Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Security Engineer

$190k - $230k

Benepass

About Us

At Benepass we're making benefits easy. We believe people are the most important asset to any company. Traditional one-size-fits-all benefits packages no longer cut it in today's hybrid and remote-first environment. With Benepass, companies can tailor their benefits to the unique needs of their workforce.

Through our easy-to-use and highly customizable fintech platform, People teams can implement, administer, and track the benefits that meet employees where they are. Employers design their benefits and perks plan by setting a contribution amount and eligible spend categories. Every employee has their own individual definition of wellness and needs different things to help them be their most productive, fulfilled self.

Our Mission

Helping companies reimagine how companies take care of their people.

Our Investors

We are backed by leading investors, including Centana Growth Partners, Portage Ventures, Threshold Ventures, Gradient Ventures, Workday Ventures, and Clocktower Technology Ventures. To date, the company has raised approximately $75 million in equity capital.

Articles
  • Founder Story - Jaclyn Chen
  • Benepass Raises $40M Series B
Candidate Resources
  • Benepass | Candidate Resource Page
  • Benepass Listed on Inc. Magazine's Best Workplaces of 2023
Team & Role

As a Lead Security Engineer at Benepass, you will build, operationalize, and scale the security engineering practices that protect our benefits platform and the sensitive employee, benefits, and financial data it processes. You will work across application security, cloud security, security architecture, supply chain security, detection engineering, and vulnerability management, balancing security depth with the speed and pragmatism required at Benepass.

Reporting to the Head of Infosec & GRC, you will be a senior individual contributor and technical lead with broad influence across Engineering, Product, Platform, and Compliance. You will partner deeply with the teams building our web and mobile applications, backend services, system integrations, card and banking workflows, infrastructure as code, and data platforms to turn risk reduction into scalable guardrails, automated controls, and clear engineering guidance.

You are a builder and security partner at heart - someone who can set direction and mature security capabilities. You know when to introduce strong standards, when to ship incremental improvements, and how to make secure paths the easiest paths for engineers without turning security into a centralized approval queue.

Role Location & Travel

This remote role is based in the United States or Canada. You will be expected to attend company-wide on-site events three to four times per year, as well as occasional on-site office travel as necessary.

