Senior Application Security Engineer

Digital Waffle

San Francisco (CA)

On-site

USD 140,000 - 210,000

Full time

7 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Digital Waffle in San Francisco is seeking a hands-on Security Engineer to own security across cloud infrastructure, application surfaces, and the AI agent stack. This is the second security hire in a high-growth AI-native platform.

You'll build the security program from the ground up, partner closely with product and infrastructure engineers, and drive secure SDLC, threat modelling, and compliance efforts (SOC 2) to earn customer trust.

Qualifications

  • 3 to 8 years hands-on information security experience, focused on security engineering.
  • Experience in infrastructure and cloud security (GCP preferred).
  • Proven track record building security systems end to end: detection/response, secure SDLC and hardening.
  • Experience at early-stage or high-growth startups building security infrastructure from scratch.
  • Ambitious hands-on builder excited to own entire security domains as second hire.
  • Strategic communicator able to discuss problems and approach at an executive level.

Responsibilities

  • Own security reviews and threat modelling for new and existing product surfaces across the AI-native platform.
  • Build and improve core security processes including secure SDLC and detection and response.
  • Harden cloud and application infrastructure and drive remediation of high-priority risks.
  • Help define how the business secures AI agents and governs their use, including guardrails, data exposure, prompt-injection and abuse risks.
  • Support enterprise customer trust through compliance (SOC 2) and customer-facing security needs.
  • Partner closely with product and infrastructure engineering to embed security into shipping cycles.

Skills

Threat modelling
Security reviews
Secure SDLC
Cloud security
Infrastructure hardening
Executive communication
Startup experience

Tools

GCP
AWS
Azure
SOC 2 tooling

Job description

A high-growth AI-native platform is hiring a Security Engineer as their second security hire to own security across cloud infrastructure, application surfaces and their AI agent stack.

This is a hands-on IC role with real scope. You'll build and scale the security programme from the ground up rather than maintain something that already exists, working closely with product and infrastructure engineering to embed security into how the business ships. Expect to own entire security domains end to end and shape how the company approaches an emerging area few teams have solved yet: securing AI agents in production.

Role: Security Engineer

What you'll be doing:
  • Own security reviews and threat modelling for new and existing product surfaces across the AI-native platform
  • Build and improve core security processes including secure SDLC and detection and response
  • Harden cloud and application infrastructure and drive remediation of high-priority risks
  • Help define how the business secures AI agents and governs their use, including guardrails, data exposure, prompt-injection and abuse risks
  • Support enterprise customer trust through compliance (SOC 2) and customer-facing security needs
  • Partner closely with product and infrastructure engineering to embed security into shipping cycles
What you'll need:
  • 3 to 8 years hands-on information security experience, with core work in security engineering rather than shipping product features or GRC-only work
  • Dedicated Security Engineer background with a primary domain in infrastructure and cloud security (GCP preferred, AWS or Azure also fine)
  • Track record building security systems end to end: detection and response, secure SDLC and infrastructure hardening, not just strategy or process documentation
  • Prior experience at an early-stage or high-growth startup (sub-500 headcount) where you built or scaled security infrastructure from scratch
  • High-slope career trajectory with clear scope and title growth
  • Ambitious, hands-on builder who thrives in ambiguity and is excited to own entire security domains as the second hire
  • Strategic communicator able to articulate problems and approach at an executive level, not only in technical detail
Nice to have:
  • Experience securing agentic AI or LLM systems, including guardrails, data exposure or prompt injection
  • Enterprise compliance experience (SOC 2, ISO 27001)

This role would suit a hands-on Security Engineer who wants to own entire domains, sit close to the founders and shape how a fast-moving AI-native business approaches security, including the parts nobody has fully figured out yet.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Security Engineer
Senior Software Security Engineer

Xcede • San Francisco (CA)

On-site
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Xcede • San Francisco (CA)

On-site
USD 120,000 - 160,000
Significant equity upside
Competitive compensation
Founding-level impact
Senior Security Engineer
Senior Security Engineer

Covenant HR • San Francisco (CA)

Hybrid
USD 150,000 - 190,000
Lead Security Engineer
Lead Security Engineer

Harrison Clarke • San Francisco (CA)

On-site
USD 180,000 - 240,000
Security Engineer
Security Engineer

Clera • San Francisco (CA)

On-site
USD 180,000 - 250,000
Medical, dental, vision coverage
401k
Visa sponsorship
+2
Security Engineer - Product Security (Senior)
Security Engineer - Product Security (Senior)

Cogent • All (MO)

On-site
USD 100,000 - 300,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
Founding Security Engineer
Founding Security Engineer

Success Matcher Recruitment • San Francisco (CA)

On-site
USD 180,000 - 280,000
Member of Technical Staff (Security) - AI Infrastructure
Member of Technical Staff (Security) - AI Infrastructure

Hamilton Barnes Associates Limited • United States

On-site
USD 213,000 - 288,000
Equity
Full Healthcare
Security Engineer
Security Engineer

Invictus Direct • San Francisco (CA)

On-site
USD 100,000 - 200,000
Relocation assistance
Visa sponsorship