Founding Security Engineer

Unizo Inc.

San Francisco (CA)

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Unizo Inc. is seeking a hands-on security practitioner to tackle exposure and risk reduction in a pioneering way. You will define exposure paths, reason about impact, and validate remediation to ensure risk declines.

You will build and shape the product to address enterprise security needs, working directly with security teams to translate recurring requirements into durable capabilities.

Qualifications

  • Hands-on experience in vulnerability management, exposure management, cloud security, product security, or security operations.
  • Investigate findings beyond severity scores and scanner output.
  • Understand how vulnerabilities, identities, permissions, reachability, and environmental context determine real risk.
  • Experience driving remediation with engineering, infrastructure, cloud, identity, and application owners.
  • Explain the difference between plausible exposure and theoretical risk to practitioners and executives.
  • Move between product definition, technical investigation, customer conversations, and implementation details.

Responsibilities

  • Define how exposure paths are identified and explained, not just re-ranking findings.
  • Investigate how vulnerabilities, identities, privileges, reachability, cloud access, code, and asset criticality combine into meaningful exposure.
  • Decide evidence to establish a real exposure, material relevance, or remediation success.
  • Judge whether the product's conclusions are technically sound, understandable, and actionable.
  • Collaborate with enterprise security teams to turn recurring needs into durable product capabilities.
  • Shape analyst behavior and guardrails within consequential security workflows.
  • Set technical standards and operating practices for the security function as the team grows.

Skills

Vulnerability management
Exposure management
Cloud security
Product security
Security operations
Threat modelling

Tools

Jira
ServiceNow

Job description

We are looking for a hands-on security practitioner who has lived the vulnerability and exposure management problem and wants to build a better way to solve it. You will help define how Unizo investigates exposures, reasons about impact, recommends remediation, and validates that risk has gone down.

This is not a role operating another vulnerability management program. You will build the product you wish you had while running one.

What you will do
  • Define how Unizo identifies and explains exposure paths, rather than re-ranking individual findings.
  • Investigate how vulnerabilities, identities, privileges, reachability, cloud access, code, and asset criticality combine into meaningful exposure.
  • Decide what evidence establishes that an exposure is real, materially relevant, or successfully remediated.
  • Judge whether the product's conclusions are technically sound, understandable, and actionable.
  • Work directly with enterprise security teams, and turn recurring needs into durable product capability.
  • Shape the behaviour and guardrails of an analyst operating inside consequential security workflows.
  • Set the technical standards and operating practices for the security function as the team grows.
You might be doing this today as a

Senior or Staff Security Engineer Vulnerability Management Engineer or Lead Threat and Vulnerability Management Engineer Cloud Security Engineer Product or Application Security Engineer Security Automation Engineer Offensive Security Engineer with remediation depth

What we are looking for
  • Hands-on experience in vulnerability management, exposure management, cloud security, product security, or security operations.
  • A habit of investigating findings beyond severity scores and scanner output.
  • Understanding of how vulnerabilities, identities, permissions, reachability, and environmental context determine real risk.
  • Experience driving remediation with engineering, infrastructure, cloud, identity, and application owners.
  • Technical judgment strong enough to separate plausible exposure from theoretical risk, and the ability to explain the difference to practitioners and executives alike.
  • Comfort moving between product definition, technical investigation, customer conversations, and implementation detail.

Useful but not required: vulnerability management, CNAPP, or endpoint platforms; AWS, Azure, or Google Cloud; IAM, privileged access, and service-account security; attack-path, reachability, or threat modelling; application and software supply chain security; Python, APIs, query languages, or graph-based investigation; ServiceNow, Jira, or remediation workflow systems.

You do not need previous startup experience. We care whether you have lived the problem, developed real practitioner judgment, and want to build a better operating model for exposure reduction.

About Unizo

Security teams have no shortage of findings. The harder problem is knowing which exposures matter in their environment, what to fix first, and whether remediation actually reduced risk.

Unizo is AI-native exposure management. We connect fragmented security signals into Live Security Context, a continuously updated model of assets, vulnerabilities, identities, access, cloud infrastructure, code, ownership, and controls. The Exposure Analyst reasons over that context to investigate exposures, explain why they matter, recommend evidence-backed actions, and verify outcomes, inside the controls and approval gates each customer sets.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Founding Customer Security Engineer
Founding Customer Security Engineer

Unizo Inc. • San Francisco (CA)

On-site
USD 150,000 - 230,000
Founding Security Engineer - Exposure Management Innovator
Founding Security Engineer - Exposure Management Innovator

Unizo Inc. • San Francisco (CA)

On-site
USD 150,000 - 190,000
Staff Vulnerability Management Engineer
Staff Vulnerability Management Engineer

United States Digital Space LLC • Seattle (WA), San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Principal Product Manager (XDR & Exposure Management) - Security Solutions
Principal Product Manager (XDR & Exposure Management) - Security Solutions

United States Digital Space LLC • United States

On-site
USD 140,000 - 190,000
Cybersecurity Engineer - Vulnerability Management
Cybersecurity Engineer - Vulnerability Management

Janestreet • New York (NY)

On-site
USD 100,000 - 130,000
Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000
Vulnerability Analyst — External Attack Surface & VDP
Vulnerability Analyst — External Attack Surface & VDP

Vanguard • Malvern

Hybrid
USD 80,000 - 110,000
Growth pathways in security roles
Hybrid working model
Senior Security Manager - Vulnerability Management
Senior Security Manager - Vulnerability Management

Alter Domus • Chicago (IL)

On-site
USD 140,000 - 190,000
Attack Surface and Exposure Validation Assistant Engineer
Attack Surface and Exposure Validation Assistant Engineer

EY • City of Rochester (NY)

On-site
USD 140,000 - 200,000
Attack Surface and Exposure Validation Assistant Engineer
Attack Surface and Exposure Validation Assistant Engineer

EY • Jericho (NY)

On-site
USD 150,000 - 210,000