Director, Security Engineering

InstaLILY AI

• $200K — $250K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in security engineering, ideally at a Series B-C SaaS company.
  • Hands-on experience with GCP and AWS IAM, Kubernetes, and infrastructure-as-code.
  • Proficient in writing production-quality Python or TypeScript for automation and tooling.
  • End-to-end ownership of SOC 2 Type II compliance, including audits and controls.
  • Strong credibility with enterprise CISOs, capable of leading security reviews and audits.
  • Experience with LLMs and understanding of their impact on security.
  • Player-coach mindset with a willingness to engage in hands-on work.

Responsibilities

  • Own customer trust by managing enterprise security reviews and leading CISO calls.
  • Run the compliance program, ensuring SOC 2 Type II and HIPAA standards are met.
  • Harden cloud security by addressing critical findings and implementing org-level guardrails.
  • Integrate security into product development through threat modeling and CI checks.
  • Oversee independent pen-testing and incident response planning.
  • Establish identity and endpoint security foundations, including SSO and MDM.
  • Set the operating model for security functions and deliver a 12-month roadmap.

Benefits

  • Medical, Dental, Vision coverage.
  • 401K plan with company matching.
  • In-office lunch reimbursement.
  • Wellness stipend for health-related expenses.
  • Generous parental leave policy.
  • Paid time off and 10 US Federal Holidays.
Full Job Description
The Role: Own Security for Agents That Do Real Work

We're hiring our first dedicated security leader, reporting directly to the CEO. Lily operates inside the systems of some of the largest enterprises in distribution, construction, healthcare, and logistics. That makes security a core part of the product and a lever on every enterprise deal we close.

This isn't a cold start. We hold SOC 2 Type II and HIPAA, an Okta rollout is underway, and a CNAPP evaluation is in progress. What we need is one accountable owner who can take a strong foundation and turn it into a proactive, evidence-backed security program.

