Hightouch

Application Security Lead

Hightouch$120K — $160K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years experience as a security engineer at a SaaS or data infrastructure company
  • Proven ability in securing multi-tenant platforms and authorization models
  • Strong expertise in cloud security across multiple cloud environments
  • Hands-on experience in designing and building secure data infrastructure
  • Knowledge of privacy laws and technical controls related to PII handling, GDPR, and CCPA

Responsibilities

  • Define and implement Hightouch's application security strategy
  • Develop multi-tenant isolation protocols to manage ~1M data syncs daily
  • Design and enhance security architecture, including threat modeling for new products
  • Improve access control, rate limiting, and abuse detection for internet-facing APIs
  • Lead security initiatives for multi-region and multi-cloud backend systems

Benefits

  • High autonomy and direct influence in shaping security practices
  • Opportunity to work closely with engineering teams on security challenges
  • Hands-on role focusing on real problem-solving rather than meetings
  • Impactful role in a company scaling from 70 to 140+ engineers
  • Chance to define the security landscape of a burgeoning SaaS company
Full Job Description
Aboutthe Role

This is our first dedicated security hire, and it's a rare chance to define the function from the ground up. You'll own Hightouch's application security posture end-to-end. We have strong engineering fundamentals and a solid foundation; now you'll shape what security looks like here as we scale from 70 to 140+ engineers.

This is a hands-on, high-autonomy role. You'll spend most of your time in the codebase, not in meetings. You'll be solving hard problems at the intersection of security and distributed systems:
  • Multi-tenantisolation on a system running ~1M data syncs per day and ingesting 100K+ events/sec
  • Sub-tenant access control - for multi-team and multi-brand use cases, requiring differentiated access to configuration and data
  • Securityarchitecture - Build and refine our frameworks for compute isolation and perform threat modeling and hardening of new products
  • Internet-facing APIs - Our high-throughput, internet-facing architecture services customer data at scale. You'll improve our rate limiting, abuse detection, and granularity of access control
  • Multi-Region and Multi-Cloud - Supporting our multi-region and multi-cloud backend, including extending it to launch Hightouch on in new regions to support data residency requirements of our global customer base

You'll own your roadmap. We're not looking for someone to run a checklist - we're looking for someone who can look at our architecture, identify the highest-leverage problems, and go fix them.
AboutYou

You've been an early security hire at a SaaS company before and moved the needle on how they approach security. You can read application code, threat model a distributed system, and ship production fixes. You have significant distributed systems expertise so that you can understand and influence what is being built by the product teams and influence from a place of trust.

Experience that's relevant:
  • Being an early security hire (first 1-3) at a SaaS or data infrastructure company
  • Securing multi-tenant platforms: tenant isolation, authorization models, etc
  • Cloud security on systems that span more than one cloud and operate against customer-owned accounts
  • Design and build of data infrastructure as an early engineer, not just a user. You helped secure it from early design or during major redesigns. You understand how it scales and how it's secured
  • Privacy-adjacent security (PII handling, data residency, GDPR/CCPA technical controls)

We don't care about certifications. We care about what you've built.
InterviewProcess
  1. RecruiterScreen [30m] - Introductory mutual fit assessment
  2. Security Architecture Interview[60m] - Threat model discussion of a real-ish system, followed by a systems design exercise
  3. Core interview [90m] - deep dive on distributed systems knowledge
  4. HiringManager Interview [60m] - What you've built in the past, how you work
  5. Security Program Interview [60m] with Head of Engineering - How you've run security programs in practice: bug bounty, pentest engagements, working with external researchers, and partnering across engineering to drive adoption.


About Hightouch

Hightouch is a software company that provides a data integration platform for businesses. The platform allows businesses to connect their customer data from various sources and sync it with their marketing and sales tools. Hightouch's platform is designed to be easy to use and requires no coding or technical expertise. The company was founded in 2019 and is headquartered in San Francisco, California.
Learn more about Hightouch
Size
20 employees
Industry
Founded
2019

Similar Jobs

More Jobs at Hightouch

More Information Technology Jobs

Find similar Application Security Lead jobs: