About the job
Promise is at the forefront of transforming how government agencies and utilities support individuals facing financial challenges. We create innovative technology that streamlines access to benefits, facilitates engagement with assistance programs, and enables flexible payment arrangements. Our goal is to empower residents to stay on track while also enhancing the efficiency of agencies, recovering revenue, and providing services with respect and dignity. We are dedicated to reshaping public systems to better serve everyone, particularly the most vulnerable.
Our team comprises experts from prestigious organizations such as Palantir, Google, and Stripe, alongside respected leaders from the government sector. We are passionate about our mission and are seeking exceptional individuals to develop cutting-edge, resilient technologies.
With over $50 million in backing from top investors—including Reid Hoffman, Howard Schultz, Michael Seibel, Y Combinator, 8VC, The General Partnership, First Round Capital, Kapor Capital, XYZ Ventures, and Bronze Investments—Promise has earned accolades such as being named one of Fast Company's "World's Most Innovative Companies of 2022" and “Forbes Next Billion-Dollar Startups 2024,” as well as Y Combinator’s #1 GovTech startup.
We are excited to welcome a Founding Security Engineer who will be our first dedicated security generalist, responsible for establishing strategic direction and implementing tangible enhancements across our security landscape.
Our security team focuses on empowering Promise and its clients while ensuring a high standard of security. We strive to collaboratively solve challenges, with security being a key outcome.
Your Responsibilities
Develop and manage detection systems: create, fine-tune, and respond to Python-based rules to identify anomalous activities and enhance signal clarity.
Collaborate with our Infrastructure team to secure GCP and cloud networking while enhancing Kubernetes security.
Enhance application security and facilitate pragmatic upgrades (e.g., Next.js, dependencies).
Boost security through code and automation (guardrails, checks, remediation workflows).
Take ownership of the vulnerability management process: identify, prioritize, and ensure fixes are completed in collaboration with code owners.
Foster a strong security culture through clear guidance, training, and partnership with engineering teams.
Create technical and policy frameworks to support ambitious and secure AI integration across the company.
Work closely with engineering on secure product design and technical implementation.

