About Reap
Reap is a global financial technology company headquartered in Hong Kong with employees across multiple countries. We enable financial connectivity and access for businesses worldwide by combining traditional finance with stablecoins for efficient money movement.
Through our stablecoin-powered corporate cards, payments, and expense management tools, we streamline financial operations and help businesses scale. Our APIs enable businesses to integrate stablecoin-enabled finance into their own products and services—from issuing Visa cards to facilitating cross-border payments.
Backed by leading investors including Acorn Pacific, Index Ventures and HashKey Capital, Reap is building the future of borderless, stablecoin-enabled finance.
Why Reap
This team owns the shared security and identity foundations that every other engineering team at Reap builds on: authentication and identity, fraud and account takeover protection, access governance, data residency and routing, and notifications infrastructure. As we expand into new markets and products, these foundations must help teams ship faster while protecting our business and clients from unnecessary loss.
This role is a senior individual contributor position, acting as the Tech Lead for our Security and Identity Platform. You'll own technical direction, architecture, and delivery while staying hands-on with the code — no people management is required. You'll build these capabilities as one connected, trusted platform, rather than separate solutions that each product team has to reinvent. It's an opportunity to make security an enabler of growth in a regulated, global fintech.
Your Mission Awaits
- Authentication & identity: Architect, build, and operate the shared identity layer across Reap's products, including login, session management, and multi-factor authentication. Design secure, reusable APIs and services that other engineering teams can adopt confidently.
- Fraud & account protection: Build platform capabilities that detect and prevent unauthorised access and account takeover before funds move. Partner with product and risk stakeholders to translate threats into practical controls that protect clients without unnecessary friction.
- Access governance & auditability: Develop consistent authorisation and access controls, with reliable audit trails that support access reviews, incident investigation, and regulatory, partner, and client security requirements.
- Data residency & routing: Design secure data and traffic routing that supports jurisdiction-specific requirements as Reap enters new markets, working with relevant stakeholders to turn those requirements into reusable platform capabilities.
- Notifications infrastructure: Build reliable, correctly targeted infrastructure for security, risk, and transaction alerts, with the delivery speed and visibility needed when something goes wrong.
- Secure delivery & reliability: Build and operate services on AWS using CI/CD and infrastructure-as-code (IaC). Embed threat modelling, security testing, monitoring, logging, and alerting into delivery; investigate incidents and address root causes to prevent recurrence.
- Technical leadership & platform adoption: Own architecture and design reviews, set engineering standards, and mentor engineers while remaining hands-on. Partner with the Knox PM and other engineering teams to prioritise work that reduces risk, unlocks markets, and removes duplicated effort. Provide clear APIs, defaults, and documentation that make the secure path easy to adopt.
- AI-assisted engineering: Use AI tools responsibly for coding, debugging, tests, and documentation, with appropriate review and safeguards for sensitive data and security-critical code.
Your Superpowers
- Experience: 8–10+ years in backend or platform engineering, including hands-on ownership of security-critical services or shared identity and access infrastructure in production.
- Leadership: At least 2+ years in a technical leadership role (Tech Lead or Engineering Manager), with a track record of owning architecture decisions, mentoring engineers, and delivering complex projects end to end. Comfortable leading through technical expertise in an individual contributor role.
- Security & identity engineering: Strong understanding of authentication, authorisation, session security, MFA, and access control. Experience implementing identity standards such as OAuth 2.0 and OpenID Connect, and applying secure-by-design practices, threat modelling, and least privilege.
- Backend: Preferably Node.js + TypeScript, with strong experience building APIs and event-driven/serverless systems. Open to strong backend engineers using other languages (e.g., Go, Java, Python) who can ramp up quickly.
- Cloud & delivery: Strong AWS experience, including securing and operating production services, with solid CI/CD and infrastructure-as-code practices.
- Data & auditability: Hands-on experience with relational databases (AWS Aurora, PostgreSQL, MySQL), schema design, and ORM frameworks such as TypeORM. Able to design for sensitive data protection, traceability, and reliable audit trails.
- Systems thinking & problem solving: Able to reason about threats, failure modes, and dependencies across services; debug complex issues; and balance security, reliability, developer experience, and delivery speed.
- AI-assisted coding: Comfortable using AI coding tools (e.g., Cursor, GitHub Copilot, Claude Code, Codex), with sound judgement about data handling and validation of generated code.
- Domain advantage: Experience with fraud prevention, account takeover protection, data residency, or security platforms in fintech, payments, crypto, or other regulated environments is a plus.
- Cybersecurity credentials: Relevant cybersecurity certifications are a plus.
Why You'll Love it Here
- A high-impact role in a rapidly growing fintech startup
- Flexible remote work environment with a global, collaborative team
- Use of AI tools at work, and the space to learn, experiment, and grow with them
- A culture of innovation, inclusion, and continuous learning
After submitting your application, please check your inbox for a confirmation email. If you don't see it, kindly check your spam or junk folder and adjust your settings to ensure future communication reaches your inbox. You can follow the steps here.
