Senior Software Engineer, Security - Application
Overview
Confido Legal is a fast-growing fintech platform that helps legal technology companies and law firms embed payments and finance features into their products and financial workflows.
By adding financial flexibility at the point where lawyers and clients transact, we increase the number of people who can access the justice system and expand our customers' addressable market. Trust and security are foundational to that mission.
We are looking for a senior-level engineer to join our engineering team and take ownership of security at Confido Legal.
This is not a standalone security function. We’re looking for someone who has built and shipped real software and wants to stay deeply embedded in the engineering process—writing code, reviewing code, and helping shape architecture—while ensuring security is built into every stage of how we design, build, and operate our platform.
We’re a small team of highly skilled engineers who take on meaningful ownership across the system. Engineers at Confido often serve as domain leads (security, hiring and growth, underwriting) while continuing to contribute directly to the product. In this role, you’ll make decisions that have an outsized impact on how the company scales securely over time.
You’ll report to the CTO and will, to start, have no direct reports. You’ll work closely with a strong, security-minded engineering team and partner across product and customer-facing teams.
Role Responsibilities
- Own Confido Legal’s security posture end-to-end, from strategy through hands-on execution
- Serve as the engineering team’s point person for security while remaining an active contributor to product development
- Ensure security is embedded into every stage of the product lifecycle, not layered on after the fact
- Lead PCI DSS Level 1 and SOC 2 compliance, including building automation and processes that make ongoing compliance sustainable
- Lead security incident response in collaboration with engineering and executive teams
- Harden our AWS infrastructure and drive security findings toward a consistently clean state
- Identify and remediate sensitive data issues, including encryption at rest where appropriate
- Stay ahead of dependency vulnerabilities and software supply chain risks
- Partner closely with engineering and product to implement practical security best practices
- Participate in customer security and diligence conversations and help build trust with security-conscious buyers
What does success look like in this role?
- PCI DSS Level 1 and SOC 2 certifications are maintained with streamlined, repeatable processes
- Sensitive data is handled securely and consistently across the platform
- Critical and high-severity vulnerabilities are rare, not routine
- Infrastructure and dependency scans return clean results without ongoing fire drills
- Security is a natural part of engineering discussions and design decisions
- Customer security reviews feel routine, clear, and confidence-building
- There is a clear, owned security roadmap aligned with the company’s growth
Technology Stack
-
TypeScript — primary language across our application stack
- React — frontend applications are built with React and Nextjs
- AWS — all infrastructure is deployed on AWS and configured with IaC
- Docker — services are containerized with Docker for consistency and scalability
- GraphQL — our external-facing API is GraphQL
- CI/CD pipelines — dependency and vulnerability monitoring integrated into deployment workflows
- Figma — used for UI/UX design; engineers actively participate in this work
An Ideal Candidate
- Has 5+ years of experience as a senior software engineer or security engineer with substantial security ownership
- Has hands-on experience securing production web applications deployed on AWS
- Has “seen this movie before” securing real SaaS systems as they scale
- Builds systems that are secure by default and practical to operate
- Is comfortable identifying risk, defining tradeoffs, and driving solutions with imperfect information
- Communicates clearly with engineers, product leaders, and non-technical stakeholders
- Takes security seriously while understanding that perfection is not achievable
- Values ownership, empathy, and long-term thinking over rigid process
Our Team
Becoming a part of Confido Legal will allow you to shape a growing team and take real ownership. Here are some of the benefits we offer:
- $175,000 – $225,000 starting salary
- Fully remote role with 2 weeks of onsite meetings per year
- Open PTO
- Fully paid medical, vision, and dental insurance
- Stock options
It is critical to keep our core principles front and center in the decisions we make each day. These are the principles that guide how we operate:
- We believe in purpose over profit
- We believe that each team member is an owner
- We believe we thrive in a culture of mutual support
- We believe in building for the long term
Application
To apply for the Security Engineer role, please complete the form below. Please ensure that your cover letter addresses the following five questions:
1. Why are you interested in working with Confido Legal?
2. What is your ideal work environment?
3. What are your strengths?
4. If we were to ask your past managers about you, what feedback would they have?
5. Where do you see yourself in five years?
