Lead Security and Infrastructure Engineer

๐Ÿข Rise Works ยท all Rise Works jobs
๐Ÿ“ United States
๐Ÿ’ฐ USD 180,000 - 210,000 / annual
๐Ÿ“… Posted 2026-08-23 ยท via Himalayas
๐Ÿท Security-Engineering,Cloud-Security,Infrastructure-Engineering,Application-Security,DevSecOps,Lead-Infrastructure-Engineer,Lead-Security-Engineer,Infrastructure-Security-Engineering-Leader,Security-Infrastructure-Engineer,Sr.-Infrastructure-Security-Engineer,Security-Engineering-Lead,Infrastructure-Security-Engineer,Lead-Information-Security-Engineer,Lead-Cybersecurity-Engineer,Cloud-Security-Engineer
Apply on original site โ†—

Lead Security & Infrastructure Engineer (GCP ยท Fintech)

Location: Remote - United States only (must reside in the U.S.) Eligibility: Must be authorized to work in the United States Team: Security & Infrastructure Reports to: CTO (you'll work directly with the CTO)
About Rise

Rise is a global payments and payroll platform built for the way modern teams actually work - across borders, currencies, and rails. We make it possible for companies to pay full-time employees, contractors, and freelancers anywhere in the world, in either fiat or digital assets, with the compliance, tax, and identity infrastructure handled underneath.

Our stack runs on Google Cloud Platform (Cloud Run, BigQuery), with MySQL , a Node.js / TypeScript application layer, and Cloudflare (including Cloudflare Pages) at the edge, plus Ethereum -based settlement for stablecoin payments. Because we move money for real people, security and correctness are first-order concerns in everything we ship.
Our Culture

We're a lean, high-trust, high-ownership team. Because we move real money for real people, we hold a high bar for correctness, security, and accountability - the work is meaningful precisely because the stakes are real. We value:

-
Ownership over hand-offs. You'll own security and infrastructure end to end and have the autonomy that comes with that.

-
Security as a default, not a phase. Handling funds and personal data means security thinking is part of every decision, not a box checked at the end.

-
Directness and low ego. We give and receive candid feedback, write things down, and prefer clarity over politics.

-
Remote-first discipline. We're a globally distributed team spread across time zones around the world, and we communicate asynchronously with a bias toward documentation and reproducibility.

What You'll Do

Working directly with the CTO, you'll own security across Rise's cloud and application surfaces, and the infrastructure operations that keep production healthy. Security is the center of gravity for this role - roughly two-thirds of your time - with infrastructure ops and reliability as the other third, on a mostly serverless stack designed to keep operational overhead low. This is a builder's role, not a purely advisory one: you'll harden what exists, design what's missing, and be the person the team turns to when security or infrastructure questions come up. As Rise grows you'll have the opportunity to define the security and infrastructure function and build a team beneath you.
Security posture & architecture

-
Own Rise's security posture across cloud, application, and data surfaces.

-
Enforce secure defaults: secrets management, least-privilege IAM, network segmentation, and audit logging.

-
Own secrets management and access governance, applying least privilege and separation of duties across production systems.

-
Harden the GCP footprint (SecOps, Cloud Run, IAM, VPC, BigQuery, Secret Manager) and Cloudflare edge configuration (WAF, DNS, rate limiting, bot management).

-
Partner with product engineering on secure design reviews for new features before they ship.

Threat detection & incident response

-
Lead incident response: detection, containment, forensics, remediation, and blameless post-mortems - and build the tooling and runbooks so we respond faster next time.

-
Build detection and alerting for anomalous traffic, abuse, credential misuse, and scanning against our public endpoints (Cloud Run / load balancer / Cloudflare).

-
Develop log-based detection and investigation capability over Cloud Audit Logs, request logs, and application telemetry.

-
Run tabletop exercises and game days so our response is proven, not assumed.

Application & data security

-
Run threat modeling and secure code review across our Node.js / TypeScript services and APIs.

-
Own vulnerability management: scanning, dependency and supply-chain risk, triage, and remediation SLAs.

-
Coordinate penetration tests and external a

โ† All remote jobs