Senior/Staff Security Engineer
Listed on 2026-08-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
About the Company
Our client is an early-stage, seed-funded startup building an AI "coworker" for enterprise IT teams — an agent that operates as a governed identity inside a customer's directory, requests scoped access for each task, and acts only under human approval. They're backed by well-known operators and investors from across the IT and security world, already have live design partners, and are building a product category with very little prior art.
Founded 2026
· 1–10 people
· Industry: AI Tools / Enterprise IT & Security
You’ll own the security posture of the company and its product end-to-end — application, cloud, network, and the agent itself. Because there’s limited prior art for securing a governed-identity agent that requests scoped access and acts under human approval, the work is genuinely novel: leading secure design reviews, building security primitives into the product, and owning the security story that enterprise buyers read before they deploy.
What you’ll be doing- Own the end-to-end security posture: application, cloud, network, and the agent itself
- Lead secure design reviews and threat modeling for a governed-identity, approval-gated agent
- Build security primitives into the product: per-customer isolation, credentials the agent uses but never sees, approval gates on write actions, a customer-controlled capability dial, and replayable audit trails
- Own the written security architecture that enterprise buyers review before deploying
- Run external validation: penetration testing, compliance frameworks, and enterprise security reviews
- Own incident readiness and response, with breach notification measured in hours
- Push scanning, secret detection, and compliance checks into CI
- Set the internal bar for credential handling and data egress
Tech stack: Python / Go / Rust / Type Script; cloud + infrastructure-as-code; identity & workload IAM; container / microVM isolation; CI security tooling
Requirements- Senior/Staff-level, hands-on experience across both application and infrastructure security
- Writes production-quality code in at least one of Python, Go, Rust, or Type Script
- Strong practical threat-modeling and vulnerability-identification skills
- Real depth in network and identity security — identity-based controls, policy enforcement, and workload IAM
- Cloud security expertise on at least one major provider, including identity federation and infrastructure-as-code
- Communicates risk trade-offs clearly to both hands-on engineers and executive stakeholders
- Thrives with high autonomy in an ambiguous, fast-moving environment
- Able to work on-site in San Francisco, Monday–Friday, at startup intensity
- Experience securing agentic or code-execution systems
- Depth in modern isolation techniques — container security, kernel-level hardening, microVMs
- Offensive security or penetration-testing background
- Have run or owned a bug bounty or vulnerability disclosure program
- Have carried a company through compliance frameworks and enterprise security reviews
- Familiarity with enterprise IT and identity — directory services, SSO, PAM
- A standout track record of excellence, whether a top-tier CS/engineering education, strong competition results, or building and leading at a high-growth company
- High agency — former founders or engineers who've owned large, ambiguous scope
- Own security end-to-end as the founding security hire, on a genuinely novel problem
- Help define a new category — securing governed-identity AI agents for enterprise IT
- Meaningful equity (1–2%) and strong backing from respected IT and security operators
- Work directly with the founders and live enterprise design partners
- Location — San Francisco, CA
- Work policy — On-site, Monday–Friday
- Compensation — $200,000–$300,000 + 1–2% equity
- Visa sponsorship — Available (H-1B, O-1, OPT)
- Employment type — Full-time
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).