Cardless logo

Product Security Lead

CardlessSan Francisco, California

$190,000 - $260,000 / year

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Overview

Schedule
Full-time
Career level
Director
Remote
On-site
Compensation
$190,000-$260,000/year
Benefits
Health Insurance
Dental Insurance
Vision Insurance

Job Description

Cardless is the infrastructure that lets consumer brands put credit cards directly in their own product. Instead of sending customers off to a bank's website to manage their card, our platform handles the credit program end-to-end (applications, underwriting, servicing, rewards, compliance), so brands can build the card experience inside their own ecosystem. We power programs for Coinbase, Bilt, Qatar Airways, Alibaba, and others. We've raised $170M to date, most recently a $60M Series C led by Spark Capital.

We're hiring a Product Security Lead to drive how we build security into the platform. The work spans authentication, authorization, anti-abuse controls, in-product fraud primitives, and the secure-by-design practices that come with running credit infrastructure for partners of this caliber. The role is hands-on and deeply cross-functional, working with Engineering, Risk, Compliance, Legal, and Data. You'll report to the Head of Engineering.

Responsibilities

  • Own the security model for our partner-facing APIs: authentication, authorization, tenant isolation, abuse prevention, signing, and audit logging.

  • Drive a coherent auth strategy across services and surfaces, including step-up auth for sensitive actions and a strong-auth roadmap (passkeys and beyond).

  • Build the device telemetry, behavioral signals, and velocity primitives that fraud and risk functions depend on.

  • Be the secure-by-design partner with Engineering โ€” sit in on architecture reviews before features ship, write the threat models, own the tradeoffs.

  • Own secure SDLC: SAST/DAST, dependency scanning, secret detection, and the security tooling engineers interact with daily.

  • Coordinate with our infrastructure team to improve our security posture across the stack: from infrastructure, to supply chain, to first-party applications, to third-party dependencies and SaaS platforms.

  • Be the technical authority on sensitive payment data. Keep the footprint small and well-defined as the platform grows.

  • Lead incident response on security events (containment, forensics, comms, blameless postmortems) and drive vulnerability remediation across services.

  • Own the relationship with our external security architecture partner: set priorities, scope engagements, integrate findings into our roadmap.

  • Serve as the technical counterpart to ensure compliance, translating SOC 2, PCI DSS, and other security frameworks into scalable engineering solutions and ensuring in-product controls are effective in practice - not just on paper.

What we look for

  • Strong programming skills in Java, Python, or a comparable language โ€” you write production code.

  • Experience designing or operating secure platform / B2B APIs at scale, especially in multi-tenant environments.

  • Background in anti-ATO, anti-fraud, or authentication systems at scale (consumer fintech, marketplace, or large consumer platform).

  • Working knowledge of AWS: IAM, KMS, networking, service-to-service auth.

  • Comfort with modern AI tooling (Claude, Copilot, and similar) as a daily force multiplier across code review, threat modeling, detection engineering, and security tooling.

  • Excellent written communication. You'll write threat models, postmortems, and partner-facing security responses.

  • Comfortable owning the security function in-house while leveraging external specialists as a force multiplier.

Nice to have

  • Fintech, payments, or other regulated environment experience.

  • Threat modeling methodology background (STRIDE, attack trees, or your own).

  • Experience working alongside or building for a risk / fraud operations team.

  • Experience operating a bug bounty or vulnerability disclosure program.

Why Cardless

You'll lead product security for a platform that powers some of the most recognizable card programs in the world. The work moves real dollars and real trust from the moment you ship. You'll have a real seat in every major architecture conversation, executive visibility, and an external security architecture partner you can lean on.

Benefits

  • ๐Ÿ’ธ Meaningful start-up equity

  • ๐Ÿฅ 100% health, vision & dental primary coverage

  • โž• 75% health, vision & dental dependent coverage

  • ๐Ÿฑ Catered lunches and dinners

  • ๐ŸšŽ $250/month commuter benefit

  • ๐Ÿ‘ถ Parental leave

  • โœˆ๏ธ Team building events

  • ๐ŸŒด Flexible PTO with a minimum of 15 days off per year

  • ๐Ÿ’ธ 401(k) plan

  • ๐Ÿš› Relocation assistance

Compensation

This role has an annual starting salary range of $190,000โ€“$260,000+ equity + benefits (see above). Actual compensation is influenced by a wide array of factors including but not limited to skills, experience, and specific work location.

Location

San Francisco, CA โ€” our office is in the Jackson Square district. This role is 5 days a week in office.

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.

pay-wall

FAQs About Product Security Lead Jobs at Cardless

What is the work location for this position at Cardless?
This job at Cardless is located in San Francisco, California, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at Cardless?
Candidates can expect a pay range of $190,000 and $260,000 per year.
What employment applies to this position at Cardless?
Cardless lists this role as a Full-time position.
What experience level is required for this role at Cardless?
Cardless is looking for a candidate with "Director" experience level.
What benefits are offered by Cardless for this role?
Cardless offers following benefits: Health Insurance, Dental Insurance, Vision Insurance, Family/Dependent Health, Paid Vacation, Parental and Family Leave, and Flexible/Unlimited PTO for this position. Actual benefits may vary depending on the employer's policies and employment terms.
What is the process to apply for this position at Cardless?
You can apply for this role at Cardless either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.