Founding Security Engineer

Promise · Washington, D.C.

Ashby Posted Feb 15, 2026 First seen May 22, 2026

Company Overview

Promise modernizes how government agencies and utilities support people in financial difficulty. We build technology that makes it simple for residents to receive benefits, engage with assistance programs, set up flexible payment plans, and stay on track—while helping agencies increase efficiency, recover revenue, and deliver services with dignity. Our mission is to transform public systems so they work better for everyone, especially the most vulnerable.

Our team includes experts from companies like Palantir, Google, Stripe , and esteemed government leaders. We work hard and believe deeply in what we do. We're looking for excellent people to build innovative, resilient technology.

Backed by over $50 million in funding from top investors – such as Reid Hoffman, Howard Schultz, Michael Seibel, Y Combinator, 8VC, The General Partnership, First Round Capital, Kapor Capital, XYZ Ventures, and Bronze Investments – Promise has been recognized as one of Fast Company's "World's Most Innovative Companies of 2022,” “Forbes Next Billion-Dollar Startups 2024,” and Y Combinator’s #1 GovTech startup.

About the Role

Promise is looking for a Founding Security Engineer to accelerate our business. This role requires you to work closely with builders of varying technical depth, enabling our business’s ambitious goals while guaranteeing the high standard of security that our clients expect.

The work spans the breadth of enterprise security and product security, and frequently requires hands-on building to drive important security outcomes. If you like solving complex security problems in a rapidly-evolving tech landscape with an ambitious team, this is the role for you.

What You'll Do

  • Partner closely with engineering to embed security best practices into product design and technical implementation, enabling the organization to move quickly without compromising on security.

  • Build and run detection: write, tune, and respond to Python-based rules to catch anomalous activity and improve signal-to-noise.

  • Partner with our Infrastructure team to secure GCP + cloud networking and improve Kubernetes security.

  • Strengthen application security and help make pragmatic upgrades (e.g., Next.js, dependencies).

  • Improve security through code + automation (guardrails, checks, remediation workflows).

  • Own vulnerability management end-to-end: identify, prioritize, and drive fixes to closure in coordination with codeowners.

  • Build infrastructure and processes to increase company velocity while upholding a high security standard.

  • Develop technical and policy frameworks to guide ambitious and safe AI adoption company-wide.

What Will Help You Succeed

  • 5–10 years of experience, with meaningful time focusing on security.

  • Creative and collaborative problem solving, with an emphasis on enablement not obstruction.

  • Strong understanding of cloud security + networking (GCP preferred).

  • Comfortable reading code and shipping fixes; Python scripting strongly preferred.

  • Experience operating security tooling (endpoint/EDR, MDM, audit logging/alerting, CSPM).

  • Familiarity with GitHub, Terraform, and CI/CD security fundamentals.

Nice to Have

  • WAFs / web app security controls

  • Threat modeling experience

  • Deep Kubernetes hardening/runtime experience

Who Thrives at Promise

You’ll love it here if:

  • You are energized by big, complex challenges and the opportunity to solve them.

  • You want your work to have a real, measurable impact on people’s lives.

  • You take ownership and run toward problems, not away from them.

  • You value clear, candid, and constructive communication.

Promise is not for you if:

  • You prefer hierarchy and rigid structures. We operate with freedom and responsibility.

  • You are uncomfortable with change. We move fast, adapt often, and expect agility.

  • You want a typical corporate culture. We are mission-driven, ambitious, and direct.

  • You believe efficiency means “doing less.” We believe efficiency means doing better.

 

How We Support Our People

At Promise, we invest in our team’s well-being, growth, and sense of ownership.

  • Equity for All: All full-time employees receive stock options to share in our company’s success.

  • 100% Paid Health Coverage: We cover 100% of base medical, dental, and vision insurance plans for employees and their dependents.

  • Hybrid Work: We collaborate in the office at least four days a week to stay connected and aligned as a team.

  • Flexible Time Off: Self-managed FTO and 12 paid holidays — we trust you to balance your work and your life.

Please note: Benefits are reviewed periodically and may be updated at the sole discretion of Promise.

Promise is an equal opportunity employer and does not discriminate against any applicant or employee because of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, genetic information, age, or military or veteran status. Additionally, the Company complies with applicable state and local laws governing non-discrimination in employment in every jurisdiction in which it operates. Promise is committed to promoting diversity and inclusion in the workplace. We also provide reasonable accommodations to qualified individuals with disabilities, pregnant individuals, and those with sincerely held religious beliefs, in accordance with applicable laws. To request a reasonable accommodation, please email accommodations@joinpromise.com.

Promise engages in US government contracts and restricts hiring to US persons, which includes US citizens and permanent residents (e.g., Green Card holders). Additionally, candidates must reside in the US.

Promise participates in E-Verify. To learn more, view E-Verify Participation Notice and Right to Work Notice.