Founding Security Engineer | Series B Dev Infrastructure Company | Remote
Most "security engineer" job posts are lying to you. They say "wear many hats" and mean "inherit five years of someone else's backlog." This one's different: you'd be employee #1 in security at a fast-growing, well-funded Series B developer infrastructure company whose product sits at the heart of the software supply chain for some of the most demanding engineering orgs in the world — think quant trading firms, AI-native companies, and platform teams who don't tolerate sloppy tooling.
There is no program to slot into. No legacy ticket queue. No 40-person security org to navigate. There's a blank whiteboard, real budget, and a CEO who treats security as core to the product — not a compliance checkbox bolted on after the fact.
What you'd actually be doing:
- Standing up detection and response from scratch — SIEM or outsourced SOC, your call, then own it
- Hardening AWS (IAM, GuardDuty, Security Hub, SCPs) and Cloudflare (WAF, Zero Trust, DLP) hands-on — not writing recommendations for someone else to implement
- Writing and enforcing security scanning directly into Infrastructure as Code — Terraform is the backbone here, and you'll be embedding tools like Checkov/tfsec into CI/CD so bad config never ships in the first place, not just catching it after deploy
- Bringing order to endpoint security across a Mac-heavy dev fleet and production infrastructure
- Owning software supply chain security end-to-end — SBOMs, SLSA, dependency scanning, remediation — for a product where that's literally the customer value prop
- Getting genuinely hands-on with application security: integrating SAST/SCA tooling (think Semgrep, Snyk, GitHub Advanced Security) straight into developer workflows, sitting in on design reviews and threat modeling for new features, and working shoulder-to-shoulder with engineers to actually fix vulnerabilities using a risk-based model — not generating an aging report and hoping someone reads it
- Rationalizing IAM, SSO, and access reviews so entitlements stay clean as the company scales
- Talking directly to enterprise customers about security posture — this product runs in serious, security-conscious environments, and you'll be the credible technical voice in those conversations
You're a fit if:
- You've got 5+ years of hands-on security engineering, ideally at a software or cloud-native company — bonus points if that company was small enough that you built something instead of maintaining it
- You can actually code or script — this isn't optional
- You've got real application security chops — you can read code, you understand common vulnerability classes, and you've partnered with developers on fixes rather than just flagging findings and moving on
- You've got hands-on Infrastructure as Code experience — Terraform specifically — and you know how to build security into the pipeline itself, not just audit what's already deployed
- You know AWS security cold and have real Cloudflare experience (or the aptitude to pick it up fast)
- You understand software supply chain security — SBOMs, artifact signing, dependency risk — as more than buzzwords
- You've deployed and managed EDR/MDM across mixed dev and production environments
- You're the person who sees something broken and fixes it, rather than filing a ticket and waiting
You're probably not a fit if
you want a large team to manage, an existing program to optimize, or a role that's mostly governance and PowerPoint. This is a builder's seat.