Senior Security Engineer
First security engineer to own application security, compliance programs (SOC 2, ISO 27001), and enterprise customer security reviews for an AI-native social commerce platform.
About the job
What You'll Be Doing
- Own the security of our deployed applications, including threat modeling, secure design reviews, and finding and fixing vulnerabilities across our services and AI infrastructure
- Lead new compliance initiatives (SOC 2, and frameworks like ISO 27001, GDPR, and CCPA as we scale), establishing the controls, policies, and evidence to back them
- Own the security side of the sales cycle: complete customer security questionnaires, support enterprise security reviews, and act as our expert in vendor assessments
- Build and run our vulnerability management, secrets management, identity and access, and security monitoring practices
- Manage third-party risk and our penetration-testing program
What We're Looking For
- 5+ years in security engineering, application/product security, or a related role at a software company
- Strong application and cloud security fundamentals; able to reason about the security of real production systems and AI workloads, not just policy
- Hands-on experience leading or operating a compliance program (SOC 2, ISO 27001, or similar) end to end
- Solid programming skills to build security tooling and automation, and to work credibly alongside engineers
- Comfortable operating in fast-moving startup environments with high ownership and autonomy
Bonus Points
- Experience establishing a security and compliance function at an early-stage or rapidly scaling SaaS company
- Familiarity with AWS, Pulumi, Postgres, ClickHouse, Turbopuffer, or Temporal
What We Offer
- Competitive compensation and early equity
- Health, vision, and dental benefits plus 401(k) match
- Clear career growth opportunities as the company scales
- Free lunch in the heart of University Ave. in Palo Alto
- Deep exposure to cutting-edge AI tooling and the opportunity to shape how brands use it
- A collaborative, ambitious team defining a new category of AI-native marketing infrastructure
Skills
AWS, Pulumi, Postgres, ClickHouse, Turbopuffer, Temporal, SOC 2, ISO 27001, GDPR, CCPA
Similar jobs
Security Engineering jobsBuild secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.