About You
  • Security Engineering Technical Lead: You have operated as a senior IC or technical lead for security engineering work, setting strategy while staying hands-on with design reviews, code, automation, tooling, and operational follow-through.
  • Application Security Builder: Deep experience with secure SDLC practices, shift-left security, threat modeling, API security, SAST/code scanning, CI/CD security integrations, security QA, vulnerability management, and developer-friendly security UX.
  • Cloud Security Partner: Comfortable partnering with Platform Engineering on IAM, KMS, CloudTrail, GuardDuty, Security Hub, VPC and network segmentation, WAF, Secrets Manager, RDS, S3, infrastructure-as-code security, container security, and continuous cloud posture management.
  • Security Architecture Partner: Able to reason about access control, encryption standards, certificate management, vaulting, key management, HSM/KMS-backed cryptography, secure system builds, DDoS/WAF/network design, and detection engineering in a modern SaaS environment.
  • Supply Chain Security Owner: Experienced improving dependency management, SBOM generation, artifact signing, secret scanning, third-party risk input, CI/CD hardening, and the security of build and release pipelines.
  • Program Builder: Familiar with NIST CSF 2.0 as a practical maturity framework and able to use OWASP SAMM to shape application security and engineering maturity.
  • Developer Enablement Mindset: You treat security as an engineering enablement function, building scalable guardrails, paved roads, documentation, training, security champions, and feedback loops that help teams move faster with less risk.
  • AI Security Pragmatist: You can help define secure AI tooling usage, LLM and code-assistant governance, and data protection practices for AI-enabled development workflows without blocking useful experimentation.
  • Pragmatic Risk Manager: You can balance ideal security outcomes with engineering velocity and business priorities, making clear tradeoffs and prioritizing the risks that matter most for a growing startup.
Requirements
  • Experience: 7+ years in security engineering, application security, cloud security, product security, platform security, or closely related technical security roles, ideally in a high-growth SaaS or technology company.
  • Technical Leadership: Proven ability to lead broad security engineering initiatives as a senior IC, influence cross-functional technical decisions, and move work from strategy to production implementation.
  • Application Security: Strong working knowledge of secure SDLC practices, secure design review, threat modeling, API security, code scanning, SAST, CI/CD security integrations, security testing, defect management, and vulnerability remediation workflows.
  • AWS Security: Hands-on experience with AWS-native security patterns and services, including IAM, KMS, CloudTrail, GuardDuty, Security Hub, VPC segmentation, WAF, Secrets Manager, S3/RDS encryption, infrastructure-as-code security, container orchestration security, and cloud posture management.
  • Architecture & Cryptography: Ability to guide secure system builds involving access control, encryption standards, key and certificate management, vaulting, secrets management, and managed HSM/KMS-backed cryptographic services.
  • Supply Chain & CI/CD Security: Experience hardening build, test, and deployment workflows through dependency scanning, SBOMs, artifact signing, secret scanning, CI/CD guardrails, least-privilege automation, and container security controls.
  • Security Program Maturity: Ability to use frameworks such as NIST CSF 2.0 and OWASP SAMM pragmatically to assess current state, sequence improvements, define metrics, and mature security practices iteratively.
  • Communication & Education: Clear communicator who can partner with engineering, product, platform, compliance, and business teams; write practical guidance; teach developers; and create durable security champions programs.
  • Execution Discipline: Strong judgment in prioritizing technical risk reduction, managing ambiguity, documenting decisions, and building lightweight processes that scale with the company.
Desirables
  • Experience securing fintech, benefits, payroll, payments, or other regulated SaaS platforms that process PII, financial data, HRIS data, transaction data, or customer administrative workflows.
  • Familiarity with SOC 2, HITRUST, PCI, or similar compliance and audit programs, with the ability to support evidence and control design while staying focused on technical risk reduction.
  • Experience with AWS serverless and managed-service architectures, including API Gateway, Cognito, Lambda, ECS/EKS, RDS, S3, Transfer Family, CloudFront, and event-driven security monitoring patterns.
  • Background with mobile application security for iOS and Android, including secure token handling, platform keychain/keystore patterns, OTA update risk, and mobile API abuse prevention.
  • Experience with detection-as-code, SIEM/SOAR workflows, security data pipelines, incident response automation, or measurable improvements to alert quality and response readiness.
  • Hands-on experience with Terraform, CloudFormation, CDK, policy-as-code, CSPM/CWPP tools, container image scanning, runtime security, or Kubernetes/ECS hardening.
  • Experience designing developer education, secure coding workshops, security champions programs, or other scalable practices that improve security outcomes without slowing delivery.
  • Experience defining practical governance for LLMs, AI coding assistants, prompt/data handling, model/tool approval, and sensitive data protection in AI-enabled software development workflows.
Compensation

$190,000-230,000 + Equity

Range(s) is subject to change. Benepass takes a number of factors into account when determining individual starting pay, including market comparables, interview performance, peer compensation, and years of experience.

What We Offer
  • 95% coverage of medical, dental, and vision
  • Fantastic benefits (of course ), including:
    • $250 WFH setup (one time)
    • $500/year Learning & Development Benefit
    • $150/month cell phone + internet
    • $100/month Wellness
    • $100/month Co-working and Commuter Benefit
  • We offer several team onsites a year
  • Flexible PTO

At Benepass, we are working towards reimagining how companies take care of their people. We are committed to creating an inclusive environment for all our employees and are seeking to build a team that reflects the diversity of the people we hope to serve with our revolutionary products. Benepass is proud to be an equal-opportunity employer.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Lead Security Engineer in United States vacancy
  • $175.2k - $262.8k

     ...learn more about life at Klaviyo? Visit klaviyo.com/careers to see how we empower creators to own their own destiny. As a Lead Security Engineer on the Enterprise Security team, you’ll play a central role in securing the corporate systems and platforms that Klaviyo runs... 
    Suggested

    Klaviyo

    Boston, MA
    1 day ago
  • $15.36k - $23.04k

     ...Lead Security Engineer (AI) – Product Security USA, Durham; USA, Miami; USA, Palo Alto; USA, Washington DC Nu is one of the largest digital financial platforms in the world, with more than 127 million customers across Brazil, Mexico, and Colombia. Guided by our... 
    Suggested
    Work at office
    Work from home
    Relocation package
    Flexible hours

    Nubank

    Durham, NC
    2 days ago
  • A global leader in network security is seeking a Principal Network Security Engineer (DDoS / BGP) to provide expertise in deploying security solutions. This remote role requires fluency in French and English, along with 5-8 years of experience in network engineering and... 
    Suggested
    Remote work

    M-Tech360

    Parsons, WV
    9 hours ago
  • $168k - $183k

     ...College Board - Technology -Cyber Security Operations Team Location: 1) This is a fully remote role. Candidates who live...  ...the Opportunity The College Board is seeking a Lead Offensive Security Engineer who will serve as the technical leader of our Red Team capability... 
    Suggested
    Full time
    Work at office
    Immediate start
    Remote work

