2 hours ago
Responsibilities
- Lead detection and incident response from initial alerts through investigation, postmortems, and follow-up improvements.
- Own the security roadmap across product security, cloud infrastructure, corporate security, incident response, and compliance.
- Secure APIs, platforms, and data systems through threat modeling, design and code reviews, authentication and authorization controls, and secrets management.
- Build and operate monitoring, detection, and incident-response capabilities.
- Own SOC 2 compliance and customer trust activities, including control design, security questionnaires, policy management, vendor reviews, and audits.
- Translate data-license requirements into enforceable controls for access, provenance, use, retention, deletion, and auditability.
- Build the security program and function from scratch in partnership with legal, commercial, engineering, and operations.
Requirements
- 5+ years of hands-on security engineering experience across infrastructure, detection and response, identity, and related domains.
- Experience leading security incidents end-to-end from containment through root-cause analysis and follow-up engineering work.
- Experience implementing or operating SOC 2 or a comparable security framework and translating requirements into technical controls.
- Experience setting up and operating SIEM and/or XDR tooling for proactive detection.
- Experience securing AI/ML infrastructure, agent execution environments, data platforms, or systems handling untrusted or sensitive data.
- Experience with attack surface management, abuse and fraud detection, and solo incident response.
- Experience building a security program or function from scratch.
- Experience working with legal teams, auditors, and customers on security questionnaires, policy management, and audit processes.
- Strong communication, high agency, and sound judgment under uncertainty.
- Relevant certifications such as OSCP, AWS Security Specialist, OSWE, CKS, or GIAC, or demonstrated expertise through CVEs, security tooling, or bug bounty work.
- Offensive security experience such as bug bounty, pentesting, or red-team work and a systems programming or low-level engineering background are strong pluses.
Benefits
- Full medical, dental, and vision coverage for US employees.
- 401k and commuter benefits.
- Access to leading AI productivity tools.
- Visa sponsorship and relocation support are available for strong candidates.
- On-site work in San Francisco, California or Singapore.
