Job Openings Security Engineer

About the job Security Engineer

Location: San Francisco Bay Area, CA, or Singapore (On-site)
Schedule: Full-time
Salary: $100K–$200K

Company:
Our client is a Y Combinator-backed company building infrastructure to create reinforcement-learning training data and evaluations for frontier AI agents, along with a marketplace connecting this work with frontier labs. Its platform is used by frontier labs, Fortune 500 companies, and startups.

Description:
Our client is seeking its first full-time Security Engineer to own and build the security program. This is a hands-on, senior individual-contributor role spanning product security, cloud infrastructure, internal systems, incident response, compliance, and customer trust.

The immediate mandate is to bring security up to the standard required of a rapidly scaling data company, strengthen controls as the supplier footprint grows, and take SOC 2 from in progress through completion. Proactive controls, detection, and attack-surface management are central priorities.

Key Responsibilities:

  • Own the security roadmap across product, cloud and infrastructure, corporate systems, incident response, and compliance
  • Harden AWS infrastructure and accounts, including IAM, networking, logging, Terraform, secrets management, and automated guardrails
  • Establish stronger monitoring, SIEM/XDR, detection engineering, alerting, and incident-response workflows that identify and stop problems before they become incidents
  • Secure applications, APIs, the platform, and data workflows through threat modeling, design reviews, code reviews, vulnerability research, authentication and authorization controls, and remediation
  • Improve container and workload isolation for systems that execute untrusted code or process sensitive data
  • Own abuse, fraud, and incident response end to end, including containment, investigation, postmortems, and durable follow-up engineering
  • Build continuous attack-surface management across domains, cloud services, third-party hosting, vendors, and externally exposed assets
  • Complete SOC 2 and own customer trust work, including control design, evidence, policy management, security questionnaires, vendor reviews, and audits
  • Translate contractual and data-license requirements into enforceable controls for access, permitted use, retention, deletion, isolation, provenance, and auditability

Qualifications:

Core Experience:

  • 5–10 years of deeply hands-on security experience across offensive security, infrastructure or cloud security, application security, and incident response
  • Experience building a security program from zero at least once, ideally as an early security hire at a fast-growing startup
  • Strong AWS and cloud-engineering depth, including infrastructure as code with Terraform
  • Current hands-on ability to review code, find vulnerabilities, design controls, deploy tooling, and personally lead investigations
  • Experience implementing or operating SOC 2 or a comparable security framework
  • Sound judgment and the ability to prioritize the risks that matter in a fast-moving environment

Preferred:

The following are considered strong signals:

  • Bug bounty work, penetration testing, vulnerability research, published CVEs, security tooling, conference talks, or substantive technical writing
  • OSCP or OSWE; AWS, cloud engineering, CKS, or hands-on GIAC certifications
  • Systems programming, operating systems, Linux kernel work, low-level networking, or experience building infrastructure from the ground up
  • Experience securing AI/ML infrastructure, agent execution environments, data platforms, or other systems that run untrusted code

This role requires current hands-on technical depth and broad security ownership. It is not designed for candidates whose recent experience has been exclusively people leadership or limited to a narrow specialty within an already mature security organization. Offensive-security experience alone is insufficient without demonstrated cloud engineering and program-building ability.

Why Join Them?

  • Become the company's first full-time Security Engineer and own the security program
  • Shape security across product, cloud infrastructure, internal systems, incident response, compliance, and customer trust
  • Address security challenges involving untrusted code execution, sensitive data, and a growing supplier footprint
  • Relocation and visa support are available for strong candidates