Software Engineer, Security
Quick facts
- Pay
- $250,000 to $350,000 base salary
- Type
- Full-time
- Location
- San Francisco, California
- Skills
- TypeScript, Rust, Kubernetes, AWS
- Industry
- Information Technology — 671 open jobs
- Visa in listing
- H-1B, OPT
- Apply
- Free to apply — never pay anyone for a job offer or visa sponsorship
Job description
Our client is building modern financial infrastructure for businesses, combining reliable banking with industry-specific software, payments, rewards, and intelligent financial workflows. The platform powers more than $10 billion per year in business purchasing across thousands of customers. Founded in 2021, the company has grown to approximately 60 employees, reports more than $300 million in annual revenue, and has raised approximately $160 million, including a recent $100 million Series C.
This is the first dedicated security engineering hire, reporting directly to the CTO and owning the security program end to end. You will build and operate the security program across infrastructure security, application security, vulnerability management, penetration testing, bug bounty operations, and engineering support for compliance. This is a hands-on generalist role for someone who wants to ship real security improvements rather than operate only through policy and checklists.
What you will do:
- Build and own the security engineering program across infrastructure and application layers.
- Identify and prioritize security gaps, develop pragmatic remediation plans, and drive high-impact changes.
- Harden AWS infrastructure, Kubernetes and EKS clusters, server configurations, networking, access controls, and cloud security posture.
- Improve application security across services written in TypeScript, Go, Rust, and related technologies.
- Manage recurring penetration tests and drive findings through remediation.
- Operate the bug bounty program, triage vulnerability reports, and coordinate responses.
- Partner with engineering on secure design, code-level fixes, deployment patterns, secrets management, and defense in depth.
- Own technical work supporting SOC 2, PCI, monitoring, incident readiness, and vulnerability-management workflows.
Requirements
- Approximately 2 to 8 years of hands-on security engineering, software security, infrastructure security, or closely related experience.
- Strong generalist ability across cloud infrastructure, application security, vulnerability management, and security operations.
- Hands-on experience securing AWS and container-orchestration environments such as Kubernetes or EKS.
- Experience assessing and remediating application vulnerabilities in production software.
- Experience managing penetration tests, bug bounty reports, or coordinated vulnerability disclosure.
- Familiarity with network security, identity and access controls, secrets management, web application defenses, and cloud posture management.
- Ability to write code, automate security work, and collaborate directly with software engineers on technical fixes.
- Strong risk judgment, high ownership, clear communication, and comfort operating independently.
- Ability to work on-site five days per week in San Francisco or willingness to relocate.
Nice to have: Experience with TypeScript, Go, Rust, CockroachDB, Kafka, Terraform, Pulumi, Cloudflare, AWS WAF, PCI, SOC 2, incident response, detection engineering, threat modeling, or secure architecture reviews.
Benefits
$250,000 to $350,000 base salary, based on qualifications and experience, plus competitive equity. This role is on-site five days per week in San Francisco. Existing visa transfers, including OPT and H-1B transfers, may be considered.
Visa sponsorship record
No public sponsorship records foundWe didn't find H-1B, H-1B1, E-3 or green card (PERM) filings under the name Raydar in the Department of Labor and USCIS data. That doesn't mean the job can't be sponsored — the company may file under a different legal name, be new to sponsorship, or sponsor a visa that isn't in these datasets (for example H-2B or J-1).
Tip: ask the recruiter early, in writing, which visa they sponsor and whether they cover the legal and filing fees.
Which visas can work for this job
Occupation: Software Developers (SOC 15-1252).
- Mentioned in the listing
H-1B, OPT
- H-1B cap-exempt employer
Regular cap-subject employer — a new H-1B needs to win the lottery in March (unless you already hold cap-counted H-1B status).
- TN (citizens of Canada and Mexico)
This kind of role may fit the USMCA profession “Computer Systems Analyst (or Engineer, for engineering-degree holders)” — it depends on the actual duties. No lottery, no cap; you need the matching degree or license.
- E-3 (Australia) and H-1B1 (Chile, Singapore)
Same degree requirement as H-1B, but no lottery and a separate quota that is rarely filled.
- O-1 (extraordinary ability)
For candidates with awards, publications, press, a high salary or critical roles at distinguished organizations. No cap, no lottery; the employer files a petition.
- STEM OPT extension (F-1 students)
Requires an E-Verify employer. We didn't find this company in the E-Verify list — ask HR.
Salary vs prevailing wage
Level IV (fully competent)Software Developers · San Francisco-Oakland-Fremont, CA. Annual prevailing wages set by the Department of Labor (OFLC).
| Level | Prevailing wage | H-1B lottery odds* |
|---|---|---|
| Level I | $137,093 | ~15% |
| Level II | $165,131 | ~31% |
| Level III | $193,149 | ~46% |
| Level IV | $221,187 | ~61% |
This job pays $250,000–$350,000 a year — that's Level IV (fully competent). In the wage-weighted H-1B lottery a Level IV registration gets 4 entries; estimated selection chance about 61% — better than average.
* Odds are DHS projections for the FY2027 wage-weighted lottery (actual results vary by year and employer). Since the FY2027 cap season the H-1B lottery is weighted by wage level: Level I = 1 entry, II = 2, III = 3, IV = 4. The level is set by the offered wage against the prevailing wage for the occupation and worksite. Separately, a $100,000 fee for new H-1B petitions for workers outside the US was announced in 2025; as of September 2026 a federal court ruling keeps it unenforceable while appeals continue — check the current status.
Sources: U.S. Department of Labor OFLC disclosure data (H-1B/H-1B1/E-3 LCA, PERM), OFLC prevailing wage data, USCIS H-1B Employer Data Hub, E-Verify participating employers. Data loaded: LCA FY2024–FY2026, PERM, USCIS Data Hub, OFLC wages; updated 2026-10-03. Employers are matched by name, so records of companies with similar names can occasionally be mixed up. This is general information, not legal advice — talk to an immigration attorney about your case.