About the Role
Cardless is seeking a Product Security Lead to integrate security into the platform, focusing on authentication, authorization, anti-abuse controls, fraud prevention, and secure-by-design practices for credit infrastructure. This hands-on, cross-functional role involves collaboration with Engineering, Risk, Compliance, Legal, and Data teams, reporting to the Head of Engineering.
Responsibilities
- Own the security model for partner-facing APIs, including authentication, authorization, tenant isolation, abuse prevention, signing, and audit logging.
- Drive a unified authentication strategy across services and surfaces, incorporating step-up authentication and a strong authentication roadmap.
- Develop device telemetry, behavioral signals, and velocity primitives for fraud and risk functions.
- Act as the secure-by-design partner for Engineering, participating in architecture reviews, creating threat models, and managing tradeoffs.
- Manage the secure SDLC, including SAST/DAST, dependency scanning, secret detection, and security tooling.
- Collaborate with the infrastructure team to enhance security across the stack, from infrastructure to third-party dependencies.
- Manage the security footprint of sensitive payment data as the platform scales.
- Lead incident response for security events and drive vulnerability remediation.
- Manage the relationship with the external security architecture partner, setting priorities and integrating findings.
- Serve as the technical counterpart for compliance, translating security frameworks into engineering solutions and ensuring control effectiveness.
Requirements
- Strong programming skills in Java, Python, or a comparable language.
- Experience designing or operating secure platform/B2B APIs at scale, particularly in multi-tenant environments.
- Background in anti-ATO, anti-fraud, or authentication systems at scale (consumer fintech, marketplace, or large consumer platform).
- Working knowledge of AWS: IAM, KMS, networking, service-to-service auth.
- Comfort with modern AI tooling (Claude, Copilot, etc.) for code review, threat modeling, detection engineering, and security tooling.
- Excellent written communication skills for threat models, postmortems, and security responses.
- Comfortable owning the in-house security function while leveraging external specialists.
Skills
- Java
- Python
- AWS IAM
- AWS KMS
- AWS Networking
- Service-to-service authentication
- AI tooling
- Threat modeling
- Secure SDLC
- SAST/DAST
- Dependency scanning
- Secret detection
- Authentication
- Authorization
- Tenant isolation
- Abuse prevention
- API security
- Incident response
- Vulnerability remediation
- SOC 2
- PCI DSS
Location
- San Francisco, CA
Work Type
- 5 days a week in office
Experience Level
- Lead
Salary/Compensations
- $190,000–$260,000
Benefits
- Meaningful start-up equity
- 100% health, vision & dental primary coverage
- 75% health, vision & dental dependent coverage
- Catered lunches and dinners
- $250/month commuter benefit
- Parental leave
- Team building events
- Flexible PTO with a minimum of 15 days off per year
- 401(k) plan
- Relocation assistance
About the Company
- Cardless is the infrastructure that lets consumer brands put credit cards directly in their own product.
- Our platform handles the credit program end-to-end (applications, underwriting, servicing, rewards, compliance), enabling brands to build the card experience within their own ecosystem.
- We power programs for Coinbase, Bilt, Qatar Airways, Alibaba, and others.
- We've raised $170M to date, including a $60M Series C led by Spark Capital.
