Remote job
Staff Security Engineer
Job details
About this role
Role overview A high-growth SaaS company building an AI-integrated engineering intelligence platform is hiring a Staff Security Engineer to own and lead all security engineering activities. This is a senior, hands-on technical authority role that defines the security vision, shapes strategy, and embeds security across the software development lifecycle and AI/ML product surface. The position partners directly with engineering leadership while remaining deeply technical through architecture, threat modeling, and code.
Responsibilities - Define and drive the multi-year security strategy and roadmap, aligning initiatives with business objectives and top-tier organizational risk reduction. - Design, mandate, and evolve scalable, resilient security architectures across core infrastructure, platform, and product surfaces. - Own the Secure Development Lifecycle (SDLC) company-wide, championing automated threat modeling, continuous risk assessments, and secure-by-default development practices. - Partner with engineering and data science teams to establish secure development and governance for internal AI tooling and customer-facing AI features, including mitigation of prompt injection, data poisoning, and sensitive data leakage. - Lead the strategy for automation at scale, including automated remediation workflows, vulnerability management, and software composition analysis. - Direct incident response, pentesting, and bug bounty programs; mentor engineers and advise executive leadership on security posture.
Requirements - Extensive track record owning and scaling application security programs in a SaaS or fast-paced startup environment. - Deep software engineering background (e.g., Python, JavaScript/TypeScript, Rust, or C/C++) with architectural-level understanding of reliability and security. - Deep familiarity with the security challenges of AI and large language models, including practical experience securing AI infrastructure and applications. - Demonstrated ability to drive cross-functional consensus and influence engineering leadership on large-scale security initiatives. - Strong business acumen balancing user needs, product velocity, and enterprise security. - Comfort working autonomously with distributed teams; eligible to work in the U.S. for any employer without visa sponsorship.
Nice to have - Expert-level familiarity with a modern stack such as Python, Django, Postgres, AWS, Terraform, CircleCI/GitLab/GitHub Actions, Semgrep, or LLVM. - Active contribution to open-source security projects or industry working groups (e.g., OpenSSF). - Prior experience leading security at a high-growth startup.
Benefits and work setup - Occasional travel may be required. - Preference for candidates located in U.S. Eastern or Central time zones. - Team-oriented culture that values humility, performance, and a sense of humor; no visa sponsorship available at this time.