This is the first dedicated security engineering hire, reporting directly to the CTO and owning the security program end to end. You will build and operate the security program across infrastructure security, application security, vulnerability management, penetration testing, bug bounty operations, and engineering support for compliance. This is a hands-on generalist role for someone who wants to ship real security improvements rather than operate only through policy and checklists.
What you will do:
• Build and own the security engineering program across infrastructure and application layers.
• Identify and prioritize security gaps, develop pragmatic remediation plans, and drive high-impact changes.
• Harden AWS infrastructure, Kubernetes and EKS clusters, server configurations, networking, access controls, and cloud security posture.
• Improve application security across services written in TypeScript, Go, Rust, and related technologies.
• Manage recurring penetration tests and drive findings through remediation.
• Operate the bug bounty program, triage vulnerability reports, and coordinate responses.
• Partner with engineering on secure design, code-level fixes, deployment patterns, secrets management, and defense in depth.
• Own technical work supporting SOC 2, PCI, monitoring, incident readiness, and vulnerability-management workflows.
Requirements
• Approximately 2 to 8 years of hands-on security engineering, software security, infrastructure security, or closely related experience.
• Strong generalist ability across cloud infrastructure, application security, vulnerability management, and security operations.
• Hands-on experience securing AWS and container-orchestration environments such as Kubernetes or EKS.
• Experience assessing and remediating application vulnerabilities in production software.
• Experience managing penetration tests, bug bounty reports, or coordinated vulnerability disclosure.
• Familiarity with network security, identity and access controls, secrets management, web application defenses, and cloud posture management.
• Ability to write code, automate security work, and collaborate directly with software engineers on technical fixes.
• Strong risk judgment, high ownership, clear communication, and comfort operating independently.
• Ability to work on-site five days per week in San Francisco or willingness to relocate.
Nice to have: Experience with TypeScript, Go, Rust, CockroachDB, Kafka, Terraform, Pulumi, Cloudflare, AWS WAF, PCI, SOC 2, incident response, detection engineering, threat modeling, or secure architecture reviews.
Benefits
$250,000 to $350,000 base salary, based on qualifications and experience, plus competitive equity. This role is on-site five days per week in San Francisco. Existing visa transfers, including OPT and H-1B transfers, may be considered.