Security Engineer

Guava

Los Angeles (CA)

On-site

USD 120,000 - 165,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Guava is the voice platform for regulated industries and is hiring a Security Engineer to own security across infrastructure, product, and internal systems. You will reduce risk in our cloud environment and voice pipeline, support SOC 2, HITRUST, HIPAA, and PCI-adjacent compliance, and partner with engineering to bake security into the product.

This hands-on IC role reports to the Head of Engineering and offers real ownership over the security program as Guava scales, with direct access to

Qualifications

  • 4+ years in security engineering or related roles.
  • Experience securing cloud infrastructure (AWS, GCP, or Azure) with IAM and encryption.
  • Comfort reading code and collaborating with engineers on fixes.
  • Experience with compliance programs SOC 2, HITRUST, HIPAA, ISO 27001, or PCI DSS.

Responsibilities

  • Own security architecture and hardening across cloud, voice pipeline, and internal systems.
  • Design controls for IAM, network segmentation, encryption, and secrets management.
  • Collaborate with engineering on secure design reviews, threat modeling, and code-level guidance.
  • Provide technical guidance on application, API, cloud, platform, and AI security.
  • Support compliance program including evidence collection and control implementation.
  • Build and maintain security monitoring, logging, and incident response leadership.
  • Manage relationships with external vendors, auditors, and testers; drive remediation.
  • Own security tooling and automation as the platform scales.

Skills

Security engineering
Cloud security
Compliance frameworks
Threat modeling
Incident response
Security monitoring
Code review

Tools

SAST/DAST tools
CSPM
SIEM

Job description

Compensation: $120,000– $165,000 + equity
About Guava

Guava is the voice platform built for regulated industries — the calls that have to be right. Trained on 10B+ live agent minutes and in regulated production. We serve healthcare systems, banks, insurance carriers, BPOs, and tech-native companies that need voice infrastructure they can stake their business on.

Security isn't a checkbox at Guava — it's the reason our customers can trust us with real calls, real patient data, and real financial transactions. We're looking for a Security Engineer to help us build, harden, and prove out the security posture that our most regulated customers require.

The Role

Guava is looking for a Security Engineer to own and mature security across our infrastructure, product, and internal systems. You will work hands-on to reduce risk across our cloud environment and voice pipeline, support our compliance program (SOC 2, HITRUST, HIPAA, and PCI-adjacent requirements), and partner directly with engineering to build security into the product rather than bolt it on afterward.

This is a hands-on, individual-contributor role reporting to the Head of Engineering. You will be one of the first dedicated security hires at Guava, with real ownership over how our security program is built and a direct line to engineering leadership.

What You'll Do
  • Own security architecture and hardening across our cloud infrastructure, voice pipeline, and internal systems.
  • Design and implement security controls for identity and access management, network segmentation, encryption, and secrets management.
  • Partner with engineering on secure design reviews, threat modeling, and code-level security guidance for new features.
  • Provide technical guidance on application, API, cloud, platform, and AI security.
  • Support Guava's compliance program (SOC 2, HITRUST i1, HIPAA, and customer security questionnaires), including evidence collection and control implementation.
  • Build and maintain security monitoring, logging, and alerting across production systems; lead incident response when issues arise.
  • Manage relationships with external security vendors, auditors, and penetration testers, and drive remediation of findings.
  • Own security-related tooling and automation (SAST/DAST, dependency scanning, CSPM, SIEM) as the team and platform scale.
  • Contribute to security policy, employee security training, and vendor risk assessments in partnership with People Ops and compliance.
What We're Looking For
  • 4+ years of experience in security engineering, application security, or a related infrastructure/security role.
  • Hands-on experience securing cloud infrastructure (AWS, GCP, or Azure) — IAM, networking, encryption, and secrets management.
  • Experience supporting a compliance framework such as SOC 2, HITRUST, HIPAA, ISO 27001, or PCI DSS.
  • Comfortable reading and reviewing code for security issues, and working directly with engineers to fix them.
  • Practical experience with vulnerability management, security monitoring/SIEM tooling, and incident response.
  • Strong written communication — you can explain risk and tradeoffs clearly to both engineers and auditors.
  • Based in or willing to work from Guava's Downtown Los Angeles (Arts District) office.
Nice to Haves
  • Experience securing real-time or telephony/voice systems (SIP/PSTN, WebRTC, or similar).
  • Experience at a company selling into healthcare, financial services, insurance, or other highly regulated industries.
  • Relevant certifications (OSCP, CISSP, GIAC, or similar) — not required, but a plus.
  • Experience building a security program from an early stage, rather than maintaining an established one.
Why Guava
  • Own security for a voice AI platform running in real, regulated production — not a research demo.
  • Direct access to engineering leadership; real influence over how the security program is built.
  • Join at a stage where you can shape the architecture and process, not just maintain someone else's.

Guava is an equal opportunity employer. We welcome applicants of all backgrounds and are committed to building a diverse and inclusive team.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Governance, Risk & Compliance
Head of Governance, Risk & Compliance

Guava • Los Angeles (CA)

On-site
USD 140,000 - 180,000
Base salary + equity
Medical/dental/vision
401(k) matching
+3
Security Engineer: Cloud, Compliance & Encryption (Equity)
Security Engineer: Cloud, Compliance & Encryption (Equity)

Guava • Los Angeles (CA)

On-site
USD 120,000 - 165,000
QA Engineer
QA Engineer

Guava • Los Angeles (CA)

On-site
USD 130,000 - 165,000
Health, dental, vision insurance
401(k) match
Parental leave (PFL/CFRA)
+1
Forward Deployed Engineer
Forward Deployed Engineer

Guava • Los Angeles (CA)

On-site
USD 110,000 - 140,000
Health insurance
401(k) match
Gym membership
+1
Machine Learning Engineer
Machine Learning Engineer

Guava • Los Angeles (CA)

On-site
USD 140,000 - 180,000
Health, dental, and vision coverage
401(k) match
Flexible PTO
+1
Enterprise Account Executive
Enterprise Account Executive

Guava • Los Angeles (CA)

Hybrid
USD 300,000 - 500,000
Competitive base pay
Uncapped commission
Equity options
+1
Head of Product-Led Growth
Head of Product-Led Growth

Guava • Los Angeles (CA)

On-site
USD 140,000 - 180,000
Competitive base salary + equity
Medical, dental, vision
401(k) with employer match
+3
Senior Security Engineer
Senior Security Engineer

Translucent • New York (NY)

On-site
USD 180,000 - 250,000
Equity
In-office 4 days/week
Competitive compensation
Security Engineer
Security Engineer

decagon • San Francisco (CA)

On-site
USD 200,000 - 330,000
Take what you need vacation policy
Medical, Dental, and Vision benefits
Life Insurance and Disability Benefits
+4
Senior Software Engineer, Security
Senior Software Engineer, Security

Nectar Social • Palo Alto (CA)

Hybrid
USD 180,000 - 240,000
Competitive compensation and early-equ
Health, vision, and dental benefits +