TrueML is a mission-driven financial software company that aims to create better customer experiences for distressed borrowers. Consumers today want personal, digital-first experiences that align with their lifestyles, especially when it comes to managing finances. TrueML’s approach uses machine learning to engage each customer digitally and adjust strategies in real time in response to their interactions.
The TrueML team includes inspired data scientists, financial services industry experts and customer experience fanatics building technology to serve people in a way that recognizes their unique needs and preferences as human beings and endeavoring toward ensuring nobody gets locked out of the financial system.
What you will do
Position Summary
We are seeking a Sr. Security Engineer to lead the integration of security across the software
development lifecycle (SDLC). This role sits at the intersection of engineering, cloud infrastructure, and
application security, driving automation, scalability, and secure-by-default development practices.
You will design and implement security-first CI/CD pipelines, embed automated security testing, and
partner with engineering teams to ensure applications are built, deployed, and operated securely—at
scale
Key Responsibilities
Security Automation & CI/CD Integration (Core Focus)
• Embed security controls and scanners (SAST, SCA, DAST, IaC, Container Security) into CI/CD
pipelines
(GitHub Actions, Jenkins, GitLab CI, Azure DevOps)
• Design and maintain automated security workflows across build, test, and deploy stages
• Implement security gates, policy enforcement, and compliance checks within pipelines
Cloud Security (AWS Focus)
• Secure cloud-native architectures across AWS (IAM, VPC, ECS/EKS, Lambda, S3, API Gateway)
• Integrate and operationalize CNAPP/CSPM tools (e.g., Wiz, Prisma Cloud)
• Enforce least privilege access, secrets management, and runtime protections
What you bring
- An Experienced Defender: You bring 7-10 years in software engineering, DevOps, or cloud engineering. 3+ years in a DevSecOps focused role and a deep mastery of cloud security, vulnerability analysis, and incident response.
- A Cloud Specialist: You have demonstrable expertise in the AWS ecosystem and are highly proficient in securing Infrastructure as Code (Terraform) and containerized environments.
- Certified and Credentialed: You hold top-tier industry certifications (such as CISSP, SANS GIAC, or CASP) and have a firm grasp of compliance frameworks like PCI and ISO 27001.
- Technically Versatile: You are familiar with OWASP, proficient with modern security tooling, and have the ability to secure complex API integrations and data protection layers.
- AI-Aware: You understand the evolving landscape of AI regulations and have the technical curiosity to investigate how threat actors use AI to bypass traditional controls.
- A Strategic Partner: You are a natural collaborator who can translate complex InfoSec projects into simple, maintainable tasks for Engineering teams.
- An Elite Communicator: You can propose strategic methodologies to tackle legacy security debt and convince stakeholders of the business value of security-first design
Core Skills & Capabilities
• Deep expertise in CI/CD pipelines (GitHub Actions, Jenkins)
• Strong hands-on experience with AWS cloud security
• Proficiency in application security tooling and integration
• Experience with container security (Docker, Kubernetes)
• Strong scripting/programming skills (Python, JavaScript)
• Understanding of modern DevSecOps and shift-left security practices
• Excellent collaboration skills across engineering, security, and DevOps teams
Flexible vacation
Medical/dental/vision insurance
Traditional/Roth retirement savings options
Company-paid disability and life insurance
Flexible Spending Account & Limited FSA
Family-friendly parental leave, volunteer and voting time off
On-demand wellness platform access for you and 5 friends and family
PerkSpot discount program for 900+ merchants nationwide
This role supports a global, cross-functional business and operates primarily in a Remote-First environment. However, flexibility outside of standard business hours and occasional local or international travel may be necessary for global operations support, company meetings, training, offsites, and collaborative projects.
This position primarily involves computer-based work, requiring extended periods at a computer, participation in virtual meetings, and use of standard office technology. We will consider reasonable accommodations to enable individuals to perform the essential functions of the role.
Maintaining a reliable internet connection and a professional work environment is expected. The ability to protect confidential company, employee, customer, and business information while working outside of a company office is also required.
We collect personal information for employment purposes. We do not sell personal information. Most of the information we have is provided to us by you and/or collected as part of the employment process. For more details on how we use, share, and delete personal information see our Privacy Policy.
Dedication to Diversity & Inclusion
We are an equal opportunity employer. We promote, value, and thrive with a diverse and inclusive team. Different perspectives contribute to better solutions and this makes us stronger every day. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or other protected characteristics.
Similar Jobs at TrueML
What you need to know about the Charlotte Tech Scene
Key Facts About Charlotte Tech
- Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
- Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
- Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
- Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
- Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

