Unknown Company

Senior/Staff Security Engineer

san francisco, ca • Posted 1 weeks ago
Onsite Full Time IT & Technology

About the Company


Our client is an early-stage, seed-funded startup building an AI "coworker" for enterprise IT teams — an agent that operates as a governed identity inside a customer's directory, requests scoped access for each task, and acts only under human approval. They're backed by well-known operators and investors from across the IT and security world, already have live design partners, and are building a product category with very little prior art.


Founded 2026 · 1–10 people · Industry: AI Tools / Enterprise IT & Security


The Role


You’ll own the security posture of the company and its product end-to-end — application, cloud, network, and the agent itself. Because there’s limited prior art for securing a governed-identity agent that requests scoped access and acts under human approval, the work is genuinely novel: leading secure design reviews, building security primitives into the product, and owning the security story that enterprise buyers read before they deploy.


What you’ll be doing



  • Own the end-to-end security posture: application, cloud, network, and the agent itself

  • Lead secure design reviews and threat modeling for a governed-identity, approval-gated agent

  • Build security primitives into the product: per-customer isolation, credentials the agent uses but never sees, approval gates on write actions, a customer-controlled capability dial, and replayable audit trails

  • Own the written security architecture that enterprise buyers review before deploying

  • Run external validation: penetration testing, compliance frameworks, and enterprise security reviews

  • Own incident readiness and response, with breach notification measured in hours

  • Push scanning, secret detection, and compliance checks into CI

  • Set the internal bar for credential handling and data egress


Tech stack: Python / Go / Rust / TypeScript; cloud + infrastructure-as-code; identity & workload IAM; container / microVM isolation; CI security tooling


Requirements



  • Senior/Staff-level, hands-on experience across both application and infrastructure security

  • Writes production-quality code in at least one of Python, Go, Rust, or TypeScript

  • Strong practical threat-modeling and vulnerability-identification skills

  • Real depth in network and identity security — identity-based controls, policy enforcement, and workload IAM

  • Cloud security expertise on at least one major provider, including identity federation and infrastructure-as-code

  • Communicates risk trade-offs clearly to both hands-on engineers and executive stakeholders

  • Thrives with high autonomy in an ambiguous, fast-moving environment

  • Able to work on-site in San Francisco, Monday–Friday, at startup intensity


Nice to Haves



  • Experience securing agentic or code-execution systems

  • Depth in modern isolation techniques — container security, kernel-level hardening, microVMs

  • Offensive security or penetration-testing background

  • Have run or owned a bug bounty or vulnerability disclosure program

  • Have carried a company through compliance frameworks and enterprise security reviews

  • Familiarity with enterprise IT and identity — directory services, SSO, PAM

  • A standout track record of excellence, whether a top-tier CS/engineering education, strong competition results, or building and leading at a high-growth company

  • High agency — former founders or engineers who've owned large, ambiguous scope


Why Join



  • Own security end-to-end as the founding security hire, on a genuinely novel problem

  • Help define a new category — securing governed-identity AI agents for enterprise IT

  • Meaningful equity (1–2%) and strong backing from respected IT and security operators

  • Work directly with the founders and live enterprise design partners


Details



  • Location — San Francisco, CA

  • Work policy — On-site, Monday–Friday

  • Compensation — $200,000–$300,000 + 1–2% equity

  • Visa sponsorship — Available (H-1B, O-1, OPT)

  • Employment type — Full-time

#J-18808-Ljbffr
Back to Job Search