Source Job

US

  • Own the security program end-to-end, including identity, IT, compliance, and application security.
  • Drive SOC 2 Type II readiness and map FERPA, COPPA, and state privacy controls.
  • Establish zero-trust access, automated provisioning, and human-centered security processes.

Security Engineering SSO/SAML SOC 2 Application Security Zero Trust

20 jobs similar to Founding Security Engineer

Jobs ranked by similarity.

US

  • Lead security and IT for Cardlytics, overseeing security engineering, IT operations, and compliance for a fully remote team.
  • Manage SOX/SOC 2 compliance, identity and access management, and cloud security across AWS environment.
  • Drive AI adoption company-wide while partnering with executives and the board to align security priorities with business strategy.

Cardlytics is a purchase intelligence and incentives platform that helps businesses attract and incentivize consumers through digital reward programs. As a public company (NASDAQ: CDLX) with a lean, high-trust team, they prioritize integrity and growth.

Global

  • Own production security across a multi-cloud footprint (AWS, GCP, Azure, Vercel) and secure multi-tenant SaaS, dedicated VPC, and air-gapped deployments.
  • Secure the Hermes Agent platform with sandboxing, kernel-level isolation, and agent identity controls, and lead SOC 2 compliance.
  • Harden identity management, vulnerability management, incident response, and secure software development lifecycle practices.

Nous Research builds open-source AI language models and agents, including Hermes Agent, used by consumers and Fortune 500 enterprises across various deployment environments. The company is a fast-growing startup with a high-velocity, open-source-native engineering culture that values security and pragmatism.

Canada Unlimited PTO

  • Own the security compliance program end-to-end, including audits, customer trust, vendor risk, and vulnerability management.
  • Automate evidence collection and control monitoring to be audit-ready year-round, not just during the August–November season.
  • Act as the external security face for enterprise prospects and translate AI regulatory changes into requirements.

Ada is an AI customer service company that helps enterprises automate customer conversations with AI agents. Founded in 2016, we've powered over 5.5 billion interactions and raised over $250M from top investors.

$180,000–$260,000/yr
US Unlimited PTO

  • Own the security boundary of Percy, including vault enclave and sandbox isolation for AI agents processing live PII.
  • Assess and harden encryption, key management, access control, and the append-only audit ledger across AWS Nitro Enclaves.
  • Drive product-security controls for SOC 2, PCI DSS, and GDPR audits, and run technical pentests.

Footprint builds Percy, an AI agent that automates financial crime investigations for banks and fintechs. Backed by QED, Index, and Box Group, the company is small, senior, and ships fast, having 5x'd revenue last year.

US

  • Lead Enterprise Security Engineering and SecOps, directing a high-performing team while owning operational defense.
  • Architect Zero Trust Architecture transition, implementing micro-segmentation and identity-based controls.
  • Oversee 24/7 MDR/SOC partnerships, incident response, and risk-based vulnerability management.

Virta Health is on a mission to reverse metabolic disease in one billion people through innovations in technology, personalized nutrition, and virtual care delivery. They have raised over $350 million and partner with large health plans, employers, and government organizations, with a values-driven culture emphasizing ownership, transparency, and evidence-based decision-making.

$151,200–$189,000/yr
5w PTO

  • Build and lead Attio's Product Security function, securing their AI-native SaaS platform and sensitive customer data.
  • Work with Engineering Leadership to ensure security by design, mitigating unique risks from AI-driven features and AI-assisted development.
  • Lead production security incident response, recruiting and retaining a world-class team of Security Engineers and SecOps practitioners.

Attio is the CRM for agentic revenue, designed for ambitious go-to-market teams to understand every customer and automate at scale. They have raised $116M from top investors and hire builders who thrive on complex technical challenges, holding themselves to a high bar and delighting users.

$110,000–$160,000/yr
North America

  • Own identity and access management across Later’s platform, including authentication, authorization, and secure machine-to-machine processes.
  • Design, implement, and maintain secure authentication systems for both internal tools and customer-facing experiences.
  • Partner with engineering teams to identify vulnerabilities, clearly communicate risk and impact, and drive effective remediation.

Later is the world’s most intelligent influencer marketing company, built to give brands the confidence to create unforgettable campaigns. Trusted by leading enterprise brands including Nike, Wayfair, Unilever, and Southwest Airlines, Later is a mid-to-large company with a culture of inclusion and innovation.

US

  • Lead vulnerability management and SOC 2 compliance across SaaS products and cloud infrastructure.
  • Harden Azure and Microsoft security tooling (Defender, Intune) and respond to security alerts.
  • Partner with engineering, IT, and legal to drive secure SDLC, policies, and customer security reviews.

HSP Group is a premier provider of global expansion services, helping companies with legal setup, HR, payroll, compliance, and tax across international markets. The company partners with scale-ups and innovative technology firms to reduce risk and scale faster, fostering a trusted-partner culture.

$250,000–$330,000/yr
Americas

  • Own Tremendous' security posture end-to-end, partnering with our engineering team on production infrastructure and code security.
  • Assess where we have gaps, prioritize them, and tackle our highest-leverage gaps first.
  • Treat incident response as core, not afterthought.

Tremendous is a global platform for businesses to send payouts like gift cards and money to anyone, anywhere, instantly. Trusted by 20,000+ organizations, they are profitable and fully remote with a high-documentation, low-meeting culture and an employee NPS in the high 80s.

