About the Role
This is a founding security engineering role at an early-stage AI/ML infrastructure company, where you will own and build the security program from the ground up. You will work across product, cloud infrastructure, compliance, and incident response to protect a platform used by frontier AI labs and large enterprise customers. The role is central to maintaining customer trust and ensuring the integrity of sensitive data assets at scale.
What You'll Do
Lead detection and incident response end-to-end, from initial signal and alert through investigation, postmortem, and durable engineering improvements.
Own the security roadmap spanning product security, cloud and infrastructure security, corporate security, incident response, and compliance.
Secure APIs, platforms, and data systems through threat modeling, design and code reviews, authentication and authorization controls, and secrets management.
Build and operate monitoring, detection, and incident-response capabilities, and turn emerging threats into engineering improvements.
Own SOC 2 compliance and customer trust, including control design, security questionnaires, policy management, vendor reviews, and audits.
Partner with legal, commercial, engineering, and operations to translate data-license requirements into enforceable controls for access, provenance, retention, deletion, and auditability.
What We're Looking For
5+ years of hands-on security engineering experience across infrastructure, detection and response, and identity domains.
Proven ability to lead security incidents end-to-end, from containment through root-cause analysis and follow-up engineering work.
Experience implementing or operating SOC 2 or a comparable security framework, translating requirements into technical and operational controls.
Hands-on offensive security experience such as bug bounty, penetration testing, or red-team work, not only defensive or blue-team work.
Experience setting up and operating SIEM and/or XDR tooling for proactive detection.
Experience with abuse and fraud detection, attack surface management, and solo incident response.
Experience securing AI/ML infrastructure, agent execution environments, data platforms, or systems handling untrusted or sensitive data.
Experience designing and implementing data protection controls including access, retention, deletion, isolation, and auditability.
Experience working with legal, auditors, and customers on security questionnaires, policy management, and audit processes.
Prior experience as an early or solo security hire, building a program or function from scratch at a fast-growing company.
Strong communication skills across engineering, legal, operations, auditors, and customers.
Relevant certifications such as OSCP, AWS Security Specialist, OSWE, CKS, or GIAC, or demonstrated expertise through CVEs, published security tooling, or bug bounty work.
Systems programming or low-level engineering background (OS internals, Linux kernel, networking fundamentals) is a strong plus.
Compensation & Benefits
Very competitive compensation package including equity. Full medical, dental, and vision coverage. 401k, commuter benefits, and additional perks. Visa sponsorship and relocation support are available for strong candidates.
Location
On-site in San Francisco, California, USA or Singapore. This is not a remote role.