Lead Security Engineer at Dave
Job Description
Who we are
Dave is on a mission to build products that level the financial playing fieldâą. We believe in financial opportunity for everyday Americansâbecause we all deserve a banking system that works for us, not against us. Our members hustle to make money work for them. They donât need a hero. They need a system that isnât designed to hold them down. Thatâs where we come in.
Why this role matters
Security at Dave protects more than infrastructureâit protects trust. As Lead Security Engineer, youâll be the technical lead for DFIR (Digital Forensics and Incident Response). Youâll own and evolve our detection and response program as we growâand work on systems that protect millions of members.
Over the years, weâve made incremental DFIR improvements. But with our scale and user base today, we need a programmatic approachâgrounded in clear triage, smart automation, and tooling that scales. Youâll drive that transformation.
You wonât be starting from zeroâwe have qualified tools (e.g., CrowdStrike, Upwinds, Chronicle) and logging pipelines in place. But digital forensics is early-stage and currently vendor-reliant. Youâll lead the shift toward in-house capability, maturity, and clarity across the stack.
What youâll tackle
Lead DFIR at Dave. Own the vision and execution for digital forensics and incident response across cloud, endpoint, and SaaS.
Build what matters. Establish core forensics workflows, evolve our SIEM, and mature our ability to respondânot just react.
Scale detection. Own detection off of CrowdStrike, tune Chronicle outputs, and build noise-resistant alert handling.
Drive coverage. Partner on Upwinds CDR deployments, increasing breadth and depth of coverage across infra and SaaS.
Automate and teach. Write tooling (Python, Terraform) that outlasts incidentsâand empower others to respond, even without deep DFIR background.
Triage, clarified. Lead efforts to define what clarity looks like when incidents hitâso response is calm, fast, and confident.
What success looks like
In your first year, youâll:
Stand up a reliable in-house digital forensics capability
Formalize alert pipelines and triage processes across core tools (CrowdStrike, Chronicle, Upwinds, etc.)
Deliver real reductions in MTTD and MTTRâwhile increasing team trust in our alerts
Proactively strengthen detection through vulnerability triage, threat modeling, and purple teaming
Be seen as the driver of DFIR strategy and executionânot just the responder
Whatâs ahead
Youâll lead some of the most critical security projects weâve ever taken on:
Standing up new detection and response tooling
Replacing vendor forensics with in-house pipelines
Defining what âclarity of triageâ means in a high-growth org
Building systems that protect members and enable engineersânot slow them down
What makes a high performer in this role
You own problems, not just tasksâand bring them to resolution
You prioritize automation over manual toil and iterate with purpose
You lead by teaching and enabling, not gatekeeping
You see around corners, proposing improvements before others feel the pain
You think in systems, not just scripts
Youâll thrive here if you have
6+ years in DFIR, detection engineering, or incident response roles
Strong hands-on experience with cloud-first environments (GCP preferred)
Proficiency with EDR (e.g., CrowdStrike), SIEM (e.g., Chronicle), and CDR tooling (e.g., Upwinds)
Python and Terraform fluency for automation and deployment
A clear communicator under pressureâable to drive calm, cross-functional collaboration
A mindset that security should accelerate, not hinder, the business
Bonus points for
Experience building DFIR programs in-house
Certifications like GCIH, GCFA
Familiarity with SaaS and endpoint hardening
Prior work in remote-first security teams
Donât let imposter syndrome get in your way of an incredible opportunity. Weâre looking for people who can help us achieve our mission and vision, not just check off the boxes. If youâre excited about this role, we encourage you to apply. You may just be the right candidate for this or other roles.
Why youâll love working here:Â
At Dave, our people are just as important as our product. Our culture is a reflection of our values that guide who we are, how we work, and what we aspire to be. Daves are member centric, helpful, transparent, persistent, and better together. We strive to create an environment where all Daves feel valued, heard, and empowered to do their best work. As a virtual first company, team members can live and work anywhere in the United States, with the exception of Hawaii.Â
A few of our benefits & perks:
đ Opportunity to tackle tough challenges, learn and grow from fellow top talent, and help millions of people reach their personal financial goals
đ» Flexible hours and virtual first work culture with a home office stipend
đ„ Premium Medical, Dental, and Vision Insurance plans
đ¶ Generous paid parental and caregiver leave
đ° 401(k) savings plan with matching contributions
đ Financial advisor and financial wellness support
đïž Flexible PTO and generous company holidays, including Juneteenth and Winter Break
đ All-company in-person events once or twice a year and virtual events throughout to connect with your team members and leadership team
Dave Operating LLC is proud to be an Equal Employment Opportunity employer and is dedicated to cultivating a diverse and inclusive workplace. We will consider for employment all qualified applicants and do not discriminate on any basis protected by federal, state, or local law, including the City of Los Angelesâ Fair Chance Initiative for Hiring Ordinance relating to an applicant's criminal history.
#LI-REMOTE
