Sr. Security Engineer

OpenSpace

San Francisco (CA)

On-site

USD 180,000 - 230,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision coverage (
Flexible paid time off
401(k) with company match
Paid parental leave
Home office stipend
Employee referral program
Annual company retreats and teamings

Job summary

OpenSpace is hiring a Senior Security Engineer to strengthen proactive security practices across our AI-powered platform. You will drive threat modeling, secure design reviews, and secure SDLC integration while partnering with the engineering org to triage and remediate vulnerabilities.

You will own AI security risk management, govern internal AI tooling use, and help advance our incident response capabilities.

Qualifications

  • 5+ years in security engineering, application security and infrastructure security.
  • Hands-on experience performing proactive security reviews on production systems.
  • Strong fundamentals in web security, cloud security (AWS/GCP) and modern auth patterns.
  • Comfort reading/reviewing code across Python, Java/Kotlin, or TypeScript stacks.
  • An informed view on how AI changes security risks and tooling.
  • Experience working in a startup or fast-moving environment; prioritization and tradeoffs.

Responsibilities

  • Run proactive security reviews of new features, architectures, and third‑party integrations before they ship.
  • Assist in optimizing the security practice: threat modeling, design review, and secure SDLC integration.
  • Own AI-related security risk approaches: securing AI/ML systems and governing internal AI tooling use.
  • Partner with engineering to triage and remediate vulnerabilities from pen tests and findings.
  • Support SOC 2 and ISO 27001 programs as a technical contributor.
  • Help mature incident response and run tabletop exercises.
  • Build internal tooling to scale security review and reduce shipping bottlenecks.
  • Collaborate with consultants on pen tests, vendor assessments, and customer security reviews.

Skills

Security engineering
Threat modeling
Cloud security
Secure code review
AI security perspective
Influencing engineers

Tools

AWS
GCP
Penetration testing tools
DevSecOps tooling
Claude Code or similar

Job description

At OpenSpace, we're redefining how the world's most complex projects are built. Our AI-powered Visual Intelligence Platform uses computer vision and spatial AI to give construction teams a real-time view of what's happening on-site, helping them build faster, safer, and with greater confidence.

But what truly sets us apart is our people. We hire curious, driven teammates who love solving hard problems, taking ownership, and making a real-world impact. Great people build great culture—and apparently it shows. Forbes has named OpenSpace one of America's Best Startup Employers five years in a row. Come see what all the fuss is about.

Brief summary of role:

Security is in OpenSpace's DNA. A significant portion of our core engineering team — including several of our most senior engineers — came together at a security SaaS company before OpenSpace, and that shows up in how we design systems, review code, and think about customer data. We run a mature program today: an external security partner handles pen testing and structured assessments, our DevOps and IT team owns infrastructure security, IAM, and endpoint, and product engineers carry real ownership of the code they ship.

This role is about pushing our team from strong to elite: building the proactive security review muscle that lives day-to-day inside the engineering org, rather than at the cadence of an external engagement.

You’ll maintain partnership with our existing security consultants. Our partners will continue to manage structured assessments including Penetration Testing and security assessments. You will support our team and maintain our in-house practice that catches issues long before they reach one.

This role reports to the Director of DevOps and IT.

