All open roles

Member of Technical Staff, Security Engineer

Engineering · Posted 2 months ago

We need an experienced security engineer with broad expertise across AWS infrastructure security, application security, and identity/access management who has owned security end-to-end as the first or sole security hire at a fast-moving startup. You should be comfortable operating with high autonomy in a small team, bu...

Way of working
On site
Location
New York, NY
Pay range
$150,000 to $250,000
Level
Staff
Experience
5+ years
Type
Full time
Visa sponsorship
Not offered for this role
The company
Higher Education · under 20 people

Skills that matter here

AWSVPCVPNIAMSSORBACKubernetes

What you would be doing

  • Own infrastructure security across the entire AWS environment — VPC/VPN peering, network segmentation, IAM, secrets management — designing guardrails that make the secure default also the fastest one
  • Take ownership of application security across web and desktop clients, embedding threat modeling, dependency/supply-chain controls, and secure code review into how the team designs and ships
  • Build and manage identity and access controls (SSO, RBAC, least-privilege) for both humans and AI agents, ensuring every actor reaches exactly what it needs and nothing more
  • Design audit trails and access controls that make autonomous agent activity fully reconstructable — what it did, on whose behalf, with what data, and why
  • Own IT security in partnership with the IT MSP — devices, endpoints, and access for a 12-person in-office team
  • Stand up and run compliance, auditability, bug bounty, VDP, and pentest programs that prove security posture to clients, partners, and auditors as a byproduct of how the system is built

The full description

What we're looking for

We need an experienced security engineer with broad expertise across AWS infrastructure security, application security, and identity/access management who has owned security end-to-end as the first or sole security hire at a fast-moving startup. You should be comfortable operating with high autonomy in a small team, building security programs from scratch, and have a track record of making the secure path the easy path rather than gatekeeping. Bonus points if you have experience securing AI/agent systems or working in financial services.

What you'll do:

- Own infrastructure security across the entire AWS environment — VPC/VPN peering, network segmentation, IAM, secrets management — designing guardrails that make the secure default also the fastest one

- Take ownership of application security across web and desktop clients, embedding threat modeling, dependency/supply-chain controls, and secure code review into how the team designs and ships

- Build and manage identity and access controls (SSO, RBAC, least-privilege) for both humans and AI agents, ensuring every actor reaches exactly what it needs and nothing more

- Design audit trails and access controls that make autonomous agent activity fully reconstructable — what it did, on whose behalf, with what data, and why

- Own IT security in partnership with the IT MSP — devices, endpoints, and access for a 12-person in-office team

- Stand up and run compliance, auditability, bug bounty, VDP, and pentest programs that prove security posture to clients, partners, and auditors as a byproduct of how the system is built

Interested in this one?

There is no apply button here on purpose. Tell us about yourself, we book a short call, and if this role fits we walk you through the company and ask before anything is sent. Always free for you.

Tell us about you
Tell us about you