
First Dedicated Security Engineer
Savvy Wealth16 hours ago
Base Salary
$220k - $235k/yr
Responsibilities
- Own vulnerability management across the product, codebases, AWS, GCP, and Cloudflare infrastructure, including identification, prioritization, and remediation to closure.
- Build and operate the AppSec tooling pipeline covering secrets scanning, SCA/dependency scanning, SAST, and CI/CD security integration.
- Define and enforce secure coding and code review standards, including controls for AI-generated code and security-sensitive paths.
- Partner with the internal AI team to establish guardrails for AI-assisted development, vibe coding, AI-built integrations, data handling, and dependency vetting.
- Harden the SaaS environment by reviewing OAuth grants and third-party integrations and reducing configuration and access risks across Google Workspace, GitHub, Rippling, and Slack.
- Help establish conditional access, SSO, phishing-resistant MFA, managed-device posture, and cloud and SaaS configuration baselines.
- Develop high-signal detections and contribute to incident response readiness.
- Work with Engineering, IT, and the internal AI team to communicate risks, remediation paths, and tradeoffs to technical and non-technical stakeholders.
Requirements
- At least 5 years of hands-on security engineering experience, including significant application or product security experience in a small security organization.
- Strong software engineering fundamentals and the ability to read, write, and remediate code.
- Experience enforcing security across technical and non-technical teams and embedding security into existing workflows.
- Deep experience with secrets scanning, SCA/dependency scanning, SAST, and GitHub-centric CI/CD security integration.
- Practical experience securing SaaS environments through OAuth and third-party application review, configuration hardening, and least-privilege access design.
- Working knowledge of AWS and/or GCP cloud security and Cloudflare edge/CDN security.
- Understanding of AI-assisted development security, including hallucinated dependencies, leaked secrets, insecure patterns, and security guardrails.
- Excellent communication, writing, independent-working, pragmatic risk prioritization, and collaboration skills.
- Preferred qualifications include experience building security programs at early- to mid-stage companies, SaaS security posture management, CSPM, identity threat detection, LLM or agentic workflow security, SIEM/MDR detection engineering, fintech, and offensive security.
Benefits
- Competitive salary and equity package.
- Unlimited PTO and paid company holidays.
- Medical, dental, and vision plans.
- Company 401(k), commuter benefits, and HSA/FSA plans.
- Work is based at Savvy’s NYC office in Manhattan.
- Lunch and snacks are provided in the office.
- Access to Spring Health virtual mental health care, Rightway health concierge services, and Guardian WorkLifeMatters EAP counseling and support.
Tech Stack
Categories
About Savvy Wealth
Savvy Wealth builds a digital-first wealth management platform and is the parent of Savvy Advisors, an SEC-registered investment advisor for independent financial advisors. Advisors join Savvy, bring their client book, and share assets-under-management revenue in exchange for a proprietary advisor/client portal, investment management, marketing, and back-office operations. Founded in 2021 and headquartered in New York, it uses AI to automate onboarding and planning workflows while leaving client advice to human advisors.