Skip to content

Security Engineer

Owns end-to-end security posture including product security, infrastructure hardening, internal tooling, corporate security, and compliance programs like SOC 2 and PCI. Requires 4+ years experience with engineering background and hands-on builder mindset in fast-paced environments.

175k – 225kSan Francisco, CANew York, NYSecurity EngineeringOnsite4+ YOE

About the role

Responsibilities

  • Lead product security: threat modeling, secure code review, vulnerability management, and building security into the development lifecycle.
  • Build internal security tooling that makes secure-by-default behavior the path of least resistance for the engineering team.
  • Harden the infrastructure that underpins Forge’s runtime – from multi-tenant isolation and secrets management to network boundaries and data handling pipelines.
  • Own corporate security programs and ensure internal systems meet enterprise standards.
  • Be the internal voice on security, communicating tradeoffs and building trust.
  • Work with external IT and Security partners.
  • Own day-to-day compliance programs – including SOC 2 and PCI.

Requirements

  • Engineering background as a software engineer who moved into security.
  • 4+ years of experience spanning product security and some corporate security or compliance work.
  • Hands-on experience with compliance programs (SOC 2, PCI, or similar) in fast-moving environments.
  • Builder’s orientation toward security tooling.
  • Soft skills to be a trusted security partner.
  • Comfort operating as a generalist across product security, corporate security, and security tooling.

Nice to Have

  • Experience securing systems that handle sensitive data in regulated verticals (banking, insurance, fintech, healthcare).
  • Familiarity with security challenges of multi-tenant AI systems (prompt injection, data isolation, output validation).
  • Experience with infrastructure security in distributed environments (container orchestration, cross-VPC networking, secrets management).
  • Familiarity with managing outsourced IT or vendor relationships.
  • Experience at an early-stage startup building security programs from scratch.

Compensation

  • Competitive salary, meaningful equity, and benefits.

Skills

Threat ModelingSecure Code ReviewVulnerability ManagementSOC 2PCISecrets ManagementMulti-Tenant IsolationContainer OrchestrationKubernetesCross-Vpc NetworkingPrompt InjectionData IsolationOutput Validation

Product Security Engineer

Product Security Engineer embedding into engineering workflows to conduct architecture reviews, threat modeling, and penetration testing coordination while serving as GCP security SME. Requires 5-7 years experience and strong GCP and Python skills.

175k – 200kUnited StatesSecurity EngineeringRemote5+ YOEGCPIAM

Security Compliance Analyst, Privacy

Build and scale LangChain's privacy compliance program across SOC 2, ISO 27001, GDPR, CCPA, and HIPAA. Partner with engineering and legal to embed controls, manage audits, and support enterprise sales.

175k – 220kSan Francisco, CA +1Security EngineeringOn-site5+ YOEGDPRCCPA

Threat Hunter

Threat Hunter on the Defense and Intelligence team responsible for proactive threat hunting, breach investigation, and improving detection coverage across cloud and corporate environments.

175k – 258kUnited StatesSecurity EngineeringRemoteGoAWS

GRC Automation & Assurance Lead

Lead GRC audit, assurance, and compliance programs while architecting and shipping AI agents to automate evidence collection, control testing, questionnaires, and audit prep for ISO 27001 and SOC 2.

174k – 215kNew York, NYSecurity EngineeringOn-site4+ YOEAWSSQL

Fraud and Abuse Operations Lead

Leads fraud and abuse operations by responding to incidents, conducting investigations, triaging high-priority events, and partnering with product teams to enhance mitigation strategies. Requires deep fraud knowledge, SQL skills, and operational maturity.

176k – 287kSan Francisco, CA +1Security EngineeringHybridSQLAML