Remote, US | $180K–$230K base + equity
About the Company
Our client is a funded, stealth-stage enterprise identity startup founded by a team with a strong track record building and scaling enterprise software. The company is tackling a large, stagnant identity market with a secure-by-design product philosophy and a strong emphasis on product quality, design, and engineering craft.
The team is currently small, fully remote, and backed by top-tier venture capital.
About the Role
This is the company’s first dedicated security hire.
You will define and build the company’s security program from scratch, working directly with a security-minded co-founder. This role spans product security, application security, corporate security, compliance, incident response, and detection. Over time, this person may build and lead the security function.
What You’ll Do
- Own the company’s security posture across product, infrastructure, and internal systems
- Lead security reviews, threat modeling, and secure design work
- Build foundational security systems such as secrets management, audit logging, vulnerability management, and certificate infrastructure
- Drive compliance programs such as SOC 2, ISO 27001, GDPR, and CCPA
- Define incident response processes and detection capabilities
- Partner closely with engineering to embed security into product development
- Help shape security culture across a small, high-caliber team
What We’re Looking For
- 5+ years of security engineering experience
- Strong application security background
- Experience with secure SDLC, threat modeling, vulnerability management, and security architecture
- Experience contributing to or running security programs
- Compliance experience, ideally SOC 2, ISO 27001, GDPR, or similar
- Backend or systems engineering fluency; Go experience is a plus
- Ability to operate with high ownership in an early-stage environment
- Low-ego, collaborative mindset and willingness to wear multiple hats
Nice to Have
- First or second security hire experience at a startup
- Detection engineering experience
- Identity, access management, enterprise IT, or security software background
- Kubernetes, GCP, cloud security, or infrastructure security experience
- Published security research, talks, or open-source security work