Cardless

Engineering

ProductSecurityLead

$190–260k San Francisco, California, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Lead candidates.

The Brief

“Product Security Lead at Cardless. Skills: Product security, API security, Fraud prevention. Own security model for APIs. Drive auth strategy across services”

Industry & Context.

Engineering
Problems you'll solve

Root cause analysis; Troubleshooting

What They're Looking For.

Must Have

programming skills in Java, Python, Experience designing or operating secure platform / B2B APIs, Background in anti-ATO, anti-fraud, or authentication systems, Working knowledge of AWS, Excellent written communication

Nice to Have

Fintech, payments, or other regulated environment experience, Threat modeling methodology background, Experience working alongside or building for a risk / fraud operations team, Experience operating a bug bounty or vulnerability disclosure program

What You'll Do.

Own security model for APIs

Drive auth strategy across services

Build device telemetry

Partner with Engineering on secure-by-design

Coordinate infrastructure security improvements

Be technical authority on payment data

Lead incident response

Drive vulnerability remediation

Own external security partner relationship

Translate compliance frameworks into solutions

Ensure in-product controls are effective

How You'll Work.

Team & Collaboration

Cross-functional teams; Work with Engineering; Work with Risk; Work with Compliance; Work with Legal; Work with Data

Communication Scope

Written communication; Partner-facing responses

Process & Methodology

Roadmap planning

Full Job Description

Cardless is the infrastructure that lets consumer brands put credit cards directly in their own product. Instead of sending customers off to a bank's website to manage their card, our platform handles the credit program end-to-end (applications, underwriting, servicing, rewards, compliance), so brands can build the card experience inside their own ecosystem. We power programs for Coinbase, Bilt, Qatar Airways, Alibaba, and others. We've raised $170M to date, most recently a $60M Series C led by Spark Capital. We're hiring a Product Security Lead to drive how we build security into the platform. The work spans authentication, authorization, anti-abuse controls, in-product fraud primitives, and the secure-by-design practices that come with running credit infrastructure for partners of this caliber. The role is hands-on and deeply cross-functional, working with Engineering, Risk, Compliance, Legal, and Data. You'll report to the Head of Engineering. RESPONSIBILITIES - Own the security model for our partner-facing APIs: authentication, authorization, tenant isolation, abuse prevention, signing, and audit logging. - Drive a coherent auth strategy across services and surfaces, including step-up auth for sensitive actions and a strong-auth roadmap (passkeys and beyond). - Build the device telemetry, behavioral signals, and velocity primitives that fraud and risk functions depend on. - Be the secure-by-design partner with Engineering — sit in on architecture reviews before features ship, write the threat models, own the tradeoffs. - Own secure SDLC: SAST/DAST, dependency scanning, secret detection, and the security tooling engineers interact with daily. - Coordinate with our infrastructure team to improve our security posture across the stack: from infrastructure, to supply chain, to first-party applications, to third-party dependencies and SaaS platforms. - Be the technical authority on sensitive payment data. Keep the footprint small and well-defined as the platform grows

Free ATS check

Applying for this Product Security Lead role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Cardless?

Real rants from real employees. Read before you apply.

Read Company Rants →