Security Lead
Sunsets HQ Corp.
About Replay At its core, Replay was founded to help founders. We started by supporting startups through shutting down, but we have since expanded into unlocking a new revenue stream for all types of businesses. In 2025, we had a unique insight: the data every company generates each day through collaboration, communication, and building is some of the most valuable training data in the world. Public and synthetic data can only get frontier models so far, so the next generation of model progress depends on real, proprietary data grounded in how actual businesses operate. We are a primary source of it, partnering directly with the frontier AI labs building what comes next.
Why Join Replay Now
Problems You Might Own
Keep sensitive data inside explicit boundaries Trace how customer data, credentials, derived artifacts, and delivery outputs move through SaaS applications, workers, data pipelines, review tools, logs, storage, and third parties. Build controls that make tenant isolation, access, retention, deletion, quarantine, and delivery decisions enforceable and auditable rather than dependent on convention.
Give people and AI systems only the authority they need Design identity, authorization, and credential systems for employees, contractors, customers, services, and AI-assisted workflows. You might build just-in-time access, scoped tool contracts, approval boundaries, safe execution environments, or protections against prompt injection, confused-deputy behavior, and data exfiltration.
Secure how the company and its people operate Design security into employee onboarding and offboarding, devices, accounts, contractors, vendors, support access, and sensitive human workflows. On the Dissolution side, that includes identity verification, approval boundaries, segregation of duties, document and credential handling, consequential actions, exception paths, and an audit trail that shows who did what and why.
Make the secure path the easiest path Build paved roads that catch important problems early without creating a security queue. This could include high-signal code and architecture review, secrets and sensitive-data detection, reusable authorization patterns, dependency and cloud controls, release checks, incident tooling, or automated evidence that serves both engineers and customer trust.
What You'll Do
Why Join Replay Now
- We have scaled from $0 to a multi-eight-figure run rate in a matter of months
- We have raised from top-tier investors, including Floodgate, Afore, Ludlow, and Hustle Fund
- We are small enough that you will carry outsized responsibility and grow as quickly as the company does
- You will partner with and build for some of the fastest and most important companies in the world
- You will help build a massive, category-defining business from the ground floor
Problems You Might Own
Keep sensitive data inside explicit boundaries Trace how customer data, credentials, derived artifacts, and delivery outputs move through SaaS applications, workers, data pipelines, review tools, logs, storage, and third parties. Build controls that make tenant isolation, access, retention, deletion, quarantine, and delivery decisions enforceable and auditable rather than dependent on convention.
Give people and AI systems only the authority they need Design identity, authorization, and credential systems for employees, contractors, customers, services, and AI-assisted workflows. You might build just-in-time access, scoped tool contracts, approval boundaries, safe execution environments, or protections against prompt injection, confused-deputy behavior, and data exfiltration.
Secure how the company and its people operate Design security into employee onboarding and offboarding, devices, accounts, contractors, vendors, support access, and sensitive human workflows. On the Dissolution side, that includes identity verification, approval boundaries, segregation of duties, document and credential handling, consequential actions, exception paths, and an audit trail that shows who did what and why.
Make the secure path the easiest path Build paved roads that catch important problems early without creating a security queue. This could include high-signal code and architecture review, secrets and sensitive-data detection, reusable authorization patterns, dependency and cloud controls, release checks, incident tooling, or automated evidence that serves both engineers and customer trust.
