Senior Security Engineer

Digital Waffle

San Francisco (CA)

On-site

USD 130,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Digital Waffle is hiring a Security Engineer to own security across cloud infrastructure, application surfaces and the AI agent stack. This hands-on IC role will build the security programme from the ground up, partnering with product and infra engineers to bake security into shipping cycles and to secure AI agents in production.

You will own security reviews, threat modelling, secure SDLC, and remediation of high-priority risks, while helping the company achieve SOC 2 compliance and meet

Qualifications

  • 3–8 years hands-on information security experience
  • Primary domain in infrastructure and cloud security
  • Experience building security systems end-to-end (detection/response, secure SDLC, hardening)
  • Previous work at an early-stage or high-growth startup
  • Ambitious hands-on builder capable of owning multiple security domains

Responsibilities

  • Own security reviews and threat modelling for new and existing product surfaces across the AI-native platform
  • Build and improve core security processes including secure SDLC and detection and response
  • Harden cloud and application infrastructure and drive remediation of high-priority risks
  • Define how the business secures AI agents and governs their use, including guardrails and data exposure
  • Support enterprise customer trust through SOC 2 and customer-facing security needs
  • Partner with product and infrastructure engineering to embed security into shipping cycles

Skills

Cloud security
Infrastructure security
Threat modelling
Security engineering
Executive communication

Tools

GCP
AWS
Azure

Job description

A high-growth AI-native platform is hiring a Security Engineer as their second security hire to own security across cloud infrastructure, application surfaces and their AI agent stack.

This is a hands-on IC role with real scope. You'll build and scale the security programme from the ground up rather than maintain something that already exists, working closely with product and infrastructure engineering to embed security into how the business ships. Expect to own entire security domains end to end and shape how the company approaches an emerging area few teams have solved yet: securing AI agents in production.

Role: Security Engineer

What you'll be doing:
  • Own security reviews and threat modelling for new and existing product surfaces across the AI-native platform
  • Build and improve core security processes including secure SDLC and detection and response
  • Harden cloud and application infrastructure and drive remediation of high-priority risks
  • Help define how the business secures AI agents and governs their use, including guardrails, data exposure, prompt-injection and abuse risks
  • Support enterprise customer trust through compliance (SOC 2) and customer-facing security needs
  • Partner closely with product and infrastructure engineering to embed security into shipping cycles
What you'll need:
  • 3 to 8 years hands-on information security experience, with core work in security engineering rather than shipping product features or GRC-only work
  • Dedicated Security Engineer background with a primary domain in infrastructure and cloud security (GCP preferred, AWS or Azure also fine)
  • Track record building security systems end to end: detection and response, secure SDLC and infrastructure hardening, not just strategy or process documentation
  • Prior experience at an early-stage or high-growth startup (sub-500 headcount) where you built or scaled security infrastructure from scratch
  • High-slope career trajectory with clear scope and title growth
  • Ambitious, hands-on builder who thrives in ambiguity and is excited to own entire security domains as the second hire
  • Strategic communicator able to articulate problems and approach at an executive level, not only in technical detail
Nice to have:
  • Experience securing agentic AI or LLM systems, including guardrails, data exposure or prompt injection
  • Enterprise compliance experience (SOC 2, ISO 27001)

This role would suit a hands-on Security Engineer who wants to own entire domains, sit close to the founders and shape how a fast-moving AI-native business approaches security, including the parts nobody has fully figured out yet.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Digital Waffle • San Francisco (CA)

On-site
USD 140,000 - 210,000
Senior Software Security Engineer
Senior Software Security Engineer

Xcede • San Francisco (CA)

On-site
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Wintermeyer Ventures • San Francisco (CA)

On-site
USD 200,000 - 330,000
Equity
Senior Security Engineer
Senior Security Engineer

Xcede • San Francisco (CA)

On-site
USD 120,000 - 160,000
Significant equity upside
Competitive compensation
Founding-level impact
Security Engineer
Security Engineer

Clera • San Francisco (CA)

On-site
USD 180,000 - 250,000
Medical, dental, vision coverage
401k
Visa sponsorship
+2
Senior Security Engineer
Senior Security Engineer

Covenant HR • San Francisco (CA)

Hybrid
USD 150,000 - 190,000
Lead Security Engineer
Lead Security Engineer

Harrison Clarke • San Francisco (CA)

On-site
USD 180,000 - 240,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
Security Engineer - Product Security (Senior)
Security Engineer - Product Security (Senior)

Cogent • All (MO)

On-site
USD 100,000 - 300,000
Member of Technical Staff (Security) - AI Infrastructure
Member of Technical Staff (Security) - AI Infrastructure

Hamilton Barnes Associates Limited • United States

On-site
USD 213,000 - 288,000
Equity
Full Healthcare