Senior/Staff Security Engineer
Job Description:
Confidential client — a Pre-seed startup (1-10 employees) building AI coworkers for IT teams: a security-focused IT product where an agent registers as a governed identity in a customer's directory, requests scoped access per task, escalates for human approval, and can drive screens it was never given an API for. Raised a $6M seed with no product and no customers at the time, backed by a strong bench of operator-angels from across the IT and security world. Several design partners today and a founding team of three. Full-Time, In-person, San Francisco, CA. Experience: 4+ years. Salary: $200,000-$300,000/yr. Visa sponsorship: H-1B, O-1, OPT.
About the Role: You will own the security posture of the company and its product end-to-end: application, cloud, network, and the agent itself. This is a system with limited prior art, so the work is genuinely novel: leading secure design reviews and threat modeling for an agent that holds a governed identity, requests scoped access, and acts under human approval. You'll build security primitives into the product rather than around it: full per-customer isolation, credentials the agent uses but never sees, approval gates on write actions, a customer-set dial on what the agent may see and do, and an audit trail complete enough to replay any run. You'll own the written architecture account that technical buyers read before deploying, run the external validation path (pen tests, compliance frameworks, enterprise security reviews), own incident readiness with a breach-notification commitment measured in hours, and push scanning, secret detection, and compliance checks into CI. You'll also set the internal security bar for how the company handles customer credentials.
What You'll Own:
- The end-to-end security posture: application, cloud, network, and the agent itself
- Secure design reviews and threat modeling for a governed-identity agent with scoped, approval-gated access
- In-product security primitives: per-customer isolation, credentials the agent never sees, write-action approval gates, a customer-controlled capability dial, and replayable audit trails
- The written security architecture account that gates enterprise deployments and closes technical buyers
- External validation: pen testing by a respected firm, required compliance frameworks, and enterprise security reviews
- Incident readiness and response, with breach notification measured in hours
Company stage: Pre-seed. Work type: In-person (San Francisco, CA).