What you’ll do
• Own Slash’s security program end-to-end — find gaps, prioritize, and propose and drive changes independently
• Work on network security: manage and harden our Cloudflare implementation, AWS WAF, VPC networking, and overall infrastructure posture
• Work on application security: ship features like passkey authentication, SMS rate limiting, and other product-level hardening
• Manage recurring pen tests and our bug bounty program, and coordinate remediation across engineering
• Assist on compliance efforts like PCI and SOC 2
• Establish security patterns, tooling, and guardrails that enable the rest of the team to move fast safely
• Own corporate IT security, including keeping company equipment and endpoints secure
• Interface with customers, internal stakeholders, and key vendors to answer questions and provide confidence in Slash’s security practices