Build production security tooling, detection systems, remediation pipelines, and secure-by-default frameworks across cloud and application security. The role requires strong software engineering fundamentals, deep expertise in one security domain, and the ability to deliver hands-on solutions.
225k – 300k/yr
Hybrid5+ YOESecurity Engineering
About the role
Responsibilities
Build security primitives, tooling, and automation that scale with the product and engineering organization.
Define and implement modern security workflows, including AI-assisted vulnerability discovery, automated code review, threat detection, and remediation.
Collaborate with Infrastructure and Product Engineering to make secure defaults the easiest path.
Own projects end to end, including design, implementation, rollout, and measurement.
Cloud Security
Secure cloud environments through IAM, network policies, container security, secrets management, and misconfiguration prevention.
Define and enforce least-privilege access patterns across services and users.
Improve cloud visibility and control using infrastructure as code and cloud security tooling.
Develop preventative controls and safe deployment patterns that reduce the probability and blast radius of incidents.
Application Security
Lead secure design and secure coding practices and prevent common vulnerability classes.
Perform architecture reviews and code-level security reviews, and work hands-on with engineers to ship fixes.
Own vulnerability discovery and validation, including static and dynamic analysis, dependency checks, penetration tests, and bug bounties.
Integrate automated detection systems to find vulnerabilities at scale.
Build and deploy security agents and automated workflows that scan codebases, propose fixes, and in some cases autonomously deploy security patches.
Build reusable frameworks and components for authentication, authorization, and secure-by-default patterns.
Define practical policies and controls for code-generation tools and coding-agent changes.
Requirements
Strong software engineering fundamentals and a track record of shipping production systems.
Deep expertise in either cloud security or application security, with the ability to work across both domains.
Ability to translate risk into concrete engineering work and ship solutions.
Comfort building from first principles and defining effective security practices.
Interest in using modern automation and AI to scale security operations while maintaining engineering rigor.
Owns corporate security architecture and automation across identity, compliance, endpoint protection, SaaS, and internal IT systems. The role requires 5+ years of security engineering experience, deep IdP design expertise, audit control ownership, and a track record of impactful automation.
220k+/yrHybrid5+ YOESecurity Engineering
Platform Engineer, Product Security
Wispr FlowSan Francisco, CA
Own product security end-to-end at Wispr: prioritize threats, architect defenses, participate in early design reviews, and embed security into the platform for a voice AI product handling highly sensitive user data. Ideal for pragmatic security experts who enjoy finding vulnerabilities and improving team practices.
220k – 350k/yrOn-site5+ YOESecurity Engineering
Security Engineer, Corporate Security
NotionSan Francisco, CA +1
Hands-on Corporate Security Engineer to own and improve technical controls across identity, endpoints, SaaS, and workforce infrastructure. Build scalable automation and partner with IT, Infrastructure, GRC, and Detection & Response.
220k – 260k/yrHybridSecurity Engineering
Software Engineer, Scaled Abuse
OpenAISan Francisco, CA
Build and operate backend and data systems for real-time fraud/abuse detection, investigation, and enforcement at OpenAI. Requires 5+ years backend engineering and 2+ years fraud/abuse experience.
230k – 385k/yrOn-site5+ YOESecurity Engineering
Technical Cyber Threat Investigator
AnthropicSan Francisco, CA +1
Investigates and disrupts misuse of AI systems for cyber threats like malware and influence operations. Develops detection techniques and intelligence reports, requiring proficiency in SQL, Python, and threat intelligence frameworks.