3 months ago
Base Salary
$200k - $400k/yr
Responsibilities
- Own security for deployed applications through threat modeling, secure design reviews, and vulnerability remediation across services and AI infrastructure.
- Lead compliance initiatives including SOC 2 and frameworks such as ISO 27001, GDPR, and CCPA.
- Establish controls, policies, and evidence to support compliance programs.
- Own security activities in the sales cycle, including customer security questionnaires, enterprise security reviews, and vendor assessments.
- Build and operate vulnerability management, secrets management, identity and access, and security monitoring practices.
- Manage third-party risk and the penetration-testing program.
Requirements
- At least 5 years of experience in security engineering, application or product security, or a related role at a software company.
- Strong application and cloud security fundamentals, including the ability to assess production systems and AI workloads.
- Hands-on experience leading or operating a compliance program such as SOC 2 or ISO 27001 end to end.
- Solid programming skills for building security tooling and automation and collaborating with engineers.
- Ability to work in a fast-moving startup environment with high ownership and autonomy.
- Experience establishing a security and compliance function at an early-stage or rapidly scaling SaaS company is a bonus.
- Familiarity with AWS, Pulumi, Postgres, ClickHouse, Turbopuffer, or Temporal is a bonus.
Benefits
- Health, vision, and dental benefits plus a 401(k) match.
- Competitive compensation and early equity.
- Clear career growth opportunities as the company scales.
- Free lunch in Palo Alto.
- Work involves deep exposure to AI tooling.
