Skip to content
SunoSunoBoston, MA

Lead Security Engineer

Leads hands-on security architecture and engineering across product and cloud environments, with responsibility for application security, cloud controls, incident response, and team development. Requires 10+ years of security engineering experience and deep expertise across multiple security domains.

275k – 395k/yr
On-site10+ YOESecurity Engineering

About the role

Responsibilities

  • Own security architecture and the roadmap across product and cloud environments.
  • Perform threat modeling to focus security efforts where they matter most.
  • Elevate application security practices, including securing the SDLC, establishing code-review guardrails, managing dependencies and secrets, and implementing pre-production security testing.
  • Drive cloud security across IAM and least privilege, account structure, network boundaries, and data-access controls.
  • Lead incident response, participate in an on-call rotation, and act as the senior responder during incidents.
  • Mentor and shape the security team and its operational processes.

Requirements

  • 10+ years of experience in security engineering.
  • Deep expertise in at least two of application security, cloud/infrastructure security, and incident response, with credibility in the third.
  • Experience creating security capabilities and setting technical direction rather than only operating established programs.
  • Strong cross-functional partnership skills.

Nice-to-Haves

  • Experience with consumer products at scale.
  • Exposure to AI/ML abuse or model security.
  • Experience as an early or founding security hire.

Compensation & Benefits

  • Compensation: $275,000 to $395,000.
  • Company equity package.
  • 401(k) with 3% employer match and Roth 401(k).
  • Medical, dental, and vision insurance, with PPO, HSA, and FSA options.
  • 11 paid holidays, unlimited PTO, and sick time.
  • 16 weeks of paid parental leave.
  • Creative education stipend.
  • Generous commuter allowance.
  • In-office lunch five days per week.
  • This role requires working onsite at one of three offices.

Skills

Application SecurityCloud Securityinfrastructure securityIncident ResponseThreat ModelingIAMSDLCCode Reviewsecrets managementpre-production security testingnetwork securityai/ml security
OpenAI

Offensive Security Engineer, Agent Security

OpenAISan Francisco, CA +3

Principal-level Offensive Security Engineer conducts red/purple team operations and penetration testing on AI agent products like Codex and Operator, hunting vulnerabilities in app-infra-model interactions and collaborating with defensive teams to strengthen security.

278k – 490k/yrRemote7+ YOESecurity Engineering
Fluidstack

Security Lead, Deployment & Ops

FluidstackNew York, NY +2

Own physical security end-to-end for greenfield hyperscale data center builds from groundbreaking through steady-state operations, managing guard forces, security systems deployment, and critical asset protection. Requires 10+ years data center security experience and deep ESS knowledge.

280k – 300k/yrOn-site10+ YOESecurity Engineering
The Voleon Group

IAM Architect

The Voleon GroupBerkeley, CA +1

Designs and implements identity and access management strategy for hybrid infrastructure including Linux, Kubernetes, Windows, AWS, and Azure. Leads IAM roadmap, privileged access management, zero-trust extensions, and builds/scales IAM team. Requires 8+ years experience with authentication protocols and cloud IAM platforms.

280k – 310k/yrRemote8+ YOESecurity Engineering
OpenAI

Systems Software Engineer, Security, First Party Hardware

OpenAISan Francisco, CA

Security Engineer owning end-to-end hardware, firmware, and system security for OpenAI's first-party AI accelerators and servers. Requires 7+ years in hardware/embedded security and strong systems programming skills.

266k – 445k/yrHybrid7+ YOESecurity Engineering
OpenAI

Secure Manufacturing & Stealth Investigator

OpenAISan Francisco, CA

Lead complex investigations into leaks, insider risks, supply chain compromises, and adversarial activity affecting OpenAI's secure manufacturing, stealth programs, unreleased hardware, and prototypes. Requires 8+ years investigative experience across cyber, physical, and operational domains.

288k – 425k/yrHybrid8+ YOESecurity Engineering