7 hours ago
Responsibilities
- Lead detection and incident response from initial alert through investigation, postmortem, containment, root-cause analysis, and follow-up engineering improvements.
- Own the security roadmap across product security, cloud and infrastructure security, corporate security, incident response, and compliance.
- Secure APIs, platforms, and data systems through threat modeling, design and code reviews, authentication and authorization controls, and secrets management.
- Build and operate monitoring, detection, and incident-response capabilities, including SIEM and/or XDR tooling.
- Own SOC 2 compliance and customer trust activities, including control design, security questionnaires, policy management, vendor reviews, and audits.
- Translate data-license requirements into enforceable controls for access, provenance, retention, deletion, isolation, and auditability in partnership with legal, commercial, engineering, and operations teams.
Requirements
- 5+ years of hands-on security engineering experience across infrastructure, detection and response, and identity domains.
- Experience leading security incidents end-to-end and implementing or operating SOC 2 or a comparable security framework.
- Hands-on offensive security experience such as bug bounty, penetration testing, or red-team work.
- Experience with SIEM and/or XDR, abuse and fraud detection, attack surface management, and solo incident response.
- Experience securing AI/ML infrastructure, agent execution environments, data platforms, or systems handling untrusted or sensitive data.
- Experience designing and implementing data protection controls and working with legal teams, auditors, and customers on security processes.
- Prior experience as an early or solo security hire building a security program from scratch.
- Relevant certifications such as OSCP, AWS Security Specialist, OSWE, CKS, or GIAC, or demonstrated expertise through CVEs, published security tooling, or bug bounty work.
- Systems programming or low-level engineering experience involving OS internals, Linux kernel, or networking fundamentals is a strong plus.
- Strong communication skills across engineering, legal, operations, auditors, and customers.
Benefits
- Very competitive compensation package including equity.
- Full medical, dental, and vision coverage.
- 401k, commuter benefits, and additional perks.
- Visa sponsorship and relocation support are available for strong candidates.
- On-site role in San Francisco, California, USA or Singapore; not remote.
