforming how consumers manage their finances while ensuring their information is secure!

Frequently Asked Questions (FAQs) for Product Security Engineer Role at OnePay
What are the primary responsibilities of a Product Security Engineer at OnePay?

As a Product Security Engineer at OnePay, you'll be responsible for architecting secure AWS configurations, enhancing CI/CD pipelines, and ensuring container and orchestration security. Additionally, you'll conduct threat modeling, perform secure code reviews, and automate security tasks using scripting languages to maintain our high standards of security throughout our platforms.

Join Rise to see the full answer
What qualifications are required for a Product Security Engineer at OnePay?

OnePay requires candidates for the Product Security Engineer position to have over 10 years of experience in security engineering and application development. A deep understanding of security frameworks like OWASP and practical knowledge in AWS services and container security is essential. Experience in threat modeling and secure coding practices is highly valued.

Join Rise to see the full answer
What does the working culture look like for a Product Security Engineer at OnePay?

At OnePay, you'll be part of an inclusive and mission-driven culture that values diverse perspectives. We promote a flexible work environment with opportunities for growth, ensuring that your contributions as a Product Security Engineer translate into real-world impact like financial empowerment for our users.

Join Rise to see the full answer
How does OnePay support the continuous learning of a Product Security Engineer?

OnePay is committed to the continuous professional development of its employees, including Product Security Engineers. We provide access to various training resources, workshops, and opportunities for team collaboration to stay abreast of the latest security trends and best practices in the financial technology sector.

Join Rise to see the full answer
What is the estimated salary range for a Product Security Engineer at OnePay?

The estimated salary range for a Product Security Engineer at OnePay is between $170,000 and $210,000 annually. This compensation reflects the level of expertise, complexity of the role, and the experience required. We encourage candidates to discuss compensation openly with our Talent Partners during the interview process.

Join Rise to see the full answer
Common Interview Questions for Product Security Engineer
Can you explain your experience with securing AWS environments as a Product Security Engineer?

When answering this question, elaborate on your specific hands-on experience with AWS services, such as IAM policies and encryption methods. Highlight any previous projects where you implemented security best practices in AWS and discuss the results or improvements that stemmed from your efforts.

Join Rise to see the full answer
What tools do you use for secure code reviews?

Discuss the various Static Application Security Testing (SAST) tools you have utilized, such as SonarQube or Checkmarx. Provide examples of how you integrated these tools into the development lifecycle and the metrics you used to gauge their effectiveness.

Join Rise to see the full answer
Describe a challenging security incident you managed in a previous role.

Frame your response by outlining the incident, the steps you took to investigate, and the ultimate resolution. Focus on how you collaborated with cross-functional teams to mitigate risks and prevent future occurrences. Explain what lessons were learned and how they influenced your security practices.

Join Rise to see the full answer
How do you approach threat modeling?

Explain your systematic approach to threat modeling, including specific frameworks or methodologies you follow. Discuss how you facilitate brainstorming sessions, identify potential threats, and develop strategies to mitigate risks throughout the software development process.

Join Rise to see the full answer
What are some best practices for improving container security?

Highlight your knowledge of container security best practices, such as image scanning, least privilege principles, and regular updates. Provide examples of how you’ve implemented these practices in past roles to enhance overall security in containerized environments.

Join Rise to see the full answer
How would you ensure secure CI/CD pipelines?

Discuss your experiences with integrating security tools into CI/CD processes, like incorporating SAST and DAST, and using policy-as-code tools for compliance checks. Explain the importance of automation and continuous monitoring in maintaining a secure pipeline.

Join Rise to see the full answer
What is your experience with automation in security tasks?

Share examples of how you have automated security tasks using scripting languages. Discuss specific tools or practices you have implemented to improve the efficiency of routine operations, and the impact these automations had on your team's productivity and error reduction.

Join Rise to see the full answer
What metrics do you believe are important to track for security posture?

Talk about the relevant metrics such as mean time to detect (MTTD) and mean time to respond (MTTR). Explain the significance of these metrics in creating actionable insights for improving security measures and maintaining compliance.

Join Rise to see the full answer
How do you ensure that your security recommendations are understood by non-technical partners?

Share techniques you employ to communicate complex security concepts clearly and concisely. This may include using visual aids, analogies, or tailoring the conversation based on your audience's background and knowledge level.

Join Rise to see the full answer
Why do you want to work as a Product Security Engineer at OnePay?

Articulate your passion for enhancing security in financial services and how your personal values align with OnePay’s mission to empower consumers financially. Share specific reasons why OnePay's approach and goals resonate with you, creating a compelling case for your fit within the team.

Join Rise to see the full answer
Similar Jobs
OnePay Remote No location specified
Posted 8 days ago
OnePay Remote No location specified
Posted 8 days ago
Photo of the Rise User
Posted 6 days ago
Vortexa Remote No location specified
Posted 11 days ago
Oura Remote No location specified
Posted 7 days ago
Photo of the Rise User
Mission Driven
Social Impact Driven
Passion for Exploration
Reward & Recognition
Photo of the Rise User
Posted 9 days ago
MATCH
VIEW MATCH
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
March 22, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Columbus just viewed Store Manager - New Store Opening at Curaleaf
S
Someone from OH, Dayton just viewed Senior Director, Employee Engagement at Scout Motors
Photo of the Rise User
Someone from OH, Akron just viewed Finance Intern - Summer 2025 at Spectrum
Photo of the Rise User
Someone from OH, Norwalk just viewed Hybrid Account Manager-Commercial Lines at AssuredPartners
Photo of the Rise User
Someone from OH, Loveland just viewed Animator at Apex Systems Bellevue, WA at Apex Systems
Photo of the Rise User
Someone from OH, Canton just viewed Lead Jr. Toddler Teacher at All Around Children
Photo of the Rise User
Someone from OH, Mentor just viewed Site Merchandising Manager at Lovepop
Photo of the Rise User
Someone from OH, Batavia just viewed Restaurant Busser at Outback Steakhouse
Photo of the Rise User
67 people applied to Electrical Apprentice at Aerotek
Photo of the Rise User
Someone from OH, New Albany just viewed Customer Success Manager at Quisitive
Photo of the Rise User
Someone from OH, Columbus just viewed UGC Creator - USA, Female 40-50 - Contract to hire at Upwork
Photo of the Rise User
Someone from OH, Strongsville just viewed Automotive Buyer at Sonic Automotive
Photo of the Rise User
Someone from OH, Strongsville just viewed Experienced Automotive Buyer at Sonic Automotive
Photo of the Rise User
8 people applied to Assembly Mechanic at Boeing
Photo of the Rise User
Someone from OH, Columbus just viewed Business Systems Analyst, Apps & Automations at Deel
Photo of the Rise User
Someone from OH, Findlay just viewed Marketing Analyst at ITW
R
Someone from OH, Cleveland just viewed Marketing Lead at Redi.Health
Photo of the Rise User
Someone from OH, Cleveland just viewed Associate Conversion Data Analyst at Bloomerang
Photo of the Rise User
Someone from OH, Cleveland just viewed Material Buyer/Planner at Aston Carter
F
Someone from OH, Cleveland just viewed Senior Materials Planner at Fortune Brands
Photo of the Rise User
Someone from OH, Cleveland just viewed Junior Data Analyst at Arkana Laboratories
Photo of the Rise User
Someone from OH, Cleveland just viewed BI Analyst, Junior at Emi Labs