    College Board

    United States
    5 days ago
  •  ...Lead Software Security Engineer As the Lead Software Security Engineer at Twelve Labs, you will be at the forefront of pioneering efforts to fortify and uphold the security and compliance standards for our cutting-edge AI models. You will play a pivotal role in devising... 
    Suggested
    Remote work

    Adapt Talent

    United States
    1 day ago
  •  ...Labcorp is seeking a Lead Network Security Engineer Palo Alto to join our team at our Durham, NC location! Location : Durham, NC. Applicants who live within 35 miles of Durham, NC location will follow a hybrid schedule. This schedule includes a minimum of three... 
    Full time
    Temporary work
    Casual work
    Internship
    Work at office
    Remote work
    Monday to Friday
    Flexible hours
    Day shift
    3 days per week

    LabCorp

    Durham, NC
    16 hours ago
  • $152k - $215k

     ...where you'll be a key part of a high-performing team delivering secure software solutions. Make a real impact as you help shape the...  ...the world's largest and most influential companies. As a Lead Security Engineer at JPMorganChase within Cybersecurity & Technology Controls... 
    Work at office

    JPMorgan Chase Bank, N.A.

    Columbus, OH
    7 days ago
  • $114.2k - $207.2k

     ...The Lead Security Engineer, working independently, will direct staff in the execution of manual activities and/or automated activities to ensure applications and projects within their portfolio meet defined quality standards. Essential Job Functions: Ensure... 
    Full time
    Temporary work
    For contractors
    Work experience placement
    For subcontractor
    Local area
    Immediate start

    Financial Industry Regulatory Authority , Inc.

    Dallas, TX
    4 days ago
  •  ...Lead Security Engineer At B&A, we foster and embrace a distinct set of values that we live by and instill in all aspects of our organization: dedication, commitment, partnership, trust, and recognition. We have incorporated these values into successful delivery... 
    Full time
    Work at office
    Local area

    Bart and Associates Inc

    Suitland, MD
    5 days ago
  • $154.05k - $278.48k

     ...Lead Security Engineer Leidos has a new and exciting opportunity for a Lead Security Engineer in our Intel Sector's Cyber & Analytics Business Area (CABA) . Our talented team is at the forefront in Security Engineering, Computer Network Operations (CNO), Mission... 
    Immediate start
    Flexible hours

    Leidos

    Annapolis, MD
    1 day ago
  • $135.2k - $181.2k

     ...Job Posting Title: Lead Security Engineer - Software Engineer Req ID: 10149285 Job Description: Department Description At Disney, we're storytellers. We make the impossible, possible. The Walt Disney Company is a world-class entertainment and... 
    Full time
    Work experience placement

    The Walt Disney Company

    Orlando, FL
    2 days ago
  •  ...This is a high-impact, hands-on security leadership role responsible for shaping and owning...  ...at global scale. You will work across engineering, DevOps, compliance, and customer-facing...  ...embedded across the SDLC and CI/CD pipelines. Lead cloud security initiatives across AWS... 
    Part time
    Remote work
    Worldwide

    Jobgether

    Richmond, VA
    5 days ago
  •  ...Title: Lead Security Encryption Engineer Wells Fargo is back in the office collaborating for fabulous outcomes. This role is in the office three days a week and a hybrid position. There is no Visa Sponsorship or Visa Transfers for this role. Join a high-impact... 
    Work experience placement
    Work at office
    Visa sponsorship
    3 days per week

    Wells Fargo

    Chandler, AZ
    2 days ago
  •  ...Lead Security Engineer This position supports Revolutional's federal customer as part of an application transformation and modernization initiative. This program is driving a large-scale transformation of systems into a data-centric, cloud-native ecosystem capable... 
    For contractors

    Harmonia | Revolutional

    McLean, VA
    2 days ago
  •  ...Job Summary As a Senior Lead AI Security Engineer in our Cybersecurity team, you will design and deliver secure artificial intelligence solutions that support critical cyber use cases. You will play a key role in shaping platform standards and governance, collaborating... 
    Work at office

    JPMorgan Chase Bank, N.A.

    Columbus, OH
    5 days ago
  •  ...Lead Security Engineer Job Description Overview CoStar Group is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar Group is on a mission to digitize the world... 
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Realty Information, Inc.

