First Dedicated Security Engineer
Core
Own vulnerability management across product, codebases, and cloud infrastructure; build AppSec tooling pipelines; enforce secure coding standards including AI-generated code; harden SaaS environments; develop security detections.
Role type
Senior IC security engineer (AppSec & Cloud)
Builds
AppSec tooling pipeline (secrets scanning, SCA, SAST, CI/CD integration), high-signal security detections, secure SaaS configurations
Domain
SaaS, Cloud Security, Application Security, AI-assisted development security
Required skills
vulnerability management, secrets scanning, SCA/dependency scanning, SAST, CI/CD security integration, OAuth and third-party application review, cloud security (AWS/GCP), Cloudflare edge/CDN security, AI-assisted development security guardrails, secure coding standards, incident response readiness
Preferred skills
security program building at early/mid-stage companies, SaaS security posture management, CSPM, identity threat detection, LLM or agentic workflow security, SIEM/MDR detection engineering, fintech, offensive security
Technologies
AWS, GCP, Cloudflare, GitHub, Google Workspace, Rippling, Slack
Responsibilities
Identify, prioritize, and remediate vulnerabilities across infrastructure; build and operate AppSec tooling pipelines; define and enforce secure coding and code review standards; partner with AI team to establish development guardrails; harden SaaS environment configurations; develop high-signal detections and contribute to incident response readiness
Seniority
Senior, hands-on IC