2 months ago
Responsibilities
- Partner with engineering teams as an embedded security expert by writing code, reviewing architectures, and building secure application features and infrastructure components.
- Design and implement automated fraud detection, real-time monitoring, and remediation workflows for platform abuse, credential stuffing, and payment fraud.
- Own the strategy and execution for hardening AWS and Python infrastructure, including network security, cloud configuration, vulnerability management, and remediation workflows.
- Lead security controls for AI and agentic systems, including agentic coding and AI agent products.
- Oversee SOC 2 compliance operations through Drata, annual audit cycles, and planning for certifications such as ISO 27001.
- Provide oversight for platform abuse and content moderation and act as the escalation point for IT security incidents.
Requirements
- Strong software engineering background with hands-on Python and AWS experience.
- Experience securing cloud infrastructure and applications, including vulnerability management, network security, IAM, and secrets management.
- Familiarity with GRC frameworks and compliance programs such as SOC 2 or ISO 27001.
- Ability to communicate threat models, compliance requirements, and security architecture to engineers, auditors, and enterprise CISOs.
- Comfort with ambiguity and rapid scaling, including prioritizing and deciding when to build versus buy.
- Experience with modern security tooling such as Drata, Infisical, or Bugcrowd is a plus.
About HeyGen
HeyGen is a message-first AI video platform that helps people and AI agents turn ideas into professional video in minutes. Used by a community of over 30 million users and 85% of the Fortune 100, HeyGen makes it easy to create and share videos seamlessly across languages and formats.