
Lead Security & Infrastructure Engineer
Pulso by ThinkSys
Visa & sponsorship
- The posting says it will not sponsor a visa for this role.
Job description
Location:
Fully remote, United States (must be U.S.-based and authorized to work in the U.S.)
Reports to:
CTO
Benefits:
Unlimited PTO, flexible schedule, 401(k) with 3% company contribution
About the company
Our client is a global payments and payroll platform that lets companies pay employees, contractors, and freelancers anywhere in the world, in fiat or digital assets, with compliance, tax, and identity handled underneath.
At their core, they bridge two worlds: traditional finance and Ethereum-based settlement. Payments move as stablecoins on-chain or through conventional banking rails. The platform is underpinned by a large smart-contract ecosystem deployed across EVM chains, where payments, settlement, and identity flows are anchored on-chain.
The stack runs on Google Cloud Platform (Cloud Run, BigQuery), with MySQL, a Node.js / TypeScript application layer, and Cloudflare at the edge.
The role
You'll be the founding security hire, working directly with the CTO and owning security across our cloud, application, and on-chain surfaces. Your first job is to look across all of our tooling and setup, tell us where the holes are, and close them. From there you own posture, detection, incident response, and compliance. This is a hands-on role with real access to production, not an advisory one.
Our infrastructure is intentionally light and mostly serverless, so this is a security role first. You'll keep the platform running, but you won't spend your days building infrastructure.
What you'll do
-
Assess our full GCP and Cloudflare setup, identify gaps, and drive remediation.
-
Stand up and run Security Command Center and Google SecOps: findings, detections, and alerting.
-
Detect and investigate traffic anomalies, abuse, credential misuse, and scanning against our public endpoints (Cloud Run, load balancer, Cloudflare).
-
Build log-based detection over Cloud Audit Logs, request logs, and application telemetry.
-
Lead incident response from detection through containment, forensics, remediation, and post-mortem, and build the runbooks and tooling behind it.
-
Harden IAM, secrets, encryption, and network controls across production, and tune Cloudflare WAF, rate limiting, and bot management.
-
Own vulnerability management, coordinate penetration tests, and run threat modeling and secure code review with engineering.
-
Drive SOC 2 and ISO 27001 readiness and represent security to auditors, partners, and customers.
-
Keep our mostly serverless GCP footprint healthy: deployment pipelines, backups and recovery, and on-call.
What we're looking for
-
8+ years in security engineering, with the judgment to set direction as the first security hire.
-
Deep, hands-on GCP security experience: IAM, networking, logging and monitoring.
-
Direct experience with Security Command Center and/or Google SecOps (Chronicle).
-
A track record in detection engineering: turning logs into alerts people act on, and spotting anomalous traffic.
-
Proven incident-response experience in production environments.
-
Experience setting up security tooling from scratch, not just operating what someone else built.
-
Application security capability: threat modeling, secure code review, and vulnerability management in a web/API stack.
-
Comfort reading Node.js / TypeScript code and working with CI/CD and infrastructure-as-code.
-
SOC 2 audit experience.
-
U.S.-based and authorized to work in the U.S.
Strongly preferred
-
Security certifications: GCP Professional Cloud Security Engineer, CISSP, OSCP, or similar.
-
Experience in fintech, payments, crypto, or another regulated, funds-handling environment.
-
Curiosity about digital-asset payments. We settle in both fiat and stablecoins, so there's plenty to learn, but no prior blockchain experience is required.
-
ISO 27001 or PCI DSS experience.
Why this role
You'll own security for a platform that moves real money across borders and blockchains, combining cloud, security, and Web3 in one place. You start as a team of one with full ownership and trust, and as the company grows you'll define the security function and build the team around it.