What You'll Do
- Establish Replay's company-wide security program, current attack surface, highest-consequence risks, and prioritized roadmap
- Threat-model product, data, AI, cloud, workforce, vendor, delivery, and human operational workflows, then stay involved through implementation and verification
- Build and improve controls for identity, authorization, tenancy, sensitive data, credentials, logging, secure execution, and customer delivery
- Define and verify workforce-security requirements for accounts, endpoints, onboarding, offboarding, contractors, vendors, training, and access reviews
- Work with Dissolution Operations to secure identity checks, approvals, segregation of duties, documents, money or asset-related actions, exceptions, and evidence of human decisions
- Find vulnerabilities through code review, architecture review, testing, production evidence, and attacker-minded investigation
- Lead the security side of incidents and exercises, including containment, recovery, learning, and durable remediation
- Create secure defaults, tooling, and review triggers that let product, machine learning, data, and platform teams move independently
- Maintain the security control framework and evidence for customer reviews and SOC 2, while keeping each control with an accountable operating owner
- Work with leadership on risk acceptance and with legal, compliance, and privacy partners on decisions outside the engineering function
- Use AI tools deeply for security analysis and engineering while treating generated findings, code, and conclusions as evidence to verify
- Replay's most consequential security risks are visible, owned, and being reduced in a deliberate order
- At least one high-risk technical or human-operational boundary is materially safer because of a control you designed, implemented with its owner, and verified
- Engineers adopt reusable security capabilities that reduce dependence on case-by-case review
- Employees, contractors, and operational teams have clear access, approval, escalation, and evidence requirements for consequential work
- Access, vulnerabilities, incidents, sensitive-data handling, vendor risk, and control evidence become easier to understand and act on
- Product and AI capabilities expand within explicit authority, isolation, monitoring, and recovery boundaries
- Customer trust evidence becomes faster to produce because it reflects real, current controls
- You have at least three years of professional security or software engineering experience, including hands-on work securing production systems
- You are a strong software engineer with security as a core specialty, and you are comfortable building controls rather than only recommending them
- You have worked in a startup and can prioritize a few consequential risks across a much larger set of possible improvements
- You have owned security outcomes across several of product engineering, infrastructure, workforce, vendors, compliance, or business operations
- You can reason deeply about application security, identity and authorization, multi-tenant systems, cloud infrastructure, sensitive data, secrets, and incident response
- You think like both a builder and an attacker and can explain the actual abuse path, affected asset, likely impact, and useful mitigation
- You create low-friction defaults and clear decision boundaries instead of making Security the approval step for routine work
- You can secure human workflows with approvals, separation of duties, training, evidence, and monitoring without pretending every risk has a software-only solution
- You can communicate risk honestly to engineers, executives, customers, and auditors without using certainty you do not have
- You use modern AI engineering tools fluently and understand their authority, data, dependency, prompt-injection, and verification risks
- You want a compliance-only role centered on collecting evidence and administering frameworks
- You prefer producing findings or policies to implementing and verifying durable controls
- You treat every possible vulnerability as equally urgent or use Security as an unconditional veto without explaining the tradeoff
- You want a narrow specialty with established teams to own every adjacent system and decision
- You do not want AI tools to be part of your daily security and engineering workflow
- Experience securing data-intensive, privacy-sensitive, or multi-tenant SaaS products
- Experience with information extraction, de-identification, data pipelines, secure delivery, or privacy-preserving systems
- Experience securing AI agents, tool-using systems, retrieval, model workflows, or MCP-style integrations
- Experience building least-privilege, just-in-time access, policy enforcement, secrets detection, data-loss prevention, or audit systems
- Experience with SOC 2, customer security reviews, vulnerability management, incident response, penetration testing, or security partners
- Experience as an early security hire who created leverage without centralizing all security work
- Experience securing operational, financial, legal, support, or other consequential human workflows
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Lead in New York, NY vacancy
- ...contracting—without committing to a formal job application. Site Lead Kings Bay, GA Are you ready to enhance your skills and build... ...services including financial, human capital, recruiting, procurement, security, and technical resources to achieve contract mission...SuggestedContract workFor contractorsWork at officeFlexible hours
- ...products that help builders move from idea to production with speed, security, and exceptional developer experience. Now, software is... ...About the role Vercel is hiring a Strategic Partnerships Lead to develop first-of-a-kind partnerships that inflect the company...SuggestedWork from homeWorldwideFlexible hours3 days per week
- ...A leading technology solutions provider in New York seeks an experienced technical professional with at least 10 years of PeopleSoft... ...installing and maintaining PeopleSoft infrastructure, and leading security product implementations. Candidates must possess strong...Suggested
$94.4k - $266.3k
