HimalayasHimalayas logo
OC

Senior Security Engineer, Product Security

Ocrolus is a document AI platform that enables faster and more accurate financial decision-making for lenders.

Ocrolus

Employee count: 501-1000

India only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Come build at the intersection of AI and fintech. At Ocrolus, we’re on a mission to help lenders automate workflows with confidence—streamlining how financial institutions evaluate borrowers and enabling faster, more accurate lending decisions.

Our AI workflow and analytics platform for lenders is trusted at scale, processing nearly one million credit applications every month across small business, mortgage, and consumer lending. By integrating state-of-the-art open- and closed-source AI models with our human-in-the-loop verification engine, Ocrolus captures data from financial documents with over 99% accuracy. Thanks to our advanced fraud detection and comprehensive cash flow and income analytics, our customers achieve greater efficiency in risk management, and provide expanded access to credit—ultimately creating a more inclusive financial system.

Trusted by more than 400 customers—including industry leaders like Better Mortgage, Brex, Enova, Nova Credit, PayPal, Plaid, SoFi, and Square—Ocrolus stands at the forefront of AI innovation in fintech. Join us, and help redefine how the world’s most innovative lenders do business.

Summary:
Ocrolus is a fast-growing financial technology SaaS (Software-as-a-Service) organization. We are building a world-class security program to secure Ocrolus and our customers' data. We are looking for diverse security practitioners to help us design, build, and scale product security at Ocrolus. We value critical thinking, creativity, data-driven and intelligence-driven approaches, and offensive experience. Security is a collaborative process, where security is a partner to help achieve business goals securely. We believe in saying “yes and;” instead of “no” when recommending security objectives. We don’t believe in using fear or penalty for the enforcement of security policies and processes, and we will always provide evidence and justification for security controls.

What you’ll do:

  • Work closely with the CISO to build the product security strategy, roadmap, and metrics to measure and monitor product security posture.
  • Conduct design and architecture reviews for Ocrolus products and infrastructure.
  • Perform code reviews and application security assessments, including AI/LLMs.
  • Engage with the development teams to conduct secure design reviews/threat modeling exercises.
  • Identify vulnerabilities/threats that could affect Ocrolus products through independent research and work with the developers on workarounds/mitigation plans.
  • Be the go-to person for developers in solving critical issues relating to secure product development.
  • Run penetration testing targeting critical data, services, and environments. Report underlying security issues and propose enhanced security protections.
  • Write and disseminate security guidelines for common security issues, remediation, and security technology baselines.
  • Collaborate with stakeholders to ensure secure deployment of AI systems by staying updated on AI security best practices and executing adversarial testing strategies.
  • Guide engineering teams on secure coding and testing principles/practices.
  • Be a role model for the team and provide a healthy platform for learning and growth. Build relationships with stakeholders throughout the engineering and product organizations.
  • Spread security culture throughout the organization.

What you'll bring:

  • A passion for identifying vulnerabilities and remediations.
  • Ability to interpret and explain multiple classes of vulnerabilities, such as cross-site scripting, SQL Injection, CSRF, cryptographic-related weakness, and code injection, to various audiences, such as development and management teams.
  • Experience in designing and building a wide variety of technical security controls.
  • Experience in performing threat modeling, design reviews, code reviews, web application security, and enterprise cloud penetration testing.
  • Stellar understanding of secure software development lifecycle (SDLC) and ability to integrate security practices and threat modeling into development processes.
  • Ability to automate product security processes and optimize productivity with SAST & DAST tools.
  • Good proficiency with a programming language (e.g., Java, Python, Go, Bash).
  • Good Knowledge of authentication, authorization, and access control mechanisms, cryptographic algorithms, and secure network communication protocols
  • Experience in cloud security architecture and infrastructure.
  • Self-driven with excellent communication and prioritization skills.
  • A total of 4+ years of experience in product security (code, web application, API)

Good to have:

  • Published CVEs / articles on application security
  • Contributions to open-source security software
  • Certified in application security, pen testing (e.g., OSCP)

Note: This is a remote position based in India.

Life at Ocrolus

We’re a team of builders, thinkers, and problem solvers who care deeply about our mission — and each other. As a fast-growing, remote-first company, we offer an environment where you can grow your skills, take ownership of your work, and make a meaningful impact.

Our culture is grounded in four core values: Empathy – Understand and serve with compassion
Curiosity – Explore new ideas and question the status quo Humility – Listen, be grounded, and remain open-minded
Ownership – Love what you do, work hard, and deliver excellence

We believe diverse perspectives drive better outcomes. That’s why we’re committed to fostering an inclusive workplace where everyone has a seat at the table, regardless of race, gender, gender identity, age, disability, national origin, or any other protected characteristic.

We look forward to building the future of lending together.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Experience

4 years minimum

Location requirements

Hiring timezones

India +/- 0 hours

About Ocrolus

Learn more about Ocrolus and their company culture.

View company profile

What began as an idea in a parent's kitchen has blossomed into a transformative force in the financial technology sector. Ocrolus was founded in 2014 by Sam Bobley, who, at the age of 22, embarked on a journey to solve a significant challenge in the financial industry: the manual and error-prone process of analyzing financial documents. The initial spark for Ocrolus came from the convoluted world of Medicaid application processing, where the sheer volume of financial paperwork created massive inefficiencies. This firsthand observation of a broken system fueled the creation of a platform that could automate and bring precision to document-driven workflows. The company's early days were characterized by a relentless drive to build a technology that could read and understand financial documents with unparalleled accuracy, a stark contrast to the existing OCR solutions that fell short.

Today, Ocrolus stands as a leader in AI-driven document automation, serving a diverse clientele that includes some of the biggest names in fintech, mortgage lending, and banking like PayPal, SoFi, and Plaid. The company's innovative approach combines the power of artificial intelligence with a human-in-the-loop verification process, ensuring over 99% accuracy in data extraction. This unique fusion of machine intelligence and human oversight has become the cornerstone of their success, enabling lenders to make faster, more informed, and more confident credit decisions. From its humble beginnings, Ocrolus has grown into a global team with a strong presence in New York City, empowering financial institutions to level the playing field for borrowers by providing expanded access to credit at a lower cost. The journey from a kitchen table startup to a key player in the digital lending ecosystem is a testament to the company's unwavering commitment to innovation, accuracy, and its mission to revolutionize financial services.

Claim this profileOC

Ocrolus

Company size

501-1000 employees

Founded in

2014

Chief executive officer

Sam Bobley

Employees live in

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

12 remote jobs at Ocrolus

Explore the variety of open remote roles at Ocrolus, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Ocrolus

Remote companies like Ocrolus

Find your next opportunity by exploring profiles of companies that are similar to Ocrolus. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan