Lead Security Engineer

Shoptalk

Brasil

Presencial

BRL 300 000 - 600 000

Tempo integral

Há 8 dias

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

LawnStarter is seeking a security leader to elevate our security from a distributed practice to a deliberate, instrumented program. You will own end-to-end security for the PHP/Laravel and TypeScript/React codebase, the AWS infrastructure, the payments and customer-data flows, and the compliance posture.

Initially hands-on, you’ll build a foundation, then scale into a team within 12–18 months, partnering with delivery and Cloud & DevOps, setting multi-year direction, standards, and hiring

Descrição da oferta de emprego

About LawnStarter

LawnStarter is the nation's leading on-demand marketplace for lawn care and outdoor services, with over $100M in annual bookings. We're expanding beyond lawn care to become the one-stop shop for all home services — operating across three brands (LawnStarter, Lawn Love, Home Gnome) on a single shared platform, with customers and pros on both sides and real money moving every day.

About Security at LawnStarter

Security is already part of how we build — today it's owned by our Cloud & DevOps team, we've kept it solid as we've scaled. As we grow a $100M+ marketplace that processes payments, holds customer and pro data, and runs on AWS — and as AI agents let us ship faster than ever — we're ready to take security to the next level with a dedicated leader.

You'd be that person: the lead who takes security from a distributed, informal practice to a deliberate, instrumented one, and who sets the multi-year direction the org — and eventually a team — follows. You'll partner closely with the delivery teams and with Cloud & DevOps, and you'll start by doing most of the heavy lifting yourself, with the autonomy of a founding hire and the backing of an engineering org that already cares about getting this right. Part of the job is building security so it can outgrow one person: the standards, playbooks, and hiring bar you lay down now are the foundation for the team you'll grow into leading.

The Role

You lead security at LawnStarter end-to-end: the PHP/Laravel and TypeScript/React codebase, the AWS infrastructure, the payments and customer-data flows, and the compliance posture. You set the multi-year direction, build the controls, and are the person the org looks to on every security question.

You start hands-on — security-of-one for now — with an explicit path to leading a small team within roughly 12-18 months, once the foundation is solid and the first hire makes sense. This isn't a hands-off management role: you lead by doing first. You'll collaborate heavily with the delivery teams and lean on Cloud & DevOps where it helps, but most of the heavy lifting is yours today. So you'll prioritize ruthlessly, automate hard, and pick the few things that actually reduce risk over the long list that merely looks thorough.

What makes this role different:

  • You lead the function. You'll take security from a distributed, informal practice to a deliberate, instrumented one — threat models, automated scanning, incident runbooks — all bearing your design, and all built to scale past you.
  • You span every layer. AppSec one day, AWS IAM the next, PCI scoping the day after. Breadth is the job, not a stretch.
  • You secure an AI-agent codebase. Most new code here is authored by AI agents. Keeping that safe — at speed — is a problem most security engineers haven't faced yet.
  • You build for the team you'll grow. You're not just solving today's problem; you're laying the standards, playbooks, and hiring bar for the security team you'll lead next.
  • You set the bar. You're the lead security voice, and the standard for the org — and its future team — is the one you define and champion.
What You'll Own
  • Application security — threat modeling the critical path, secure-SDLC practices, code and design review, SAST/secret-scanning/dependency-scanning in CI, and a vulnerability-management loop that actually closes findings.
  • Cloud & infrastructure security — AWS posture (IAM, network, encryption), secrets management, EKS/Kubernetes hardening, partnering with Cloud & DevOps on the guardrails that keep misconfigurations out of production.
  • Compliance & data protection — mapping PCI scope for payments, driving SOC 2 and LGPD readiness, vendor risk, and being the person who can confidently answer a customer or auditor security questionnaire.
  • Detection & response — strengthening detection coverage on the critical path (Datadog, Sentry, AWS signal), an incident runbook, and the muscle to lead a response when something fires.
  • The security bar for AI-agent code — the scans, review gates, and conventions that let agent-authored code ship fast and safely.
  • The foundation for the team you'll lead — the standards, playbooks, and hiring bar that let security scale beyond one person.
Leading security across a $100M marketplace

The surface is broad — payments, customer and pro PII, three brands, a shared codebase, live AWS infra — and for now it's just you. The hard part isn't knowing what to do; it's sequencing it well when you can't do everything at once, and automating enough that one person can hold a high bar while planning for the team that comes next. How do you find the risks that matter most, burn them down first, and build in a way that a second and third engineer can pick up cleanly?

Keeping pace with AI-agent-authored code

Most of our code is now written by AI agents, which means more code shipping faster than any human reviewer can read. Manual security review alone doesn't scale to that. How do you build automated gates, secure-coding conventions, and evals that catch real vulnerabilities at agent speed — without becoming the bottleneck the engineering org routes around?

Maturing our compliance posture

We take payments and protect customer data with care; the next step is formalizing that into structured, audit-ready compliance (PCI scope, SOC 2, LGPD). You'll map what's in scope, decide what's worth doing now versus later, and get us audit-ready without turning the company into a checkbox factory. What's the right program that protects customers and unblocks deals

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Lead Security Engineer
Lead Security Engineer

FyrFly Venture Partners • Brasil

Presencial
BRL 400 000 - 640 000
Lead Security Engineer
Lead Security Engineer

LawnStarter • Recife

Presencial
BRL 200 000 - 350 000
Lead Security Engineer
Lead Security Engineer

LawnStarter • Belo Horizonte

Teletrabalho
BRL 260 000 - 480 000
Lead security function
Top-of-market cash compensation
Fully remote (Brazil)
+2
Staff Product Engineer
Staff Product Engineer

Ai Wiki • Brasil

Presencial
BRL 362 000 - 492 000
Software Engineering Manager
Software Engineering Manager

LawnStarter Inc. • São Paulo

Híbrido
BRL 624 000 - 728 000
Data Governance & Platform Manager
Data Governance & Platform Manager

LawnStarter • São Paulo

Híbrido
BRL 390 000 - 520 000
Fully remote
Staff Product Engineer (Campinas)
Staff Product Engineer (Campinas)

The Resume Database • Campinas

Presencial
BRL 402 000 - 504 000
Work from anywhere
High ownership and autonomy
Fast-moving team that loves to build, learn, and grow
Senior/Lead AppSec Engineer ID71672
Senior/Lead AppSec Engineer ID71672

AgileEngine, LLC. • Brasília

Presencial
BRL 180 000 - 290 000
Growth without limits
Competitive compensation
Flexibility — 100% remote
+3
Senior/Lead AppSec Engineer ID71672
Senior/Lead AppSec Engineer ID71672

AgileEngine, LLC. • Salvador

Teletrabalho
BRL 180 000 - 320 000
Growth without limits
Competitive compensation
Flexibility: 100% remote with flexible
+3
Senior DevOps Engineer - LATAM
Senior DevOps Engineer - LATAM

Neura Market • Brasil

Presencial
BRL 260 000 - 420 000
None