This is a player-coach role. You'll spend 30-50% of your time writing code (automation, infrastructure-as-code, security tooling, remediation PRs), and most of the rest threat-modeling, reviewing architecture and PRs, and hardening cloud and IAM. You'll also be the face of security to enterprise customers, spending roughly 25-30% of your time on CISO calls, audits, and security reviews.
What You'll Do
  • Own Customer Trust: Run enterprise security reviews end to end. Build one source of truth for security answers, launch a trust center and security package, and lead CISO and InfoSec calls, audits, and RFP security sections, often on short notice.
  • Run the Compliance Program: Keep SOC 2 Type II and HIPAA healthy in Drata: continuous control monitoring, policy refreshes, and access reviews. Lead us through our next audit window and stand up a GDPR program.
  • Harden the Cloud: Partner with SRE to prioritize and close critical and high cloud findings. Make org-level guardrails the default: org policies, secrets management, and least-privilege IAM across GCP and AWS.
  • Secure the Agents: Build security into Lily from the start: threat models, prompt-injection defenses, tenant isolation, agent authorization, and security checks in CI as part of a secure SDLC.
  • Test and Respond: Commission and run our independent pen-test program and drive remediation. Refresh the incident response plan, run tabletop exercises, and serve as the escalation point for security incidents.
  • Build Identity and Endpoint Foundations: Complete SSO (Okta) coverage for tier-1 apps, run quarterly access reviews, and put device management (MDM) in place.
  • Set the Operating Model: Decide whether to partner with a vCISO or GRC service for paperwork-heavy work, complete the CNAPP evaluation, and deliver a 12-month security roadmap to the CEO and leadership.
  • Grow the Function: Hire and lead 1-2 security or AppSec engineers as the program scales.
What Success Looks Like in Year One
  • A clean SOC 2 Type II and HIPAA renewal with no exceptions, and 6495% of controls passing continuously.
  • Standard security questionnaires returned in 3 business days or less, customer CISO calls covered within 1 business day, and every answer backed by evidence.
  • An annual independent pen test completed, with critical findings remediated within SLA.
  • Critical and high cloud findings closed, with secure-by-default guardrails enforced across the org.
  • SSO on all tier-1 apps, quarterly access reviews, and MDM in place.
  • AI and agent security built into the platform, not bolted on.
  • A GDPR program running and a clear decision on ISO 27001 and HITRUST.
What You'll Need
  • 8+ Years in Security Engineering: Including hands-on ownership of a security or compliance program at a SaaS company, ideally at the Series B-C stage.
  • Hands-On Cloud and AppSec Depth: Strong in GCP and AWS IAM, Kubernetes, and infrastructure-as-code (Terraform/OpenTofu). You can threat-model a multi-tenant, multi-cloud architecture and review code, not just run scanners.
  • A Builder, Not Just a Reviewer: You write production-quality Python or TypeScript and ship your own automation, tooling, and fixes. You'd rather build and harden systems than monitor alerts or manage checklists.
  • End-to-End SOC 2 Type II Ownership: You've run the program yourself: audits, controls, evidence, and GRC tooling. You treat compliance as real risk reduction. HIPAA experience is a strong plus.
  • Credibility With Enterprise CISOs: You've led customer security reviews, questionnaires, and audits, and can hold your own in a room with a Fortune 500 security team.
  • Real LLM Experience: You've built something real with LLMs and understand how agentic systems change the threat model.
  • Player-Coach Mindset: You're energized by doing the work yourself. Tech-lead or program-lead experience is enough; formal people management is a plus, not a requirement.
  • In-person availability. 5 days/week in our New York or San Francisco office.
Bonus Points
  • You've built a security function from scratch at a Series B/C SaaS company and taken it through SOC 2 Type II.
  • You've secured an LLM or agent product in production (prompt injection, agent authorization, OWASP Top 10 for LLMs).
  • You've led a real incident response.
  • Experience with multi-tenant isolation, pen-test programs, Okta or IdP rollouts, and CNAPP tooling such as Wiz or Aikido.
  • Familiarity with GDPR, ISO 27001, HITRUST, NIST CSF, or the EU AI Act.
  • Certifications such as CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Security Specialty, or OSCP. None are required.
  • Public work: talks, writing, or open-source security tooling.
Our Stack
  • Cloud: GCP primary (Cloud Run, Cloud SQL, GKE), AWS secondary (EKS); customer deployments also run in AWS and Azure
  • Infra and code: Kubernetes, OpenTofu, Postgres, TypeScript/Next.js, Python
  • Identity and compliance: Okta, WorkOS, Drata
  • Observability and edge: Datadog, Grafana, Sentry, Cloudflare

You'll secure a multi-tenant platform with hundreds of cloud services across multiple clouds, at a company of roughly 100-150 people.
Location, Travel, and On-Call
  • Location: New York strongly preferred; San Francisco considered for exceptional candidates.
  • Travel: Minimal. Occasional customer onsites or audits, plus periodic trips to New York if based in San Francisco.
  • On-call: You'll be the escalation point for security incidents. This is not part of a routine ops rotation.
Compensation and Benefits
  • Salary Range: $200,000 - $250,000 per year, commensurate with experience
  • Equity: Generous stock option awards and refreshers for top performers
  • Benefits: Medical, Dental, Vision, 401K, in-office lunch reimbursement, Wellness Stipend, generous parental leave, PTO and 10 US Federal Holidays, and more!

Quality Over Quantity

To ensure a focused, high-quality hiring experience, we kindly ask candidates to limit their applications to 3 open requisitions at any given time. Applying strategically to roles that best align with your skills and career goals gives you the highest chance of standing out. Have you interviewed with us in the past 12 months? We encourage you to reach out directly to your previous interviewer rather than submitting a new application.

Similar Jobs

More Jobs at InstaLILY AI

More Information Technology Jobs

Find similar Director, Security Engineering jobs: