Security Engineer
Versana is an industry-backed fintech on a mission to make the syndicated loan market better. By digitally capturing agent banks' data on a real-time basis, Versana provides unprecedented transparency into loan-level details and portfolio positions, bringing efficiency and velocity to the entire market. Through our platform, participants can rest assured they are accessing the loan market's most credible source of deal information.
Versana is looking for a Security Engineer to join our InfoSec squad. You will play an essential role in safeguarding our organization's information systems and data from potential threats and vulnerabilities. You will work collaboratively with senior engineers and cross-functional teams to enhance our security posture using cutting-edge technologies.
Key Responsibilities:
- Identify and help remediate application security vulnerabilities, ensuring compliance with industry standards and best practices.
- Integrate and maintain security tooling in CI/CD (SAST, SCA, DAST, container and secrets scanning) and collaborate with developers to tune signal vs noise.
- Assist in the configuration and management of security tools (e.g. DLP, SIEM, CNAPP, Cloud Security Posture Management tools).
- Configure and tune security monitoring and alerting (log sources, detection rules, dashboards) to reduce false positives and improve actionable signal.
- Participate in threat modeling and secure design reviews for new and existing applications.
- Participate in incident response activities, including containment, eradication, and recovery efforts.
- Work continuously with cross-functional teams (engineering, DevOps, product, QA) to embed security controls and guidance throughout the SDLC ("shift left").
- Contribute to securing AI/ML/LLM related technologies (prompt injection defenses, output filtering, API key/secret protection, data minimization, monitoring for misuse).
- Automate repetitive security tasks and reporting where possible (scripts, pipeline jobs, policy-as-code).
- Support the implementation of security policies, procedures, and standards.
- Stay up-to-date with the latest security trends, threats, and technology advancements.
Must Haves:
- 1–3 years combined experience in software development and/or application or cloud security.
- Ability to read and reason about code in at least one of: Python, Java, JavaScript/TypeScript, Go, or C#.
- Understanding of Application Security principles and web application vulnerabilities such as OWASP Top 10, their risk and remediations.
- Basic understanding of cloud computing principles and services (e.g., AWS, Azure, Google Cloud).
- Exposure to security tools such as firewalls, intrusion detection systems, and vulnerability scanners.
- Strong communication and teamwork skills.
- Detail-oriented with a proactive approach to identifying and mitigating security risks.
Nice to Haves:
- CompTIA Security+, CompTIA CySa+, Certified Ethical Hacker (CEH), or similar certifications.
- Infrastructure-as-Code knowledge such as Terraform.
- Experience in the financial sector
$100,000 - $120,000 a year
Equal Opportunity Employer
We are committed to providing equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.