    Arlington, VA
    7 days ago
  •  ...Lead Security Engineer Take on a crucial role where you'll be a key part of a high-performing team building and maintaining foundational cryptographic infrastructure. Make a real impact as you help shape the way secure communications are configured, tested, and deployed... 

    Chase

    Palo Alto, CA
    9 hours ago
  •  ...you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Lead Security Engineer to join our team in Fort Washington, Pennsylvania (US-PA), United States (US). The Security Engineer is a hands-on... 
    Work at office
    Local area
    Remote work
    Flexible hours

    NTT America

    Fort Washington, PA
    11 days ago
  •  ...that we serve. The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted...  ...have in this role: Being a member of CISO team, as a Lead PKI Engineer, you will significantly contribute to the advancement of our... 
    Remote work
    Flexible hours

    Dtcc

    Coppell, TX
    1 day ago
  •  ...growing team of world-class researchers, engineers, and GTM operators. Our culture is open,...  ...the broader ecosystem. About the Job Security of the protocols developed at Babylon is...  ...Establish overall security objectives and lead the planning and execution to achieve... 
    Contract work
    Remote work

    Babylon Labs Ltd

    West Babylon, NY
    9 hours ago
  • $121.79k - $166.95k

     ...Facebook, Twitter, YouTube and Instagram. Position Summary: We have an exciting opportunity to join our team as a Lead Engineer - Network Security Systems. Reporting to the Director of Network Security Systems Engineering, the Lead Engineer of Network... 

    NYULMC

    New York, NY
    4 days ago
  •  ...Job Title Leading the creation, improvement and education of security policies, procedures, standards, and practices. Leading the implementation, management, and monitoring of core security infrastructure. Leading the detection, mitigation and resolution of security... 

    1872 Consulting

    New York, NY
    2 days ago
  •  ...assets to the mainstream, consider building your career at Paxos Labs. We believe security is critical to our culture and long term success. We are hiring a Lead Security Engineer to help take Paxos Labs's security capabilities to the next level. Who we're looking... 
    Contract work

    Paxos Labs

    New York, NY
    2 days ago
  • $140k - $155k

     ...Lead Security Engineer (Active Top Secret Clearance Required) Washington, D.C. Clear Creek Federal is part of the Seneca Nation Group (SNG) portfolio of companies. SNG is Seneca Holdings' federal government contracting business that meets mission-critical needs... 
    Full time
    Contract work
    Flexible hours

    Seneca Holdings LLC

    Washington DC
    5 days ago
  •  ...Senior Lead Security Engineer The ideal candidate for this role must have a minimum of 5 years of experience with Cisco Firepower Firewall, strong understanding of network security protocols, and experience with network engineering and infrastructure projects. Additionally... 

    InterSources

    Columbus, OH
    4 days ago
  •  ...National Human Genome Research Institute’s Information Systems Security Officer and their team is to make information security...  ...NHGRI to succeed in its research mission. What you will do The Lead Security Engineer is responsible for supporting the IT Security tools,... 
    Full time
    Work experience placement

    Richard S. Carson & Associates Inc

    New York, NY
    3 days ago
  • The Intake Coordinator is responsible for the overall coordination of Agency referrals for Medicare and non-Medicare clients under the direct supervision of the Branch Director or Centralized Intake Director. The Intake Coordinator is a resource person for referral sources...

    NYU Langone Health

    Charlotte, NC
    4 days ago
  • $178.9k - $252.7k

     ...What you'll do Join our Cloud & Infrastructure Security team as a Technical Leader to define the strategy, lead the programs, deliver automation, and drive the...  ...response and remediation efforts with engineering teams Establish technical security baselines... 
    Contract work
    Work at office
    Local area
    Remote work
    2 days per week

    DocuSign

    Seattle, WA
    1 day ago
  • $172k - $215k

     ...Lead Security Engineer Copia Automation builds the version control and change management platform for industrial automation. Our customers are in oil & gas, manufacturing, and critical infrastructure — environments where the code running on PLCs, SCADA systems, and... 
    Permanent employment
    Full time
    Work at office

    Copia Automation

    New York, NY
    2 days ago
  • $98.5k - $141.5k

     ...people and institutions who rely on us to help them build more secure and prosperous futures. THE ROLE A technical...  ...technologies, threats, vulnerabilities and exposures. The Lead Security Engineer advances one or more security-related programs and/or oversee... 
    Work experience placement
    Local area
    Remote work
    Flexible hours
    Shift work
    Night shift
    Weekend work

    MFS Investment Management

    Boston, MA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Security Engineer. Be the first to apply!