About the job Security Engineer
Location: San Francisco Bay Area, CA, or Singapore (On-site)
Schedule: Full-time
Salary: $100K–$200K
Company:
Our client is a Y Combinator-backed company building infrastructure to create reinforcement-learning training data and evaluations for frontier AI agents, along with a marketplace connecting this work with frontier labs. Its platform is used by frontier labs, Fortune 500 companies, and startups.
Description:
Our client is seeking its first full-time Security Engineer to own and build the security program. This is a hands-on, senior individual-contributor role spanning product security, cloud infrastructure, internal systems, incident response, compliance, and customer trust.
The immediate mandate is to bring security up to the standard required of a rapidly scaling data company, strengthen controls as the supplier footprint grows, and take SOC 2 from in progress through completion. Proactive controls, detection, and attack-surface management are central priorities.
Key Responsibilities:
- Own the security roadmap across product, cloud and infrastructure, corporate systems, incident response, and compliance
- Harden AWS infrastructure and accounts, including IAM, networking, logging, Terraform, secrets management, and automated guardrails
- Establish stronger monitoring, SIEM/XDR, detection engineering, alerting, and incident-response workflows that identify and stop problems before they become incidents
- Secure applications, APIs, the platform, and data workflows through threat modeling, design reviews, code reviews, vulnerability research, authentication and authorization controls, and remediation
- Improve container and workload isolation for systems that execute untrusted code or process sensitive data
- Own abuse, fraud, and incident response end to end, including containment, investigation, postmortems, and durable follow-up engineering
- Build continuous attack-surface management across domains, cloud services, third-party hosting, vendors, and externally exposed assets
- Complete SOC 2 and own customer trust work, including control design, evidence, policy management, security questionnaires, vendor reviews, and audits
- Translate contractual and data-license requirements into enforceable controls for access, permitted use, retention, deletion, isolation, provenance, and auditability
Qualifications:
Core Experience:
- 5–10 years of deeply hands-on security experience across offensive security, infrastructure or cloud security, application security, and incident response
- Experience building a security program from zero at least once, ideally as an early security hire at a fast-growing startup
- Strong AWS and cloud-engineering depth, including infrastructure as code with Terraform
- Current hands-on ability to review code, find vulnerabilities, design controls, deploy tooling, and personally lead investigations
- Experience implementing or operating SOC 2 or a comparable security framework
- Sound judgment and the ability to prioritize the risks that matter in a fast-moving environment
Preferred:
The following are considered strong signals:
- Bug bounty work, penetration testing, vulnerability research, published CVEs, security tooling, conference talks, or substantive technical writing
- OSCP or OSWE; AWS, cloud engineering, CKS, or hands-on GIAC certifications
- Systems programming, operating systems, Linux kernel work, low-level networking, or experience building infrastructure from the ground up
- Experience securing AI/ML infrastructure, agent execution environments, data platforms, or other systems that run untrusted code
This role requires current hands-on technical depth and broad security ownership. It is not designed for candidates whose recent experience has been exclusively people leadership or limited to a narrow specialty within an already mature security organization. Offensive-security experience alone is insufficient without demonstrated cloud engineering and program-building ability.
Why Join Them?
- Become the company's first full-time Security Engineer and own the security program
- Shape security across product, cloud infrastructure, internal systems, incident response, compliance, and customer trust
- Address security challenges involving untrusted code execution, sensitive data, and a growing supplier footprint
- Relocation and visa support are available for strong candidates