ABOUT THE ROLEWe are hiring a Security Engineer to own product and application security for a multi-tenant platform handling sensitive insurance data. You will build security into how we ship, across secure SDLC, AppSec, cloud posture, and supply-chain, and lead our response when issues arise.
WHY THIS ROLE- Own security for a platform trusted with sensitive insurance and customer data.
- Build security into the product from the ground up, not bolt it on.
- Have broad scope across application, cloud, and supply-chain security.
WHAT YOU'LL DO- Drive secure SDLC and security-focused code review across the engineering org.
- Own application security: authz, tenant isolation, SSRF and injection prevention, secrets management.
- Strengthen cloud security posture (GCP IAM, egress controls) and supply-chain controls.
- Coordinate penetration testing, threat modeling, and vulnerability management.
- Lead incident response and advance compliance readiness (e.g., SOC 2).
WHAT WE'RE LOOKING FOR- 4+ years in security engineering, with strong application security depth.
- Hands-on experience securing cloud-native, multi-tenant systems.
- Working knowledge of OWASP-class risks and how to prevent them in real code.
- Ability to partner with engineers and make security practical, not blocking.
BONUS IF YOU HAVE- Detection & response or compliance/GRC experience.
- Experience securing AI/LLM systems or regulated-data products.