Staff Security Engineer
at Credit Karma
Charlotte, United States
Intuit Credit Karma is a mission-driven company, focused on championing financial progress for our more than 140 million members globally. While we're best known for pioneering free credit scores, our members turn to us for everything related to their financial goals, including identity monitoring, applying for credit cards, shopping for insurance and loans (car, home and personal) and savings accounts and checking accounts* – all for free. Credit Karma has grown significantly through the years: we now have more than 1,700 employees across our offices in Oakland, Charlotte, Culver City, San Diego, London, Bangalore, and New York City.
*Banking services provided by MVB Bank, Inc., Member FDIC
We are looking for an exceptional security leader to strategize, design, and guide the implementation of our rapidly expanding security capabilities to secure applications and data in multi-/hybrid-cloud environments. With strong technical competency in the areas of cloud infrastructure, Application, and data security ,you'll lead and partner with an innovative and passionate team of engineers to create and implement effective, cost-efficient, and low-friction security solutions using cutting-edge technologies.
What You'll Do
- Lead strategic initiatives to mitigate and remediate security risk across the organization
- Implement & Instrument security controls and tooling across cloud infrastructure to uplevel the security posture
- Work on a cloud native environment leveraging Containerized Workloads, Serverless Architecture and Automated CICD Pipeline to manage Infrastructure-as-a-Service
- Perform Scripting and Coding to build security tooling and for automating redundant tasks.
- Use terraform to deploy security baseline controls, perform code reviews, and provide recommendations for improved security.
- Research and advocate new technologies, architectures, and security products that will support security strategies, patterns, and standards and help address new threat vectors
- Lead Applied Cryptography function focussed on PKI, Key Lifecycle Management and Secrets/Vault Management in a distributed and multi-tenant environment.
- You will be working on at least 2-3 vertical domains within Security Engineering- Applied Cryptography, IAM, Network Security, Vulnerability Management or Detection & Response Engineering
- Operate in a Tier 0 environment with a rigor and discipline to handle rotational on call and incident response.
- Define, document and implement security standards, guidelines and procedures for secure operations in a cloud infrastructure environment.
What we expect
- 10+ years of experience in Security Engineering building, operating and architecting a combination home grown and vendor solutions.
- Strong understanding of Computer Engineering with a focus on Security, Infrastructure, Platform, IAM and Application (Cloud, Containerization, Container orchestration, Network, Application Reliability, Database Architecture).
- Demonstrable knowledge of Network Architecture, web application security, and experience supporting multi-tier web application architectures.
- Experience running Infrastructure at scale; utilizing Configuration Management and automation to ensure idempotency, ephemerality, security, and reliability.
- Experience operating Tier 0 Systems in Production which are customer and revenue impacting.
- Expertise in at least 2-3 vertical domains within security engineering is a big plus - Applied Cryptography, IAM, Network Security, Vulnerability Management or Detection & Response Engineering
- Professional knowledge of Golang, Java or other higher-level OOP languages
- Professional experience with Kubernetes, Helm, Terraform and CI/CD toolsets
- Familiar with SRE and Devsecops methodologies and passionate about solving operation problems by utilizing automation and software.
- Ability to communicate effectively vertically and horizontally within the organization via demonstrated written and verbal communication skills.
Benefits include:
- Medical and Dental Coverage
- Retirement Plan
- Commuter Benefits
- Wellness perks
- Paid Time Off (Vacation, Sick, Baby Bonding, Cultural Observance, & More)
- Education Perks
- Paid Gift Week in December
Equal Employment Opportunity:
Credit Karma is proud to be an Equal Employment Opportunity Employer. We welcome all candidates without regard to race, color, religion, age, marital status, sex (including pregnancy, childbirth, or related medical condition), sexual orientation, gender identity or gender expression, national origin, veteran or military status, disability (physical or mental), genetic information or other protected characteristic. We prohibit discrimination of any kind and operate in compliance with applicable fair chance laws.
Credit Karma is also committed to a diverse and inclusive work environment because it is the right thing to do. We believe that such an environment advances long-term professional growth, creates a robust business, and supports our mission of championing financial progress for everyone. We offer generous benefits and perks with a single eye to nourishing an inclusive environment that recognizes the contributions of all and fosters diversity by supporting our internal Employee Resource Groups. We’ve worked hard to build an intensely collaborative and creative environment, a diverse and inclusive employee culture, and the opportunity for professional growth. As part of the Credit Karma team, your voice will be heard, your contributions will matter, and your unique background and experiences will be celebrated.
Privacy Policies:
Credit Karma is strongly committed to protecting personal data. Please take a look below to review our privacy policies:
US Job Applicant Privacy Notice
UK Job Applicant Privacy Notice
India Job Applicant Privacy Notice
