2 months ago
Base Salary
$180k - $250k/yr
Responsibilities
- Own and evolve Liberate’s production cloud foundation across AWS, Kubernetes/EKS, networking, compute, storage, data services, environment isolation, and production access.
- Build reusable Terraform modules, CI/CD pipelines, deployment automation, configuration standards, and self-service infrastructure paths.
- Improve reliability through observability, alerting, SLOs, capacity and cost management, backup and recovery, disaster recovery, and production-readiness standards.
- Participate in on-call operations, lead infrastructure incidents when needed, and turn incidents and operational toil into platform improvements.
- Lead threat modeling and secure design reviews for agent capabilities, tool execution, memory, integrations, multi-tenant services, and sensitive data flows.
- Build a secure SDLC with code, dependency, container, and infrastructure-as-code scanning, CI gates, security tests, and secure defaults.
- Own identity, authorization, secrets, key management, encryption, network boundaries, audit trails, production access, and tenant and data-isolation patterns.
- Establish controls for agentic AI risks such as scoped tool access, credential handling, data exfiltration, prompt injection, model and vendor risk, and traceable actions.
- Run vulnerability management, penetration tests, third-party reviews, security telemetry, detection, playbooks, tabletop exercises, and incident response.
- Own SOC 2 and related compliance programs, lead audits and customer security reviews, and translate requirements into automated technical controls.
- Maintain the security roadmap, drive mitigations, and use vendors and external specialists while retaining internal technical ownership.
Requirements
- 8+ years of experience across infrastructure engineering, platform engineering, SRE, DevOps, cloud security, or security engineering.
- 4+ years of meaningful ownership of security architecture or security programs for a production SaaS platform.
- Deep hands-on experience with AWS, Kubernetes/EKS, Terraform or equivalent infrastructure as code, CI/CD, observability, and production incident response.
- Strong working knowledge of IAM, network security, secrets and key management, vulnerability management, secure software delivery, and multi-tenant cloud architecture.
- Demonstrated ownership of SOC 2 or a comparable compliance program in a fast-moving environment.
- Proficiency in a programming or automation language such as Python, Go, or TypeScript.
- Experience in an early-stage or high-growth company where systems had to be built rather than inherited.
- Helpful experience includes securing LLM-based or agentic systems, working in regulated industries, designing disaster recovery or multi-account cloud foundations, regional or tenant isolation, and managing security or incident-response vendors.
Benefits
- Hybrid work preferred in Boston or the Bay Area, with two days per week in the office.
- Equity included.
- Opportunity to build Liberate’s security engineering function and team.
Tech Stack
About Liberate
Liberate builds insurance‑native AI agents for carriers, agencies, and brokers that handle customer interactions across voice, SMS, email, and web. Delivered as a SaaS platform, its agents resolve requests and complete downstream work inside core systems such as Guidewire, Duck Creek, Applied Epic, and Salesforce. Founded in 2022 and headquartered in the San Francisco Bay Area, the company is privately held.
