Software Engineer Security - Remote US - Paraform (USA)
Summary
First dedicated security hire at a seed-stage, stealth-mode identity/access-management startup. You own the security posture end to end — building secrets management, PKI, audit logging, detection/response, and SOC 2/ISO 27001 compliance — embedded with engineers writing Go on GCP/Kubernetes, with a path to lead the security team.
Software Engineer, Security
Full-time · Remote (USA) · Reports to Co-founder
About Us
Our client is a seed-stage, stealth-mode startup building a next-generation enterprise identity platform. Our founders have previously built and sold a successful company, and we're now reimagining how companies manage who gets access to what, how that access works, and how users authenticate into their systems.
The identity and access management space has been stagnant for years, and it's dominated by players like Okta and Auth0. We're changing that by combining secure-by-design architecture with consumer-grade user experience, for both the end users logging in and the IT admins configuring access. Our platform is designed so that IT administrators don't need to be security experts to keep their company's tools and data secure, while world-class security engineering does the work under the hood.
We're pre-launch, and our most immediate milestone is using our own V1 product internally. We have a clear line of sight to launching with a solid customer base within the next year. We're a 12-person team backed by a sizable seed round from a top-tier Bay Area venture fund, and we have significant runway to build ambitiously.
How We Work
- Remote by design. We're fully remote and distributed throughout the US and Canada, with a remote-friendly culture we've built intentionally from day one.
- Together in person, too. We get together a few times a year for company offsites and team retreats.
- Flat and fast. Everyone reports to one of our co-founders. The team is flat, high-ownership, and moves quickly.
- Balanced craft. We believe great software requires great product thinking, great design, and great engineering in equal measure.
- A high bar. We're intentional, curious, and united by a high bar for craft and delivery.
- Shared ownership of culture. Because we're small, everybody has a hand in shaping our culture, including hiring.
The Role
As our first dedicated security hire, you'll own our security posture across the entire stack. You'll work inside engineering throughout the product development process, not as a gate at the end. You'll report directly to a co-founder with a deep security background. You'll get a strong partner and a lot of autonomy, and you'll have a clear path to building and leading the security team as we scale.
Much of what you'll work on doesn't exist yet. If you've built a security program before, great. If you haven't, but you have deep engineering chops and want to own one, this is the place to do it.
Until now, our engineers have been generalists. We're now bringing on specialists to build and own the functions that matter most, and security is one of them.
What You'll Do
- Own our security posture end to end. Work embedded with engineering from design through deployment so that security is part of how we build, not something we add afterward.
- Build foundational security systems from scratch. This includes secrets management, certificate and PKI infrastructure, audit logging, and vulnerability management.
- Be a trusted engineering partner. Lead security reviews, threat modeling, and secure design consultations that help the team move quickly and safely.
- Drive our compliance programs. Own SOC 2, ISO 27001, GDPR, and CCPA from an engineering perspective, building controls that are real rather than just auditable.
- Establish incident response and detection. Define our IR processes and build detection-as-code capabilities, including the automation that makes triage fast.
- Wear multiple hats. Cover product security, corporate security, and compliance, then shape the security team we hire over time.
What We're Looking For
- Deep security engineering expertise. 5+ years as a security engineer, with engineering depth as your foundation.
- Hands-on production Go. You currently write and ship Go, not just review it.
- Application and product security on a real product. You've done secure design, code review, and in-product vulnerability remediation.
- Detection and response experience. You've built detections, triaged alerts, and run incident response.
- Detection engineering skills. You've worked in a SIEM or detection-as-code stack (Splunk, Panther, Sigma, or similar) and use Python for detection and triage automation.
- Compliance experience. You've worked with frameworks such as SOC 2, ISO 27001, or GDPR.
- Willingness to own program work. If you haven't built a security program before, you're excited to.
- A low-ego, collaborative approach. You're excited to wear multiple hats and play a true security generalist role.
- Real passion for security. You stay current on the evolving threat landscape because you genuinely care about it.
Bonus Points
- Experience building security programs from the ground up
- A background in identity and access management, or in enterprise IT or security software
- Kubernetes and cloud security experience (GCP preferred)
- Familiarity with identity protocols such as OAuth, SAML, OIDC, and WebAuthn
- A relevant bachelor's degree (preferred)
Our Tech Stack
Go · Python · GCP · Kubernetes · PKI · HashiCorp Vault · GCP Secret Manager · OAuth 2.0 · SAML · OIDC · WebAuthn · SOC 2 · ISO 27001
Why Join Us
- Real ownership. You'll define the security function at a company where security is the product.
- A proven team. Our founders have built, scaled, and sold a company before.
- Direct line to leadership. You'll report directly to a co-founder, with high ownership from day one and a real path to leading a team as we grow.
- Stability to build well. Significant runway means you can build ambitiously and do things right instead of in a rush.
- Ground-floor timing. You'll join before launch and help take the product from internal dogfooding to its first customers.
Compensation & Benefits
- Salary: $180,000–$230,000
- Equity: Competitive early-stage equity is part of the total compensation package. We'll share specific equity details later in the interview process.
- Health: Health, dental, and vision insurance for employees and dependents, with 99% of premiums covered
- Time off: Unlimited PTO subject to manager approval, and we heavily encourage taking at least 3 weeks of vacation per year
- Holidays: About 21 paid company holidays, including a Winter Break
- Parental leave: 12 weeks of paid parental leave
- In-person time: Twice-yearly company offsites, plus team retreats
Visa sponsorship: We're open to visa transfers, including H-1B transfers, and we can sponsor TN visas. O-1 visas may be considered for highly qualified candidates. We're unable to sponsor new H-1B visas or F-1 OPT/CPT.
We appreciate every application we receive. Due to the volume of interest, only candidates selected for an interview will be contacted.

