hirly

Footprint

Member of Technical Staff (Security)

New York City · San Francisco

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Footprint first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Stated salary
$180,000 – $260,000 per year
Country
US
Work mode
On-site / unstated
First seen by hirly
28 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Footprint is the agentic platform that learns your compliance program and runs it end to end.

Compliance teams at banks and fintechs are drowning in financial crimes investigations. Transaction volumes are surging, regulators keep raising the bar, and the work still runs on manual review queues stitched together from legacy vendors. Percy, our agentic system, learns each team's procedures and makes the same calls their analysts would: clearing false positives, escalating real risk, writing the case narrative, and documenting every decision for audit. It cuts review workloads by 70%+.

The harder problem is underneath. Every investigation is grounded in the data sources compliance teams already trust, and every case commits to an organizational memory that compounds — so a pattern one analyst caught in March surfaces automatically in October, across KYC, EDD, sanctions, and monitoring. Whether the team is five analysts or 500, they share one brain. Every memory carries provenance. Agents propose; humans approve. That's four years of identity infrastructure sitting under the agent, and it's the part nobody can bolt on later.

We're backed by QED, Index, and Box Group, and trusted by FDIC- and OCC-regulated banks plus fintechs like Bilt, Nuvei, and MoonPay. We 5x'd revenue last year. The team is small, senior, and ships fast.

The Role

Footprint sells trust to banks and fintechs: verify an identity, vault the PII, and prove to an auditor that every step was done correctly. The architecture reflects four years of that job. Identity records live in an AWS Nitro Enclave-backed vault as an append-only ledger, and our SDKs collect sensitive data straight from end-user devices.

This year the surface changed. Percy, our AI agent platform, now runs AI-powered agents in isolated Modal sandboxes that make compliance and risk decisions on live PII. An agent that acts on real identity data raises new questions: what the sandbox can reach, and how does a person's most sensitive data stay safe while an AI system works on it. At the same time, our customers' diligence teams keep asking harder security questions, because our audit trails are part of what they're buying.

Footprint was built with strong security foundations, but we're hiring the first person to fully own the product's security boundary end to end. This is an engineering seat: you'll spend most of your time in the product, with security as your lens.

You'll inherit a real security architecture: hardware attestation, KMS-based key management, an audit ledger designed to be tamper-evident, secret management, and compliance programs that already pass their audits. Assessment, hardening, security tooling, and the standards engineering builds against all become yours.

You'll report directly to the Head of Engineering - Elliott Forde.

What You'll Own

Vault and enclave security. The Nitro Enclave-backed vault holds millions of identity records. Encryption, key management, hardware attestation, the integrity of the append-only audit ledger, and cross-tenant isolation are yours to assess, harden, and stand behind

The Percy sandbox boundary. The agents run in isolated Modal sandboxes against live PII. Sandbox isolation, token scoping, network egress, and the integrity of agent audit logs are the newest and fastest-moving part of this job - you set the standards here

The end-user data path. From a stranger's phone through our SDKs into the vault: PII collection, document capture, and the generative UI layer that renders screens off agent decisions. You own the security review of everything that touches an end user

Document pipeline integrity. Forged documents are an adversarial input, and the attackers iterate. Tamper detection, classification, and fraud checks all have to hold against that - adversarial robustness of this pipeline is yours

Product security in our compliance programs. Footprint runs SOC 2 Type 2, PCI DSS Level 1, GDPR, and ISO 27001. The programs have their own owner, but the product-security controls inside them are yours: the technical evidence, the remediations, and the deep technical answers when an auditor or a customer's security team pushes past the questionnaire. You scope and run our technical pentests, and you own product and infrastructure vulnerability remediation through to resolution

Stack

Rust · TypeScript · Postgres · AWS (Nitro Enclaves, KMS, IAM, VPC, CloudTrail, GuardDuty) · Modal · Vercel

Deep experience with most of this, and the judgment to pick up the rest, is what matters.

Must-Have

5+ years of hands-on security engineering - application security, infrastructure security, or both

You understand encryption, key management, and access control well enough to audit a production system holding millions of PII records, and to say precisely where it's weakest

You know how code execution environments get escaped, how to enforce least privilege on ephemeral compute, and how cross-tenant leaks actually happen

You've done offensive work - pen testing, threat modeling, or vulnerability research - and it changed how you build

You've secured AWS environments hands-on: IAM, VPC, KMS, CloudTrail, GuardDuty

You've been through a SOC 2 or PCI DSS audit and translated real controls into evidence an auditor accepted

You've shipped security fixes nobody assigned you - you find gaps and close them on your own initiative

Nice-to-Have

You've secured AI/LLM agent systems or autonomous code execution. Percy is the fastest-growing surface here, and prior art is thin - if you have real experience, it counts for a lot

You know trusted execution environments (AWS Nitro Enclaves, Intel SGX). The vault lives inside one

You've worked on document fraud detection or adversarial robustness of ML pipelines. Our document pipeline faces deliberate attacks, and it has to hold

You've worked in Rust. The vault and core services are built in it

You've built security tooling - SAST, DAST, CI/CD gates. That work is a first-year deliverable of this role, so having done it before counts

You know the KYC and identity verification space. It's the regulatory context the whole product lives in

Success Looks Like

90 Days: You've completed a security assessment across the vault, the Percy sandbox layer, and our cloud infrastructure, and shipped the first round of hardening. Security decisions get routed to you.

1 Year: The product-security controls in our audits pass on evidence you produced, and the hardest technical questions from auditors and customer security teams land on you. Automated security gates run in CI/CD, incident response runs on playbooks you've pressure-tested, and the team trusts you to make security trade-offs at speed.

Why Join Footprint

Massive impact, fast: You'll work on projects that shape company direction, not analysis that gets shelved.

Own meaningful work: From day one, you'll have direct ownership over strategic initiatives that drive the business forward.

Real growth opportunity: Promotion timelines depend on performance: the harder you work, the quicker you'll get promoted.

Winning team and culture: We're a fast-moving, no-BS team that likes to win (and have fun doing it).

Benefits

💰 Generous compensation and equity packages

🍽 Free lunch and dinner (after 7pm)

💪 Monthly wellness stipend

🏖 Unlimited PTO

🏥 Fully covered health, dental, and vision insurance

🚀 The chance to help shape the future of internet identity and financial crime prevention

Original posting on Footprint's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job
Member of Technical Staff (Security) – Footprint | hirly.me