Senior Software Engineer, Security
Company: LoanCrate
Location: Los Angeles, CA (Remote)
Salary: $170,000 - $300,000 a year
Type: Full-time
Remote: Yes
Posted: 2026-04-13
About this role
## What is Loancrate?
We started Loancrate to make home-buying simpler and less expensive for lenders and borrowers (us!). Today, mortgage lenders are stuck running their companies on software products built 20 years ago. These products are slow, unstable, and don't lead to material improvements in efficiency. When using these systems, the average human cost to originate a loan is still over $11,000.
Loancrate builds AI-native tooling to automate mortgage workflows. Our ultimate goal is fully automated origination, which has the potential to save lenders over $16B in operating expense per year.
Since starting in 2020, our remote team has enabled our customers to power >$85 billion in new home loans. We are a group of people excited to tackle the complexity of the home-lending industry. We care about collaboration, very open communication covering the good & the bad so that we learn from our decisions quickly, and ultimately having fun while we’re building. You’ll fit in well if you like diving deep quickly!
## The Opportunity
We’re looking for a Senior Software Engineer, Security to help make Loancrate more secure without making it harder to build here.
This is a hands-on senior IC software engineering role for someone who specializes in security. You will work directly in our product and platform code, build internal tooling and guardrails, review designs and implementations, and help engineers eliminate classes of vulnerabilities at the source.
We handle highly sensitive personal and financial data, so security matters deeply here. But we believe good security work shows up as better architecture, safer defaults, useful tooling, and sound engineering judgment — not process theater.
This role is focused primarily on product security and security engineering: secure design, threat modeling, code review, authentication and authorization, secrets handling, CI/CD guardrails, and internal tooling. It is not primarily a compliance-management, endpoint-IT,...