
Lead Security Engineer
Job Description
Posted on: January 26, 2026
Who We Are Dave is on a mission to build products that level the financial playing fieldâ˘. We believe in financial opportunity for everyday Americansâbecause we all deserve a banking system that works for us, not against us. Our members hustle to make money work for them. They donât need a hero. They need a system that isnât designed to hold them down. Thatâs where we come in. Why this role matters Security at Dave protects more than infrastructureâit protects trust. As Lead Security Engineer, youâll be the technical lead for DFIR (Digital Forensics and Incident Response). Youâll own and evolve our detection and response program as we growâand work on systems that protect millions of members. Over the years, weâve made incremental DFIR improvements. But with our scale and user base today, we need a programmatic approachâgrounded in clear triage, smart automation, and tooling that scales. Youâll drive that transformation. You wonât be starting from zeroâwe have qualified tools (e.g., CrowdStrike, Upwinds, Chronicle) and logging pipelines in place. But digital forensics is early-stage and currently vendor-reliant. Youâll lead the shift toward in-house capability, maturity, and clarity across the stack. What Youâll Tackle
- Lead DFIR at Dave. Own the vision and execution for digital forensics and incident response across cloud, endpoint, and SaaS.
- Build what matters. Establish core forensics workflows, evolve our SIEM, and mature our ability to respondânot just react.
- Scale detection. Own detection off of CrowdStrike, tune Chronicle outputs, and build noise-resistant alert handling.
- Drive coverage. Partner on Upwinds CDR deployments, increasing breadth and depth of coverage across infra and SaaS.
- Automate and teach. Write tooling (Python, Terraform) that outlasts incidentsâand empower others to respond, even without deep DFIR background.
- Triage, clarified. Lead efforts to define what clarity looks like when incidents hitâso response is calm, fast, and confident.
What Success Looks LikeIn your first year, youâll:
- Stand up a reliable in-house digital forensics capability
- Formalize alert pipelines and triage processes across core tools (CrowdStrike, Chronicle, Upwinds, etc.)
- Deliver real reductions in MTTD and MTTRâwhile increasing team trust in our alerts
- Proactively strengthen detection through vulnerability triage, threat modeling, and purple teaming
- Be seen as the driver of DFIR strategy and executionânot just the responder
Whatâs Ahead Youâll lead some of the most critical security projects weâve ever taken on:
- Standing up new detection and response tooling
- Replacing vendor forensics with in-house pipelines
- Defining what âclarity of triageâ means in a high-growth org
- Building systems that protect members and enable engineersânot slow them down
What Makes a High Performer In This Role
- You own problems, not just tasksâand bring them to resolution
- You prioritize automation over manual toil and iterate with purpose
- You lead by teaching and enabling, not gatekeeping
- You see around corners, proposing improvements before others feel the pain
- You think in systems, not just scripts
Youâll thrive here if you have
- 6+ years in DFIR, detection engineering, or incident response roles
- Strong hands-on experience with cloud-first environments (GCP preferred)
- Proficiency with EDR (e.g., CrowdStrike), SIEM (e.g., Chronicle), and CDR tooling (e.g., Upwinds)
- Python and Terraform fluency for automation and deployment
- A clear communicator under pressureâable to drive calm, cross-functional collaboration
- A mindset that security should accelerate, not hinder, the business
Bonus points for
- Experience building DFIR programs in-house
- Certifications like GCIH, GCFA
- Familiarity with SaaS and endpoint hardening
- Prior work in remote-first security teams
Donât let imposter syndrome get in your way of an incredible opportunity. Weâre looking for people who can help us achieve our mission and vision, not just check off the boxes. If youâre excited about this role, we encourage you to apply. You may just be the right candidate for this or other roles. Why Youâll Love Working Here At Dave, our people are just as important as our product. Our culture is a reflection of our values that guide who we are, how we work, and what we aspire to be. Daves are member centric, helpful, transparent, persistent, and better together. We strive to create an environment where all Daves feel valued, heard, and empowered to do their best work. As a virtual first company, team members can live and work anywhere in the United States, with the exception of Hawaii. A Few Of Our Benefits & Perks đ Opportunity to tackle tough challenges, learn and grow from fellow top talent, and help millions of people reach their personal financial goals đť Flexible hours and virtual first work culture with a home office stipend đĽ Premium Medical, Dental, and Vision Insurance plans đś Generous paid parental and caregiver leave đ° 401(k) savings plan with matching contributions đ Financial advisor and financial wellness support đď¸ Flexible PTO and generous company holidays, including Juneteenth and Winter Break đ All-company in-person events once or twice a year and virtual events throughout to connect with your team members and leadership team Dave Operating LLC is proud to be an Equal Employment Opportunity employer and is dedicated to cultivating a diverse and inclusive workplace. We will consider for employment all qualified applicants and do not discriminate on any basis protected by federal, state, or local law, including the City of Los Angelesâ Fair Chance Initiative for Hiring Ordinance relating to an applicant's criminal history.
Apply now
Please let the company know that you found this position on our job board. This is a great way to support us, so we can keep posting cool jobs every day!
ReactRemoteJobs.com
Get ReactRemoteJobs.com on your phone!
