About the job
At Credit Karma, we are driven by our mission to empower financial progress for over 140 million members worldwide. Known for our pioneering approach to providing free credit scores, we offer a comprehensive suite of services aimed at helping members achieve their financial goals. Our offerings include identity monitoring, credit card applications, insurance shopping, and savings and checking accounts— all at no cost. With a workforce exceeding 1,700 employees, our presence spans across several cities, including Oakland, Charlotte, Culver City, San Diego, London, Bangalore, and New York City.
*Banking services are provided by MVB Bank, Inc., Member FDIC*
Key Responsibilities
- Drive strategic initiatives to identify and mitigate security risks across the organization's infrastructure.
- Implement and optimize security controls and tools within cloud infrastructure, focusing on vulnerability management, container security, and supply chain security.
- Work within a cloud-native environment utilizing containerized workloads, serverless architecture, and automated CI/CD pipelines to manage Infrastructure-as-a-Service.
- Develop scripts and automation tools to streamline security processes and eliminate redundant tasks.
- Utilize Terraform to establish security baseline controls, conduct code reviews, and recommend enhancements for improved security measures.
- Research and promote emerging technologies, architectures, and security products that align with security strategies to address evolving threat vectors.
- Develop and maintain Agentic AI solutions for automating remediation of known vulnerabilities and ensuring security guardrails for pre-merge validation.
- Enhance user activity monitoring and enforce the principle of least privilege for all cloud identities.
- Define, document, and implement security standards, guidelines, and procedures for secure operations in a cloud environment.
- Participate in on-call support for security tickets and serve as a Security System SRE on a rotational basis.
- Collaborate with engineering and operations teams to implement controls and processes addressing identified security gaps.
- Identify and remediate security vulnerabilities and incidents.
Qualifications
- Bachelor's degree or equivalent experience, with a minimum of 6 years in security engineering.
- Proficiency in Applied Generative AI (LLMs/Agents) for security automation.
- Strong knowledge of cloud security best practices and tools.
- Experience with scripting languages for security tooling development.
- Familiarity with Terraform and CI/CD processes.

