Security Engineer
Summary
Founding security engineer at an early-stage AI/ML infrastructure company, building the security program from scratch: leading detection and incident response, securing APIs/cloud/data systems, and owning SOC 2 compliance for a platform used by AI labs and enterprises. On-site in San Francisco or Singapore.
About the Role
This is a founding security hire at an early-stage AI/ML infrastructure company, giving you the opportunity to build the security program from scratch. You will work across product, cloud infrastructure, compliance, and incident response to protect a platform used by leading AI labs and large enterprises. The role is critical to maintaining customer trust and safeguarding sensitive data assets at scale.
What You'll Do
Lead detection and incident response end-to-end, from initial signal and alert through investigation, postmortem, and durable engineering improvements.
Own the security roadmap spanning product security, cloud and infrastructure security, corporate security, incident response, and compliance.
Secure APIs, platforms, and data systems through threat modeling, design and code reviews, authentication and authorization controls, and secrets management.
Build and operate monitoring, detection, and incident-response capabilities, and turn emerging threats into lasting improvements.
Own SOC 2 compliance and customer trust, including control design, security questionnaires, policy management, vendor reviews, and audits.
Partner with legal, commercial, engineering, and operations to translate data-license requirements into enforceable controls covering access, provenance, retention, deletion, isolation, and auditability.
What We're Looking For
5+ years of hands-on security engineering experience across infrastructure, detection and response, and identity domains.
Proven ability to lead security incidents end-to-end, from containment through root-cause analysis and follow-up engineering work.
Experience implementing or operating SOC 2 or a comparable security framework and translating requirements into technical controls.
Experience securing AI/ML infrastructure, agent execution environments, data platforms, or systems handling untrusted or sensitive data.
Experience designing and implementing data protection controls including access, retention, deletion, isolation, and auditability.
Experience working with legal teams, auditors, and customers on security questionnaires, policy management, and audit processes.
Strong communication skills with a broad range of stakeholders, including engineers, operations, legal, auditors, and customers.
High agency and sound judgment, with the ability to prioritize risks and make pragmatic decisions under uncertainty.
Relevant certifications (OSCP, AWS Security Specialist, OSWE, CKS, GIAC) or demonstrated expertise through CVEs, security tooling, or bug bounty work are a plus.
Compensation & Benefits
Very competitive compensation package. Full medical, dental, and vision coverage. Additional benefits include a 401k, commuter benefits, and access to leading AI productivity tools. Visa sponsorship and relocation support are available for strong candidates.
Location
On-site in San Francisco, CA or Singapore. Visa sponsorship and relocation support are provided.
Skills
As published by ashby · 2 questions
Basics
Name, Email, Resume
Short answers (1)
Pick from a list (1)
- Do you have work authorization to work in that country?
