All open roles

Lead Application Security Engineer

Engineering · Posted 4 months ago

This is our first dedicated security hire, and it's a rare chance to define the function from the ground up. You'll own Hightouch's application security posture end-to-end. We have strong engineering fundamentals and a solid foundation; now you'll shape what security looks like here as we scale from 70 to 140+ engineer...

Way of working
Remote
Location
Remote
Pay range
$220,000 to $320,000
Level
Staff
Experience
6+ years
Type
Full time
Visa sponsorship
Not offered for this role
The company
B2B SaaS · 200 to 1000 people

Skills that matter here

TypeScriptGoCloud: Multi-cloud across AWS, Azure, and GCP

The full description

About the Role

This is our first dedicated security hire, and it's a rare chance to define the function from the ground up. You'll own Hightouch's application security posture end-to-end. We have strong engineering fundamentals and a solid foundation; now you'll shape what security looks like here as we scale from 70 to 140+ engineers.

This is a hands-on, high-autonomy role. You'll spend most of your time in the codebase, not in meetings. You’ll be solving hard problems at the intersection of security and distributed systems:

- Multi-tenant isolation on a system running ~1M data syncs per day and ingesting 100K+ events/sec

- Sub-tenant access control - for multi-team and multi-brand use cases, requiring differentiated access to configuration and data

- Security architecture - Build and refine our frameworks for compute isolation and perform threat modeling and hardening of new products

- Internet-facing APIs - Our high-throughput, internet-facing architecture services customer data at scale. You’ll improve our rate limiting, abuse detection, and granularity of access control

- Multi-Region and Multi-Cloud - Supporting our multi-region and multi-cloud backend, including extending it to launch Hightouch on in new regions to support data residency requirements of our global customer base

You'll own your roadmap. We're not looking for someone to run a checklist — we're looking for someone who can look at our architecture, identify the highest-leverage problems, and go fix them.

About You

You’ve been an early security hire at a SaaS company before and moved the needle on how they approach security. You can read application code, threat model a distributed system, and ship production fixes. You have significant distributed systems expertise so that you can understand and influence what is being built by the product teams and influence from a place of trust.

Experience that's relevant:

- Being an early security hire (first 1-3) at a SaaS or data infrastructure company

- Securing multi-tenant platforms: tenant isolation, authorization models, etc

- Cloud security on systems that span more than one cloud and operate against customer-owned accounts

- Design and build of data infrastructure as an early engineer, not just a user. You helped secure it from early design or during major redesigns. You understand how it scales and how it’s secured

- Privacy-adjacent security (PII handling, data residency, GDPR/CCPA technical controls)

We don't care about certifications. We care about what you've built.

How hiring runs

  1. 1Recruiter Screen
  2. 2Hiring Manager Screen (60 min)
  3. 3Security Architecture + Core Interview
  4. 4Hiring Manager Interview
  5. 5Security Program Interview with Head of Engineering

Interested in this one?

There is no apply button here on purpose. Tell us about yourself, we book a short call, and if this role fits we walk you through the company and ask before anything is sent. Always free for you.

Tell us about you
Tell us about you