Clutch is hiring a Senior Software Engineer - Security to play a critical role in shaping our application and infrastructure security posture. You’ll be embedded in engineering, driving secure-by-design practices, threat modeling, and proactive risk mitigation.
What You'll Do
- Embed with engineering teams to review and co-develop security-critical features, providing practical guidance on secure design and implementation.
- Perform code and architecture reviews focused on identifying and mitigating risks in our backend services and web applications.
- Integrate developer-friendly security tooling (SAST, SCA, secret scanners) into our CI/CD pipelines and improve feedback loops.
- Work closely with developers to fix early security issues, promote secure coding standards, and minimize recurring vulnerabilities.
- Lead the design and rollout of a developer-focused Secure SDLC, with actionable security gates and clear ownership per stage.
- Collaborate with product and engineering to build features securely by default, including auth, encryption, and access control layers.
- Build internal tools or contribute to platform codebases to help automate threat detection or harden developer workflows.
- Launch an internal security knowledge base or playbook, based on real scenarios and tailored to Clutch’s tech stack and dev needs.
- Develop and maintain secure libraries and frameworks used across engineering (e.g., auth modules, secure wrappers, input validators).
- Contribute code and reviews to critical systems or developer tooling, ensuring security is deeply integrated.
- Support and mentor a security champion network inside engineering teams to scale knowledge and influence through code.
- Partner with developers to threat model new services and architecture evolutions, helping teams make informed trade-offs.
What We're Looking For
- 5+ years of experience in software/application security
- Deep knowledge of web application security, secure software design, API hardening, and threat modeling
- Experience integrating security into CI/CD pipelines, including use of SAST, DAST, SCA, and IaC scanning tools
- Strong coding background (e.g., Node.js, Python, Go) and ability to read, understand, and debug code securely
- Excellent communication skills, with the ability to influence without authority and foster cross-functional collaboration
Nice to Have
- Experience ideally in fast-growing startups or fintech environments
- Familiarity with common compliance frameworks (e.g., SOC 2, GLBA, PCI-DSS)
- Familiarity with cloud-native security (AWS, GCP preferred)
Technical Stack
- Node.js
- Python
- Go
- AWS
- GCP
Team & Environment
You will be embedded in engineering as part of the Security, Infrastructure & Platform team.
Benefits & Compensation
- Remote Flexibility: Enjoy the freedom of remote work from anywhere
- Unforgettable Off-Sites: Twice a year, bond with colleagues in exciting destinations
- Paid Time Off and National Holidays: Enjoy 20 PTO days yearly and the National Holidays
- Stock Options: Receive stock options as part of your compensation package
- Home Office Setup: Dedicated budget for home office essentials
- Work Trip Budget: Budget for work-related trips and co-working
Work Mode
This is a global, remote position. You can work from anywhere.
Clutch values pragmatism, ownership, and curiosity, and we are building a security-first engineering culture that enables teams to move fast responsibly.


