# Security Engineer

**Company:** [hud](https://hotfix.jobs/companies/hud)
**Location:** San Francisco, CA
**Role:** Security Engineering
**Skills:** Incident Response, Infrastructure Security, Cloud Security, Identity And Access Management, Threat Modeling, Authentication, Authorization, Secrets Management, SOC 2, Security Monitoring, AWS, Cves, Bug Bounty
**Posted:** 2026-09-09

> Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.

## Job Description

## Responsibilities
- Lead detection and incident response from signal and alert through postmortem.
- Own the security roadmap across product, cloud and infrastructure, corporate security, incident response, and compliance.
- Secure APIs, platforms, and data systems through threat modeling, design and code reviews, authentication and authorization controls, and secrets management.
- Build monitoring, detection, and incident-response capabilities; lead investigations and postmortems; and convert incidents and emerging threats into durable improvements.
- Own SOC 2 and customer trust, including control design, security questionnaires, policy management, vendor reviews, and audits.
- Partner with legal, commercial, engineering, and operations to translate customer contracts and data-license requirements into enforceable controls for data access, provenance, permitted use, retention, deletion, isolation, and auditability.

## Requirements
- Strong security engineering fundamentals and hands-on experience across multiple areas, such as infrastructure security, detection and response, and identity.
- Experience leading security incidents end-to-end, from detection and containment through root-cause analysis and follow-up engineering work.
- Experience implementing or operating SOC 2 or a comparable security framework, including translating requirements into technical and operational controls.
- High agency, sound judgment, risk prioritization, and the ability to drive implementation.
- Strong communication skills for working with founders, engineers, operations, legal, auditors, customers, and external partners.

## Nice-to-haves
- Experience as an early security hire or building a security program from scratch at a fast-growing startup.
- Experience securing AI/ML infrastructure, agent execution environments, data platforms, developer tools, or systems that run untrusted code or process sensitive data.
- Experience protecting licensed, proprietary, or customer-provided data and operationalizing contractual requirements around access, use, retention, and deletion.
- Experience finding CVEs, creating security tooling on GitHub, participating in bug bounty programs, giving conference talks, or writing security-related blog posts.
- OSCP, AWS Security Specialty, OSWE, CKS, or GIAC certifications.

## Compensation and Benefits
- Very competitive compensation.
- Company-paid medical, dental, and vision coverage for US employees.
- Lunch and dinner in the office.
- Company-wide holiday break, PTO, and paid holidays.
- Equinox membership, 401(k), and commuter benefits for US employees.
- Access to AI coding and productivity tools, including ChatGPT, Claude Code, and Cursor.
- Full-time, on-site role with offices in the San Francisco Bay Area and Singapore.
- Relocation and visa support for strong candidates joining the US or Singapore offices.

## Similar jobs

- [Security Engineer, Threat Intelligence](https://hotfix.jobs/jobs/a9d333c0-2242-416f-a470-d3a19f982046) - Fluidstack - New York, NY - $220k – $280k/yr
- [Security Scientist](https://hotfix.jobs/jobs/36a4a0c9-f833-41fb-bd29-ad40c4d5050f) - Figma - Remote - $140k – $348k/yr
- [Abuse Research Engineer](https://hotfix.jobs/jobs/2f1effd6-b955-48c7-9d30-3d0aed220264) - Stripe - Remote
- [Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e5c4fc22-2c3a-4334-8eae-e8ab5bcf2a8a) - Anthropic - San Francisco, CA - $300k – $320k/yr
- [Software Engineer, HSM Infrastructure Security, Consumer Devices](https://hotfix.jobs/jobs/c59b2911-dd77-45cf-a787-90da0f7be1b7) - OpenAI - San Francisco, CA - $347k – $445k/yr

**Apply:** https://hotfix.jobs/jobs/061a2617-4d6a-4cf3-96a0-ad832100d55f
**Canonical:** https://hotfix.jobs/jobs/061a2617-4d6a-4cf3-96a0-ad832100d55f