S

Senior/Staff Security Engineer

Visa Sponsorship
Apply
AI Summary

Own the security posture of Init and its product end-to-end, leading secure design reviews and threat modeling for a governed-identity agent. Build security primitives into the product and own incident readiness with breach-notification commitment measured in hours.

Key Highlights
End-to-end security posture ownership
Secure design reviews and threat modeling
Incident readiness and response
Key Responsibilities
Own the end-to-end security posture: application, cloud, network, and the agent itself
Secure design reviews and threat modeling for a governed-identity agent with scoped, approval-gated access
In-product security primitives: per-customer isolation, credentials the agent never sees, write-action approval gates, a customer-controlled capability dial, and replayable audit trails
Technical Skills Required
Python Go Rust
Benefits & Perks
Meals in office
Health insurance
Unlimited PTO
Nice to Have
Experience securing agentic or code-execution systems
Deep expertise in modern isolation: container security, kernel-level hardening, microVMs
Offensive security or penetration testing experience

Job Description


My Client in San Francisco, US is looking for:


Senior/Staff Security Engineer (4+ year’s experience minimum)


Key Job Info Location San Francisco, CA Work Type In-person (On Site Role)


Employment Full-Time Experience 4+ Years Salary Range $200000 - $300000 / per year


Visa Sponsorship :H-1B transfer only. US Citizens and Greencard Holders.


About the Role

You will own the security posture of Init and its product end-to-end: application, cloud, network, and the agent itself. This is a system with limited prior art, so the work is genuinely novel: leading secure design reviews and threat modeling for an agent that holds a governed identity, requests scoped access, and acts under human approval.

You'll build security primitives into the product rather than around it: full per-customer isolation, credentials the agent uses but never sees, approval gates on write actions, a customer-set dial on what the agent may see and do, and an audit trail complete enough to replay any run. You'll own the written architecture account that technical buyers read before deploying (which, for a technical buyer, decides the deal more than any certificate), run the external validation path (pen tests, compliance frameworks, enterprise security reviews), own incident readiness with a breach-notification commitment measured in hours, and push scanning, secret detection, and compliance checks into CI. You'll also set the internal security bar for how the company handles customer credentials.


What You'll Own

The end-to-end security posture: application, cloud, network, and the agent itself Secure design reviews and threat modeling for a governed-identity agent with scoped, approval-gated access. In-product security primitives: per-customer isolation, credentials the agent never sees, write-action approval gates, a customer-controlled capability dial, and replayable audit trails

The written security architecture account that gates enterprise deployments and closes technical buyersExternal validation: pen testing by a respected firm, required compliance frameworks, and enterprise security reviews Incident readiness and response, with breach notification measured in hours Continuous cloud/IAM auditing and security-as-a-pipeline-step in CI

The internal bar for credential handling, data egress, and endpoint policy


Requirements:


Must-Have

  • Hands-on application and infrastructure security experience
  • Production-quality code in Python, Go, Rust, or TypeScript
  • Practical threat-modeling and vulnerability-identification skills
  • Hands-on network and identity security: identity-based controls, policy enforcement, workload IAM4.
  • Cloud security depth on at least one major provider, including identity federation and infrastructure-as-code5.
  • Able to explain a risk trade-off clearly to both an engineer and a CIO in the same week.
  • Operates well with high autonomy and ambiguity.
  • Able to work in person in SF, Monday to Friday, at startup intensity


Nice-to-Have

  • Experience securing agentic or code-execution systems
  • Deep expertise in modern isolation: container security, kernel-level hardening, microVMs
  • Offensive security or penetration testing experience
  • Has run or owned a bug bounty or vulnerability disclosure program
  • Has carried a company through compliance frameworks and enterprise security reviews
  • Experience in or alongside enterprise IT and identity: directory services, SSO, PAM


Benefits & Perks

Meals in office, Health insurance, Unlimited PTO


Similar Jobs

Explore other opportunities that match your interests

Senior Device Security Researcher

Cyber Security
2d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Palo Alto Networks

United State

Lead Application Security Engineer

Cyber Security
2d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Director

Xcede

United State

Principal Software Engineer - Prisma AIRS Runtime Security

Cyber Security
2d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Palo Alto Networks

United State

Subscribe our newsletter

New Things Will Always Update Regularly