Security Engineer
Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.
About the job
Responsibilities
- Lead detection and incident response from signal and alert through postmortem.
- Own the security roadmap across product, cloud and infrastructure, corporate security, incident response, and compliance.
- Secure APIs, platforms, and data systems through threat modeling, design and code reviews, authentication and authorization controls, and secrets management.
- Build monitoring, detection, and incident-response capabilities; lead investigations and postmortems; and convert incidents and emerging threats into durable improvements.
- Own SOC 2 and customer trust, including control design, security questionnaires, policy management, vendor reviews, and audits.
- Partner with legal, commercial, engineering, and operations to translate customer contracts and data-license requirements into enforceable controls for data access, provenance, permitted use, retention, deletion, isolation, and auditability.
Requirements
- Strong security engineering fundamentals and hands-on experience across multiple areas, such as infrastructure security, detection and response, and identity.
- Experience leading security incidents end-to-end, from detection and containment through root-cause analysis and follow-up engineering work.
- Experience implementing or operating SOC 2 or a comparable security framework, including translating requirements into technical and operational controls.
- High agency, sound judgment, risk prioritization, and the ability to drive implementation.
- Strong communication skills for working with founders, engineers, operations, legal, auditors, customers, and external partners.
Nice-to-haves
- Experience as an early security hire or building a security program from scratch at a fast-growing startup.
- Experience securing AI/ML infrastructure, agent execution environments, data platforms, developer tools, or systems that run untrusted code or process sensitive data.
- Experience protecting licensed, proprietary, or customer-provided data and operationalizing contractual requirements around access, use, retention, and deletion.
- Experience finding CVEs, creating security tooling on GitHub, participating in bug bounty programs, giving conference talks, or writing security-related blog posts.
- OSCP, AWS Security Specialty, OSWE, CKS, or GIAC certifications.
Compensation and Benefits
- Very competitive compensation.
- Company-paid medical, dental, and vision coverage for US employees.
- Lunch and dinner in the office.
- Company-wide holiday break, PTO, and paid holidays.
- Equinox membership, 401(k), and commuter benefits for US employees.
- Access to AI coding and productivity tools, including ChatGPT, Claude Code, and Cursor.
- Full-time, on-site role with offices in the San Francisco Bay Area and Singapore.
- Relocation and visa support for strong candidates joining the US or Singapore offices.
Skills
Incident Response, Infrastructure Security, Cloud Security, Identity And Access Management, Threat Modeling, Authentication, Authorization, Secrets Management, SOC 2, Security Monitoring, AWS, Cves, Bug Bounty
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.
Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.