Lead Security Engineer
Summary
Lead the security of HighLevel’s AI-powered platform, embedding secure SDLC practices, threat modeling, and AI-specific protections into Web, Mobile, API, and LLM systems.
About Us
Our People
Our Impact
About the Role
What You’ll Be Doing:
- Lead Application Security initiatives across HighLevel’s products and engineering teams.
- Proliferate security standards recommended by central security team as best practices within Dev teams.
- Conduct architecture reviews, secure design assessments, and threat modeling for new features and platforms.
- Perform security assessments for Web, Mobile, and API-based applications.
- Define and drive secure SDLC practices across engineering teams.
- Partner with developers to identify, prioritize, and remediate security vulnerabilities.
- Lead security reviews for AI/LLM-powered applications, agents, and AI integrations.
- Develop security guardrails for AI systems, including protections against prompt injection, data leakage, insecure tool usage, model abuse, and emerging AI attack techniques.
- Improve security tooling and automate security testing within CI/CD pipelines.
- Champion secure coding practices through developer enablement, documentation, and training.
- Drive vulnerability management efforts and improve remediation workflows.
- Mentor engineers and foster a strong security-first engineering culture.
- Drive cross-functional collaboration by communicating complex security risks to technical and non-technical stakeholders, influencing product roadmaps, and ensuring alignment between security priorities and engineering objectives.
- Stay current with emerging threats, application security trends, and advancements in AI security.
What You’ll Bring:
- 8+ years of experience in Cybersecurity, with deep expertise in Application Security and leading engineering-focused security initiatives.
- Comprehensive technical knowledge in securing Web, Mobile (Android/iOS), and API (REST/GraphQL) environments, including OWASP standards and authentication protocols (OAuth 2.0, OIDC, JWT, SAML).
- Proven experience performing security assessments including threat modeling, secure design/code reviews, penetration testing, and architecture reviews.
- Hands-on DevSecOps proficiency: automating security in CI/CD pipelines, container security (Kubernetes/Docker), and managing security tooling (SAST, DAST, SCA, Secret Scanning).
- Specialized expertise in AI/LLM security, including mitigation of prompt injection, data leakage, model misuse, and insecure agent/tool integration.
- Proficiency in programming/scripting (Python, Go, JavaScript, or Bash) and strong communication skills to influence technical stakeholders across product and engineering teams.
Preferred Qualifications
- Experience securing workloads on Google Cloud Platform (GCP).
- Experience with Infrastructure as Code security (Terraform).
- Familiarity with CSPM/CNAPP solutions.
- Experience leading or participating in Red Teaming, adversary simulation, or purple team exercises.
- Experience with DevSecOps and security automation.
- Security certifications such as CEH, OSCP, GWAPT, CISSP, GCP Professional Cloud Security Engineer, or similar.
- Contributions to open-source security projects, bug bounty programs, or security research.