What you will be doing:
  • Run proactive security reviews of new features, architectures, and third‑party integrations before they ship
  • Assist in optimizing our application and product security practice: threat modeling, design review, secure SDLC integration
  • Ownership in our approach to AI‑related security risk, including:
    • Securing our own AI/ML systems and the data flowing through them
    • Governing internal use of AI dev tools (Claude Code and similar) so we move fast without leaking sensitive data
    • Reviewing AI‑assisted code contributions and helping us evolve our policies as the tooling matures
  • Partner with engineering teams to triage and remediate vulnerabilities from pen tests, customer findings, and internal discovery
  • Support our SOC 2 and ISO 27001 programs as a key technical contributor (compliance ownership lives elsewhere, but you'll be the engineering voice in the room)
  • Help mature our incident response practice and run security tabletop exercises
  • Build internal tooling and automation that scales security review without bottlenecking shipping
  • Work with our consultant on scoping pen tests, vendor assessments, and customer security reviews
What we are looking for:
  • 5+ years in security engineering, application security/product security and infrastructure security (DevSecOps, etc)
  • Hands‑on experience doing proactive security review (threat modeling, design review, secure code review) on production systems
  • Strong fundamentals in web application security, cloud security (we run primarily on AWS and GCP), and modern auth patterns
  • Comfortable reading and reviewing code across at least one of our stacks (Python, Java/Kotlin, TypeScript)
  • A real point of view on how AI changes the security landscape, both as a new risk surface and as new tooling for defenders
  • Track record of working effectively in a startup or fast‑moving environment where you have to prioritize ruthlessly and make tradeoffs
  • Ability to influence engineers without owning their roadmap
Nice to have:
  • Experience as the first or early security hire at a growth‑stage company
  • Hands‑on contributor experience with SOC 2 and/or ISO 27001
  • Background in security automation, internal tooling, or open‑source security work
  • Familiarity with construction tech, geospatial systems, or computer vision
Our US Benefits include:
  • 100% employer‑paid medical, dental, and vision coverage
  • Flexible paid time off
  • 401(k) with company match
  • Paid parental leave
  • Home office stipend
  • Employee referral program
  • Annual company retreats and team gatherings

Base Salary: $180,000-$230,000

The "Base Salary: range represents the low and high end of the anticipated salary range for this position across all US locations including but not limited to CA, CO, NY, WA, NV, MD, CT and RI. The determination of this anticipated Base Salary involves the consideration of many factors in making compensation decisions including but not limited to: location of candidate, unique skill sets, experience, training, performance, licensure and certifications, as well as other business and organizational needs.

Please note: We are unable to provide visa sponsorship or employment‑based immigration support for this position. Applicants must be authorized to work in the country of employment without current or future sponsorship

OpenSpace welcomes employees from varied backgrounds and walks of life, and it's reflected in our diverse community. OpenSpace is proud to be an equal opportunity employer and is committed to providing equal employment opportunities to all employees and applicants for employment, without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Engineer
Sr. Security Engineer

openspace • United States

On-site
USD 180,000 - 230,000
100% employer-paid medical, dental, &
Flexible paid time off
401(k) with company match
+4
Staff+ Security Engineer, Developer Tools
Staff+ Security Engineer, Developer Tools

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare coverage
Mental health support
Parental leave
+3
Staff+ Software Engineer, Security Infrastructure
Staff+ Software Engineer, Security Infrastructure

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare programs
Vision, dental coverage
HSA/FSA contributions
+8
Staff+ Security Engineer, Core Command
Staff+ Security Engineer, Core Command

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare programs
Medical/Vision/Dental coverage
HSA with employer contributions
+7
Security Engineer, Application Security
Security Engineer, Application Security

OpenAI • San Francisco (CA)

On-site
USD 325,000 - 405,000
Senior Corporate Security Engineer
Senior Corporate Security Engineer

United States Digital Space LLC • Bellevue (CA)

Hybrid
USD 166,000 - 195,000
Health insurance
Equity ownership
401(k) matching
+2
Enterprise Security Engineer – OpenAI
Enterprise Security Engineer – OpenAI

ISC2 East Bay Chapter • San Francisco (CA)

On-site
USD 260,000 - 325,000
Security Engineer, Application Security
Security Engineer, Application Security

OpenAI • Los Angeles (CA)

Hybrid
USD 325,000 - 405,000
Software Engineering Manager, Data Protection Platform
Software Engineering Manager, Data Protection Platform

United States Digital Space LLC • San Mateo (CA)

On-site
USD 250,000 - 350,000
Healthcare programs
Vision and dental coverage
HSA with employer contributions
+3
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Spinwheel Solutions Inc. • Oakland (CA)

On-site
USD 140,000 - 190,000
Remote-First
Salary & Equity
Unlimited PTO
+2