/roles — ROLE_346
Lead Application Security Engineer
Fast-scaling data platform moving customer data at high volume for large enterprises across several clouds
The role
- COMP
- $220K - $320K
- EQUITY
- Competitive Equity
- LOCATION
- Canada · San Francisco · New York · Texas
- WORKPLACE
- Remote
- EXPERIENCE
- 6+ years
- VISA
- None, Visa transfers
- STACK
- TypeScript, Go, AWS, Azure, GCP, Snowflake
- INDUSTRY
- B2B, Data, Marketing, AI, Enterprise
The company
A late-stage data and AI company whose platform lets businesses activate customer data from their own warehouse for marketing, advertising, and personalization, increasingly through AI agents.
- STAGE
- scale-up
- FUNDING
- $320M+ raised
- TEAM
- 350+ people
- FOUNDED
- 2018
- BACKING
- backed by Y Combinator, Goldman Sachs
JD — the work
About the role
The company has never had a dedicated security engineer, so you would be the first, with room to build the application security function from scratch and own it end to end. Engineering fundamentals are already strong, and you would shape the security program as the engineering org roughly doubles in size. The role is hands-on and highly autonomous: most of your time goes into the codebase, finding the highest-leverage problems in the architecture and fixing them rather than working through a checklist. What you have built matters far more than certifications.
What you'll do
- Strengthen tenant isolation on a platform handling a very large daily volume of data syncs and events
- Design finer-grained access control within a tenant for customers running many teams or brands
- Create frameworks for isolating compute, and threat model and harden new products
- Improve abuse detection, rate limiting, and more granular access control on high-throughput public APIs
- Secure the multi-region, multi-cloud backend as it expands into new regions for data residency
- Set and own your own security roadmap
What they're looking for
- 6+ years, including a stint among the first 1 to 3 security hires at a software or data platform company
- Comfort reviewing application code, threat modeling distributed systems, and shipping fixes to production
- Experience securing multi-tenant platforms, including tenant isolation and authorization models
- Cloud security across more than one provider, including systems that operate inside customer-owned accounts
- Significant distributed systems depth, ideally gained by designing and building data systems early in a company's life
Nice to have
- Privacy-focused security work such as data residency, handling of personal data, and GDPR or CCPA technical controls