/roles — ROLE_346

Lead Application Security Engineer

Fast-scaling data platform moving customer data at high volume for large enterprises across several clouds

The role

COMP
$220K - $320K
EQUITY
Competitive Equity
LOCATION
Canada · San Francisco · New York · Texas
WORKPLACE
Remote
EXPERIENCE
6+ years
VISA
None, Visa transfers
STACK
TypeScript, Go, AWS, Azure, GCP, Snowflake
INDUSTRY
B2B, Data, Marketing, AI, Enterprise

The company

A late-stage data and AI company whose platform lets businesses activate customer data from their own warehouse for marketing, advertising, and personalization, increasingly through AI agents.

STAGE
scale-up
FUNDING
$320M+ raised
TEAM
350+ people
FOUNDED
2018
BACKING
backed by Y Combinator, Goldman Sachs

JD — the work

About the role

The company has never had a dedicated security engineer, so you would be the first, with room to build the application security function from scratch and own it end to end. Engineering fundamentals are already strong, and you would shape the security program as the engineering org roughly doubles in size. The role is hands-on and highly autonomous: most of your time goes into the codebase, finding the highest-leverage problems in the architecture and fixing them rather than working through a checklist. What you have built matters far more than certifications.

What you'll do

  • Strengthen tenant isolation on a platform handling a very large daily volume of data syncs and events
  • Design finer-grained access control within a tenant for customers running many teams or brands
  • Create frameworks for isolating compute, and threat model and harden new products
  • Improve abuse detection, rate limiting, and more granular access control on high-throughput public APIs
  • Secure the multi-region, multi-cloud backend as it expands into new regions for data residency
  • Set and own your own security roadmap

What they're looking for

  • 6+ years, including a stint among the first 1 to 3 security hires at a software or data platform company
  • Comfort reviewing application code, threat modeling distributed systems, and shipping fixes to production
  • Experience securing multi-tenant platforms, including tenant isolation and authorization models
  • Cloud security across more than one provider, including systems that operate inside customer-owned accounts
  • Significant distributed systems depth, ideally gained by designing and building data systems early in a company's life

Nice to have

  • Privacy-focused security work such as data residency, handling of personal data, and GDPR or CCPA technical controls
APPLY FOR THIS ROLE →All open rolesOne application covers up to 3 roles.