About Slash
Slash is building the future of business banking, one industry at a time. We believe businesses deserve financial infrastructure tailored to how they actually operate. That's why we're creating a new category of business banking. We combine the reliability of traditional banking (high yields, competitive rewards, and comprehensive security) with industry-specific features that make businesses more efficient, more competitive, and more profitable.
Started in 2021, Slash is one of the fastest growing fintechs in the world and we power over ten billion dollars a year in business purchasing across numerous industries. We recently raised a $100M Series C led by Ribbit Capital with participation from Khosla Ventures, Goodwater Capital, NEA, and Y Combinator, accelerating our expansion into new markets and products.
Slash is headquartered in San Francisco, and has a strong in-person culture.
About the role
Slash is, at its core, a technology company and is on a mission to build the best engineering team in the world. We're looking for a Software Engineer to own and scale the security of our platform as we grow fast. You'll be responsible for keeping our systems secure across the entire stack — from network and infrastructure to application-level security — while establishing the patterns and guardrails that let the rest of the team move quickly without having to worry about security. You'll define and own our security program end-to-end, and play a key role in enabling Slash to serve billions of dollars in business spend reliably and securely.
What you'll do
• Own Slash's security program end-to-end — find gaps, prioritize, and propose and drive changes independently
• Work on network security: manage and harden our Cloudflare implementation, AWS WAF, VPC networking, and overall infrastructure posture
• Work on application security: ship features like passkey authentication, SMS rate limiting, and other product-level hardening
• Manage recurring pen tests and our bug bounty program, and coordinate remediation across engineering
• Assist on compliance efforts like PCI and SOC 2
• Establish security patterns, tooling, and guardrails that enable the rest of the team to move fast safely
• Own corporate IT security, including keeping company equipment and endpoints secure
• Interface with customers, internal stakeholders, and key vendors to answer questions and provide confidence in Slash's security practices
We're looking for someone who
• Is a security generalist — knowledgeable across the stack, from infrastructure to application code
• Can think through, understand, reason about, and work on our platform and infra (Kubernetes/EKS, CockroachDB, Kafka, Terraform/Pulumi, AWS) — while spending their day-to-day 100% focused on improving our security
• Is organized and able to coordinate pen tests, audits, and competing security priorities
• Has proficiency in TypeScript or another object-oriented language
• Can find gaps and drive high-impact changes independently, without waiting to be told what to work on
• Potentially fits one of two archetypes:
What's in it for You:
• Opportunity for high growth
• High autonomy + ownership culture
• Comprehensive health + benefits plan
• Working out of our downtown San Francisco office space
• Unlimited PTO