Canada

  • Lead a team of Security Engineers, providing decision-making support and enabling them to deliver security consulting to the wider business.
  • Work directly with Product & Technology teams to assist in how our platform is built and how applications behave, supporting everything from user security to internet connectivity.
  • Have significant impact on security of systems used by thousands of firefighters, paramedics, and hospitals worldwide.

ESO is a data, technology, and research company passionate about improving community health and safety through the power of data. We serve thousands of customers out of our offices across the US, Canada and Northern Ireland, and we are small enough to be nimble and fun but big enough to be a great place to work.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

India

  • Design, implement, and secure hybrid cloud environments across Microsoft Azure, AWS, and Microsoft 365.
  • Lead SOC 2 Type II audit support, cybersecurity operations, and incident response.
  • Develop automation and security monitoring using Sentinel, Defender, and PowerShell.

XO Health is the first health plan designed by and for self-insured employers, delivering a unified health experience for all stakeholders. The company is growing a multi-disciplinary team of diverse and digitally empowered employees focused on rebuilding trust in healthcare.

US

  • Lead the technical architecture and engineering strategy for cybersecurity assessment offerings and an agentic AI platform across multiple markets.
  • Establish and scale the Cyber Engineering function, including operating models, team charters, and delivery frameworks.
  • Partner with sales, consulting, and OEM alliances to align technical execution with strategic growth objectives.

Emergent is an award-winning IT solutions provider and value-added reseller specializing in cybersecurity and complex technology challenges. The company has a collaborative culture centered on respect, empathy, excellence, and fun, with a focus on employee well-being.

Global

  • Act as the primary security partner for the Walrus team, providing architectural guidance and embedding security practices throughout the development lifecycle.
  • Lead security assessments for new features and contribute to ecosystem-wide security initiatives, identifying systemic risks and actionable remediation plans.
  • Drive a security-by-design culture, leveraging AI and automation to focus on high-impact, complex security research and mentor engineers.

Mysten Labs builds foundational infrastructure to accelerate the adoption of decentralized protocols based on blockchain technologies. They are a well-funded, remote-first team with over $300M in Series B funding from top venture firms, fostering a culture of innovation and growth.

US

  • Design, implement, and maintain enterprise security infrastructure including firewalls, IDS/IPS, and SIEM solutions.
  • Lead cybersecurity strategy, incident response, and risk management aligning with business objectives.
  • Conduct vulnerability assessments, enforce security policies, and mentor colleagues to foster a culture of security awareness.

McNees Wallace & Nurick is a trusted, client-focused law firm delivering practical, results-driven legal solutions with integrity. With more than 170 attorneys and 350 professionals, the firm fosters a culture of authentic relationships, excellence, and balance.

$170,000–$230,000/yr
US

  • Build secure-by-default infrastructure and automation to eliminate entire vulnerability classes across money-moving systems.
  • Own application security, threat modeling, and vulnerability disclosure from design review to production.
  • Partner with engineering to set security standards, make risk-based decisions, and ship fast without compromising safety.

Flex is building the AI-native private bank for business owners, re-architecting the entire financial system for entrepreneurs. Since launching in 2023, Flex has scaled to nine-figure annualized revenue, raised $100M+ in equity and $300M+ in debt, and operates with a high-bar, low-ego culture focused on speed and execution.

$170,000–$190,000/yr
US Unlimited PTO

  • Take ownership of the information security program, lead the IT team, and collaborate with engineering on deep technical work.
  • Own SOC 2, Vanta, governance, IT/TechOps, vendor diligence, SIEM, vulnerability management, and cloud security.
  • Partner with the CTO and AI Labs to build security capabilities and automate with AI tooling.

We are a Forbes Fintech 50, SHRM-backed company tackling employer talent retention and the student debt crisis. We are a Series B startup with a strong technical team, enterprise customers, and a high security bar.

$153,000–$214,000/yr
US Canada

  • Lead end-to-end response to product security incidents, from discovery to disclosure.
  • Own and evolve 1Password's PSIRT function, including severity frameworks and playbooks.
  • Drive coordinated vulnerability disclosure and partner with external security researchers.

1Password is a cybersecurity company providing enterprise password management and Unified Access Management, trusted by over 180,000 businesses. With $400M ARR and a remote-first culture, it values collaboration, transparency, and innovation.

United States

  • Partner with Engineering to design, implement, and improve security controls across software, application architecture, and AWS infrastructure.
  • Strengthen security monitoring, detection, incident response, and integrate security into CI/CD pipelines.
  • Support compliance efforts including SOC 2 and ISO audits, and lead customer security reviews.

AlertMedia helps organizations protect their people, operations, and brand with a modern Risk Intelligence and Response platform. It is a high-growth, PE-backed SaaS company with more than 4,000 clients and a 10-year award-winning culture.

US Unlimited PTO

  • Own the security program day-to-day, pursuing ISO 27001 certification and FedRAMP readiness.
  • Manage GRC tool (Vanta), maintain SOC 2 Type II, and run vendor security reviews.
  • Answer customer security questionnaires and ensure compliance documents are accurate.

Massed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. We are a lean, ambitious team operating in one of the most important technology markets in the world.