Senior/Founding Security Engineer

Code Red Partners • United State
Relocation
Apply
AI Summary

Code Red Partners is seeking a Senior/Founding Security Engineer to own the full security posture of a fast-growing AI automation startup. The ideal candidate will have deep application security chops, infra & cloud security fundamentals, and a strong ownership instinct. This is a unique opportunity to shape the security direction of a category-defining product.

Key Highlights
First and only security hire
Own full security posture
Deep application security chops
Infra & cloud security fundamentals
Key Responsibilities
Own code review, cloud infrastructure hardening, and incident response end-to-end
Hunt for broken auth, missing RBAC, and OWASP risks across PRs and the broader codebase
Map the full attack surface and build a living risk model across the product and integrations
Technical Skills Required
Secure SDLC Code review OWASP Top 10 Multi-tenant SaaS Infra & Cloud security fundamentals CSPM tooling GCP Containerized, microservices environments Kubernetes Docker
Benefits & Perks
Competitive Bay Area salary
Meaningful equity
Full health, dental, and vision coverage
Paid relocation
One month of temporary housing
Direct CTO reporting line
Nice to Have
Background transitioning from SWE into product or application security

Job Description


Code Red is partnered with a well-backed & fast-growing AI automation startup that's looking to bring on a Senior / Founding Security Engineer.


About the Team: Started as a side project built by two ex-Big Tech engineers and have grown into a category-defining product in under two years, with major enterprise customers and significant institutional backing (Series B). The team is small by design- everyone has real ownership & is part of shaping direction.


About the Role

You'll be the first (and for a while, the only) security hire. That means you'll own the full security posture: application security, cloud infrastructure, AI/LLM-specific risks, and incident response. You'll report directly to the CTO and be supported by an experienced vCISO who will act as a strategic mentor and force multiplier.


What we're looking for:

First and foremost: a builder. You reach for code before process docs, and you automate what others would staff. Beyond that:

  • Deep application security chops: secure SDLC, code review, OWASP Top 10, multi-tenant SaaS
  • Infra & Cloud security fundamentals and CSPM tooling (GCP preferred)
  • Deep breadth across core cybersecurity pillars- looking for a true generalist
  • Comfortable in containerized, microservices environments (Kubernetes, Docker)
  • Strong ownership instinct: you move from strategy to execution without hand-holding
  • Ideal/Bonus: background transitioning from SWE into product or application security


What you'll do:

  • Own code review, cloud infrastructure hardening, and incident response end-to-end
  • Hunt for broken auth, missing RBAC, and OWASP risks across PRs and the broader codebase
  • Map the full attack surface and build a living risk model across the product and integrations
  • Automate security into CI/CD pipelines using AI-driven tooling
  • Secure AI-generated code and build defenses against LLM-specific attack vectors
  • Run the vulnerability management lifecycle with clear SLAs from intake to remediation
  • Evaluate and operate CSPM tooling; own finding and fixing high/critical issues


What we offer:

  • Competitive Bay Area salary + meaningful equity (benchmarked against 2025 SF Series A norms)
  • Full health, dental, and vision coverage
  • Paid relocation + one month of temporary housing
  • Direct CTO reporting line and real influence on product direction
  • Mentorship from an experienced vCISO


Interview Process:

  • Recruiter screen (30 min - virtual)
  • CTO intro call (30 min - virtual)
  • Technical Assessment (45 min - virtual with a peer engineer)
  • Onsite (3 hours in-person)

Similar Jobs

Explore other opportunities that match your interests

Staff Cybersecurity Systems Engineer

Cyber Security
•
1h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Northrop Grumman

United State

Staff Cybersecurity Systems Engineer

Cyber Security
•
1h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Northrop Grumman

United State

Full Stack Security Software Engineer

Cyber Security
•
19h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Anduril Industries

United State

Subscribe our newsletter

New Things Will Always Update Regularly