Sr. Security Engineer

C1

Portland (OR)

On-site

USD 100,000 - 200,000

Full time

13 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Equity
Health benefits
Competitive salary

Job summary

C1 is hiring a Senior Security Engineer to join a small, early-stage security team with a broad remit spanning security engineering, application and cloud security, and compliance. This is a generalist role: you'll have the opportunity to go deep in one domain over time while staying hands-on and supportive across others. Our stack is primarily Go and AWS.

Little of this job is manual. Instead of hand-reviewing every ticket, spec, or deploy, you'll spend your time building the purpose-built

Qualifications

  • Senior security engineer role with hands-on security engineering, app and cloud security, and compliance.
  • Go and AWS stack; focus on automation and security in the development lifecycle.
  • Build agents and skills to automate security tasks and reduce manual work.

Responsibilities

  • Define and drive security standards and secure-by-default solutions for applications and cloud.
  • Build agents and skills to automate triage, enrichment, and review across the lifecycle.
  • Shift security left by embedding risk-based review into design and architecture decisions.
  • Develop security tooling and observability signals at scale across engineering teams.
  • Lead threat modeling and risk assessment for high-risk features and platform changes.
  • Assess risks from agentic development and AI-powered features in production.
  • Collaborate with engineering to prioritize remediation and API security standards.
  • Explore open-source tools to assess security and reduce manual review.
  • Identify systemic risks and lead multi-team remediation end-to-end.

Skills

Security engineering
Application security
Cloud security
Go
AWS
Threat modeling
Automation
Open-source tooling

Tools

Kubernetes
Envoy
Istio
Consul
Cilium
Vault

Job description

C1 is the first AI-native identity security platform that protects every identity: human, non-human, and AI. With powerful automation, platform-level AI, and out-of-the-box connectors, it centralizes access visibility, enforces fine-grained controls, enables just-in-time access, and automates user access reviews across all apps. It's easy to use, quick to deploy, and trusted by enterprises like DigitalOcean, Instacart, Ramp, and Zscaler.

The Role

We're hiring a Senior Security Engineer to join a small, early-stage security team with a broad remit - spanning security engineering, application and cloud security, and compliance. This is a generalist role: you'll have the opportunity to go deep in one domain over time while staying hands-on and supportive across others. Our stack is primarily Go and AWS.

Little of this job is manual. Instead of hand-reviewing every ticket, spec, or deploy, you'll spend your time building the purpose-built agents and skills that do that work continuously, and using them to orchestrate security into the development lifecycle through a risk-based approach. Our goal is to bake security into design specs up front, not catch it in post-deploy review.

You don't just want to hand engineering teams a list of findings - you want to roll up your sleeves and help implement the fix. You care about solving problems systemically, not just patching individual instances, and you want your work to make it easier for everyone at the company to build securely by default.

What You'll Do
  • Define and drive security standards and secure-by-default solutions, serving as a subject matter expert for application and/or cloud security.
  • Build purpose-built agents and skills that orchestrate security into the development lifecycle through a risk-based approach, automating the manual, repetitive work (triage, enrichment, review) so the team can focus on judgment calls, not queues.
  • Shift security left by baking risk-based review into design specs and architecture decisions, rather than relying on post-deploy audits to catch issues.
  • Build security tooling and automation that scales security practices across engineering, and help implement meaningful, actionable security observability and detection signals.
  • Lead threat modeling and risk assessment for high-risk features and platform changes.
  • Assess and help mitigate security risks introduced by agentic development practices and AI-powered product features running in production.
  • Partner with engineering teams to prioritize and remediate critical threats, help define API security standards, and conduct security code reviews.
  • Continuously explore and adopt open-source tools to assess the security of and test our services, rather than defaulting to manual review.
  • Identify systemic security risks and lead multi-team remediation efforts end-to-end, not just the initial recommendation.
  • Partner across security, compliance, and engineering on cross-domain problems — be a go-to point of contact when a hard security question needs clarity.
  • Contribute to compliance and trust initiatives (e.g., SOC 2, ISO 27001/42001) as they intersect with your area of focus.
  • Invest in the growth of teammates and in raising the security bar across the broader engineering org.
Show Us Your Agent Work

This role expects real, hands-on experience building agents and automation for security, so we ask candidates to show it rather than just claim it. As part of the process, be ready to share one or more of the following:

  • A project, demo, or repo where you built an agent, skill, or automation that replaced manual security work (triage, review, detection, etc.).
  • Examples of how you use AI coding tools or agentic workflows in your day-to-day work.
  • A short walkthrough - live or recorded - of a security automation you shipped, including the problem, your approach, and the impact.

We care about practical results and good judgment in where (and where not) to apply automation, not just familiarity with the latest tools.

Nice to Have
  • Experience with Kubernetes, service mesh, or PKI/network technologies (Consul, Envoy, Cilium, Vault, Istio, etc.).
  • Experience building or extending internal security tooling, automations, or agents.
  • Prior experience at a high-growth SaaS or identity/access management company.
Why This Role

This is a high-leverage role on a small, early-stage security team: your scope will be broad, your ownership will be real, and the systems you build will shape how a security-first company secures its own products and development lifecycle. You'll have the chance to specialize in the domain you care most about while still touching the full breadth of the security program.

Compensation & Benefits

C1 offers a competitive salary, meaningful equity, and comprehensive health benefits. Specific compensation will be commensurate with experience.

ConductorOne, Inc. is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status or any other category protected by law.

Compensation Range: $100K - $200K

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Engineer
Sr. Security Engineer

Garuda Ventures • San Francisco (CA)

On-site
USD 170,000 - 250,000
Comprehensive health benefits
Equity
Sr. Security Engineer
Sr. Security Engineer

C1 • San Francisco (CA)

On-site
USD 180,000 - 280,000
Sr. Security Engineer
Sr. Security Engineer

JobCubby • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Competitive salary
Meaningful equity
Comprehensive health benefits
Senior Software Engineer, Internal Tools
Senior Software Engineer, Internal Tools

Garuda Ventures • San Francisco (CA)

On-site
USD 180,000 - 260,000
Competitive salary
Meaningful equity
Comprehensive health benefits
Security Engineer - Corporate Security (Senior)
Security Engineer - Corporate Security (Senior)

Cogent • All (MO)

On-site
USD 100,000 - 300,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Cogent-Security • United States

On-site
USD 100,000 - 300,000
Senior Security Engineer - Corporate Security
Senior Security Engineer - Corporate Security

Cogent Security • San Francisco (CA)

On-site
USD 100,000 - 300,000
Security Engineer - Corporate Security (Senior)
Security Engineer - Corporate Security (Senior)

Cogent-Security • United States

On-site
USD 100,000 - 300,000
Security Engineer - Product Security (Senior)
Security Engineer - Product Security (Senior)

Cogent • All (MO)

On-site
USD 100,000 - 300,000
Agent Engineer (Member of Technical Staff)
Agent Engineer (Member of Technical Staff)

Cogent Security • San Francisco (CA)

On-site
USD 100,000 - 300,000