All open roles

Security Engineer

Engineering · Posted 2 months ago

We need someone with 3+ years of hands-on information security experience who has strong fundamentals in application and/or cloud security (AWS/GCP). You should be comfortable operating with high autonomy in a fast-moving startup environment and have a track record of building and improving security programs from the g...

Way of working
Hybrid
Location
San Francisco, CA
Pay range
$200,000 to $315,000
Level
Mid
Experience
3 to 8 years
Type
Full time
Visa sponsorship
Not offered for this role
The company
Software Development · 200 to 1000 people

Skills that matter here

AWSGCPSOC 2ISO 27001AI/LLM SecurityCloud SecurityApplication SecuritySDLCThreat ModelingDetection & Response

What you would be doing

  • Own security reviews and threat modeling for new and existing product surfaces across Nooks' AI-native platform
  • Build and improve core security processes including secure SDLC, detection & response
  • Harden cloud and application infrastructure and drive remediation of high-priority risks
  • Help define how we secure AI agents and govern their use — including guardrails, data exposure, prompt-injection, and abuse risks
  • Support enterprise customer trust through compliance (SOC 2) and customer-facing security needs
  • Partner closely with product and infra engineering to embed security into how we ship

The full description

What we're looking for:

We need someone with 3+ years of hands-on information security experience who has strong fundamentals in application and/or cloud security (AWS/GCP). You should be comfortable operating with high autonomy in a fast-moving startup environment and have a track record of building and improving security programs from the ground up. Bonus points if you have experience securing AI agents/LLM systems or enterprise compliance experience (SOC 2, ISO 27001).

What you'll do:

- Own security reviews and threat modeling for new and existing product surfaces across Nooks' AI-native platform

- Build and improve core security processes including secure SDLC, detection & response

- Harden cloud and application infrastructure and drive remediation of high-priority risks

- Help define how we secure AI agents and govern their use — including guardrails, data exposure, prompt-injection, and abuse risks

- Support enterprise customer trust through compliance (SOC 2) and customer-facing security needs

- Partner closely with product and infra engineering to embed security into how we ship

Interested in this one?

There is no apply button here on purpose. Tell us about yourself, we book a short call, and if this role fits we walk you through the company and ask before anything is sent. Always free for you.

Tell us about you
Tell us about you