Remote job
Application Security Lead
Job details
About this role
Role overview
The Application Security Lead will be the first dedicated security hire at a fast-scaling SaaS company, owning the application security posture end-to-end during a period of significant engineering growth. This is a hands-on, high-autonomy role focused on building security into a distributed system that handles very high data volumes and operates across multiple clouds and regions.
Responsibilities
- Design and harden security frameworks for multi-tenant isolation across systems that process large-scale data syncs and ingest high-volume event streams. - Build and refine sub-tenant access control models that support differentiated permissions for multi-team and multi-brand customer use cases. - Lead threat modeling and architecture reviews for new products, including compute isolation patterns. - Improve the security of internet-facing APIs through stronger rate limiting, abuse detection, and finer-grained access control. - Support a multi-region and multi-cloud backend, including the rollout of new regions to meet customer data residency requirements. - Set the security roadmap independently by identifying the highest-leverage risks in the architecture and driving them to resolution in code.
Requirements
- Prior experience as one of the first few security hires (around the first 1-3) at a SaaS or data infrastructure company. - Strong distributed systems expertise and the ability to read production application code and ship fixes. - Hands-on experience securing multi-tenant platforms, including tenant isolation and authorization models. - Cloud security experience across environments spanning more than one cloud and operating against customer-owned accounts. - Background designing or significantly hardening data infrastructure, not only consuming it, with an understanding of how it scales and how it is secured. - Familiarity with privacy-adjacent security work such as PII handling, data residency, and technical controls for regulations including GDPR and CCPA.
Benefits and work setup
- Remote-first, location-independent policy. - Salary range of $180,000 to $400,000 USD per year, depending on experience and scope. - Meaningful equity compensation is included in addition to base pay. - Focus on impact and growth potential rather than tenure, with a team culture that values humility, kindness, and direct collaboration with engineering.