About this opportunity
Invictus Direct lists this Security Engineer opportunity in san francisco, California. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Location
San Francisco Bay Area, CA, or Singapore (On-site)
Schedule
Full-time
Salary
$100K–$200K
Company
Our client is a Y Combinator-backed company building infrastructure to create reinforcement-learning training data and evaluations for frontier AI agents, along with a marketplace connecting this work with frontier labs. Its platform is used by frontier labs, Fortune 500 companies, and startups.
Description
Our client is seeking its first full-time Security Engineer to own and build the security program. This is a hands‑on, senior individual‑contributor role spanning product security, cloud infrastructure, internal systems, incident response, compliance, and customer trust.
The immediate mandate is to bring security up to the standard required of a rapidly scaling data company, strengthen controls as the supplier footprint grows, and take SOC 2 from in progress through completion. Proactive controls, detection, and attack‑surface management are central priorities.
Key Responsibilities
Own the security roadmap across product, cloud and infrastructure, corporate systems, incident response, and compliance
Harden AWS infrastructure and accounts, including IAM, networking, logging, Terraform, secrets management, and automated guardrails
Establish stronger monitoring, SIEM/XDR, detection engineering, alerting, and incident‑response workflows that identify and stop problems before they become incidents
Secure applications, APIs, the platform, and data workflows through threat modeling, design reviews, code reviews, vulnerability research, authentication and authorization controls, and remediation
Improve container and workload isolation for systems that execute untrusted code or process sensitive data
Own abuse, fraud, and incident response end to end, including containment, investigation, postmortems, and durable follow‑up engineering
Build continuous attack‑surface management across domains, cloud services, third‑party hosting, vendors, and externally exposed assets
Complete SOC 2 and own customer trust work, including control design, evidence, policy management, security questionnaires, vendor reviews, and audits
Translate contractual and data‑license requirements into enforceable controls for access, permitted use, retention, deletion, isolation, provenance, and auditability
Qualifications
Core Experience
5–10 years of deeply hands‑on security experience across offensive security, infrastructure or cloud security, application security, and incident response
Experience building a security program from zero at least once, ideally as an early security hire at a fast‑growing startup
Strong AWS and cloud‑engineering depth, including infrastructure as code with Terraform
Current hands‑on ability to review code, find vulnerabilities, design controls, deploy tooling, and personally lead investigations
Experience implementing or operating SOC 2 or a comparable security framework
Sound judgment and the ability to prioritize the risks that matter in a fast‑moving environment
Preferred
The following are considered strong signals:
Bug bounty work, penetration testing, vulnerability research, published CVEs, security tooling, conference talks, or substantive technical writing
OSCP or OSWE; AWS, cloud engineering, CKS, or hands‑on GIAC certifications
Systems programming, operating systems, Linux kernel work, low‑level networking, or experience building infrastructure from the ground up
Experience securing AI/ML infrastructure, agent execution environments, data platforms, or other systems that run untrusted code
This role requires current hands‑on technical depth and broad security ownership. It is not designed for candidates whose recent experience has been exclusively people leadership or limited to a narrow specialty within an already mature security organization. Offensive‑security experience alone is insufficient without demonstrated cloud engineering and program‑building ability.
Why Join Them?
Become the company's first full‑time Security Engineer and own the security program
Shape security across product, cloud infrastructure, internal systems, incident response, compliance, and customer trust
Address security challenges involving untrusted code execution, sensitive data, and a growing supplier footprint
Relocation and visa support are available for strong candidates
#J-18808-Ljbffr
Worksite address
san francisco, CA, 94199, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.