Member of Technical Staff (Security)
Footprint
- Location
- New York City
- Employment
- Full Time
- Work model
- On-Site
- Level
- Staff
- Posted
- 2h ago
Skills
About this role
We're building Percy, the AI agent that runs financial crime investigations end to end. Compliance teams at banks and fintechs are drowning in financial crimes investigations. Transaction volumes are surging, regulators keep raising the bar, and the work still runs on manual review queues that take hours and are stitched together from legacy vendors. We believe AI will make most of these decisions within a few years, so we built Percy to handle them. Percy learns each team's procedures and makes the same calls their analysts would: clearing false positives, escalating real risk, writing the case narrative, and documenting every decision for audit. It cuts review workloads by 70%+ and routinely catches fraud that human reviewers miss. Percy is only possible because of the identity platform we've spent four years building underneath it. Because we own the entire identity flow, Percy resolves ambiguity at the source, running its own checks across our verification tools before a case ever reaches a human. We're backed by QED, Index, Box Group, and Lerer Hippeau, and trusted by companies like Bilt, Nuvei, and MoonPay. We 5x'd revenue last year and plan to do it again in 2026. The team is small, senior, and ships fast.
The Role
Footprint sells trust to banks and fintechs: verify an identity, vault the PII, and prove to an auditor that every step was done correctly. The architecture reflects four years of that job. Identity records live in an AWS Nitro Enclave-backed vault as an append-only ledger, and our SDKs collect sensitive data straight from end-user devices. This year the surface changed. Percy, our AI agent platform, now runs AI-powered agents in isolated Modal sandboxes that make compliance and risk decisions on live PII. An agent that acts on real identity data raises new questions: what the sandbox can reach, and how does a person's most sensitive data stay safe while an AI system works on it. At the same time, our customers' diligence teams keep asking harder security questions, because our audit trails are part of what they're buying. Footprint was built with strong security foundations, but we're hiring the first person to fully own the product's security boundary end to end. This is an engineering seat: you'll spend most of your time in the product, with security as your lens. You'll inherit a real security architecture: hardware attestation, KMS-based key management, an audit ledger designed to be tamper-evident, secret management, and compliance programs that already pass their audits. Assessment, hardening, security tooling, and the standards engineering builds against all become yours. You'll report directly to the Head of Engineering - Elliott Forde.
What You'll Own
Vault and enclave security. The Nitro Enclave-backed vault holds millions of identity records. Encryption, key management, hardware attestation, the integrity of the append-only audit ledger, and cross-tenant isolation are yours to assess, harden, and stand behind The Percy sandbox boundary. The agents run in isolated Modal sandboxes against live PII. Sandbox isolation, token scoping, network egress, and the integrity of agent audit logs are the newest and fastest-moving part of this job - you set the standards here The end-user data path. From a stranger's phone through our SDKs into the vault: PII collection, document capture, and the generative UI layer that renders screens off agent decisions. You own the security review of everything that touches an end user Document pipeline integrity. Forged documents are an adversarial input, and the attackers iterate. Tamper detection, classification, and fraud checks all have to hold against that - adversarial robustness of this pipeline is yours Product security in our compliance programs. Footprint runs SOC 2 Type 2, PCI DSS Level 1, GDPR, and ISO 27001. The programs have their own owner, but the product-security controls inside them are yours: the technical evidence, the remediations, and the deep