About the RoleThis is a founding security role at an early-stage AI/ML infrastructure company, giving you full ownership to build the security program from the ground up. You will work across product, cloud infrastructure, compliance, and incident response to protect a platform used by frontier AI labs and large enterprises. The role is critical to maintaining customer trust and safeguarding sensitive data assets at scale.
What You'll Do- Lead detection and incident response end-to-end, from signal and alert through investigation, postmortem, and durable engineering improvements.
- Own the security roadmap spanning product security, cloud infrastructure, corporate security, incident response, and compliance.
- Secure APIs, platforms, and data systems through threat modeling, design and code reviews, authentication and authorization controls, and secrets management.
- Build and operate monitoring, detection, and incident-response capabilities, and turn emerging threats into lasting improvements.
- Own SOC 2 compliance and customer trust, including control design, security questionnaires, policy management, vendor reviews, and audits.
- Partner with legal, commercial, engineering, and operations to translate data-license requirements into enforceable controls for access, provenance, retention, deletion, and auditability.
What We're Looking For- 5+ years of hands-on security engineering experience across infrastructure, detection and response, and identity domains.
- Proven ability to lead security incidents end-to-end, from containment through root-cause analysis and follow-up engineering work.
- Experience implementing or operating SOC 2 or a comparable security framework and translating requirements into technical controls.
- Hands-on offensive security experience, including bug bounty, penetration testing, or red-team work, not only defensive or blue-team work.
- Experience setting up and operating SIEM and/or XDR tooling for proactive detection.
- Experience with abuse and fraud detection, and comfort running solo incident response.
- Experience with attack surface management, including continuous monitoring of domains and third-party hosting infrastructure.
- Experience securing AI/ML infrastructure, agent execution environments, or data platforms handling untrusted or sensitive data.
- Experience designing data protection controls covering access, retention, deletion, isolation, and auditability.
- Strong communication skills when working with engineers, legal, auditors, and customers.
- High agency, sound judgment, and the ability to prioritize risks and make pragmatic decisions under uncertainty.
- Relevant certifications such as OSCP, AWS Security Specialist, OSWE, CKS, or GIAC are a plus, as is systems programming or low-level engineering background.
- Prior experience as an early or sole security hire building a program from scratch at a fast-growing startup is a strong advantage.
Compensation & BenefitsVery competitive compensation package. Benefits include 100% employer-covered medical, dental, and vision for US employees, 401k, commuter benefits, and unlimited access to leading AI productivity tools. Visa sponsorship and relocation support are available for strong candidates.
LocationOn-site in San Francisco, CA or Singapore. Visa sponsorship and relocation support are provided.