...We Are: Accenture is a global professional services company with leading capabilities in digital, cloud and security. Combining unmatched experience and specialized skills across more than 40 industries, we offer Strategy and Consulting, Interactive, Technology and...SuggestedWork experience placementLive inWork at officeLocal area- ...for months, trigger 50+ emails , and pull in Finance, Legal, Security, and IT just to get something approved. We’ve raised $75M from... ...audit in the customer's APAC entity. As Omnea's AI Solutions Lead, you own deployment of the Omnea platform end to end - typically...SuggestedContract workWork at officeShift workDay shift
$25 - $50 per hour
...Role Overview TSA is accepting applications for Lead and Supervisory Transportation Security Officers at airports in San Mateo. These roles are ideal for individuals looking to step into leadership positions within airport security operations. TSA provides training...Shift workNight shiftWeekend work- United States Digital Space LLC in Ireland seeks a Security Operations Manager to shape global SOC processes and scale operations 24/7.... ...emphasizes cross‑region collaboration and training. A track record of leading diverse cybersecurity teams, experience in Windows forensics/IR...Remote jobFull time
- Harvard Protection Services is seeking a Site Account Manager to lead security personnel for a single client account in Manhattan. You will ensure delivery of professional, customer-focused security and life safety services, and supervise day-to-day operations for the account...Local area
- ...stakeholders retain control of their assets. We have a thriving community and a TVL of $8B+. We are committed to decentralization, security, and onboarding the next billion users into the digital asset space. We make it easy for people to save, earn, and spend their...Contract work
- Monarch Money is seeking a Senior Security GRC Analyst to join our Security team. You will own the day-to-day of our compliance program and customer security assurance while maturing the GRC program across the organization. You'll work cross-functionally with People, Legal...Remote job
- RemoteLeads seeks an experienced event security operations coordinator to support nationwide and international deployments. You will coordinate between operations centers, clients, zone leads, venue personnel, and public safety partners to maintain situational awareness...Contract work
- SPHERE Technology Solutions, a leader in identity hygiene, seeks a Strategic Program Manager in the United States. This role leads enterprise customer engagements from kickoff through delivery, owning scope, schedule, budget, and quality across multiple workstreams. You...
- Gazer is seeking a full-cycle B2B sales professional to own the New York market from day one. You will identify targets, open doors, run conversations, close contracts, and manage accounts as relationships grow. The role is hybrid with remote coordination and on-site partner...Remote work
- ...Engagement Manager Cybersecurity based in New York City. In this role, you will design and optimize security architectures, develop comprehensive security strategies, and lead initiatives to enhance cybersecurity resilience. The ideal candidate should have a Bachelor’s...
$200k - $300k
...intellectual curiosity—all while delivering real business impact for our multi-billion-dollar global business What you’ll do As the Linux Security Lead, you will own and drive a consistent and enforceable security posture across the firm's Linux fleet — building enforceable...Work experience placementWorldwide- Microsoft in New York, NY seeks a Threat Context Team Lead for the Business Analytics team. This on-site role leads threat-context initiatives, mentors analysts, and collaborates with security engineering and data science to translate risk insights into actionable actions...
- ...Summary Securing Travel, Protecting People - At the Transportation Security Administration, you will serve in a high-stakes environment... .... Learn more about this agency Duties Help This Lead Transportation Security Officer position is located at John F...Permanent employmentFull timePart timeTraineeshipWork experience placementWork at officeRemote workTrial periodFlexible hoursShift work
- ...A leading media and entertainment company is seeking a Close Protection Officer to provide personal security for senior executives. The role is based in major cities like Philadelphia, New York City, and Los Angeles, and requires extensive experience in law enforcement...
- Lead, Data Governance L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do... ...space, air, land, sea and cyber domains in the interest of national security. Job Location: Remote (US), or Melbourne-FL Job Schedule: 9/80...Local areaRemote work
- Doppel is seeking a Manager, Governance, Risk & Compliance to own and scale our GRC program end to end in the United States. You will lead a team of GRC analysts and set the strategy, roadmap, and operating model for certifications, risk management, and third-party risk...
- Gartner is seeking an Engagement Manager Cybersecurity to design, implement, and optimize security solutions for a rapidly evolving landscape. The ideal candidate will have over 5 years of experience in cybersecurity and strong expertise in cloud security architectures...
- Omni-Serv is seeking a part-time Security Supervisor to lead front-line security operations at JFK Airport, Terminal 4 (JFKIAT). You will supervise security personnel, enforce standards, and support post integrity during weekend and rotating shifts. This role requires 3...Contract workPart timeShift workRotating shiftWeekend work
- Mastercard is seeking a Senior Physical Security Analyst in New York City to uphold physical security standards across facilities and personnel. You will lead security officers, manage emergency planning, and ensure compliance with corporate security policies to protect...
- ...Assistant Deputy Chief of Supply Chain Analytics to set strategy and lead the build, monitoring, and analysis of supply chain metrics and... ...the procurement system within PeopleSoft with an emphasis on security and compliance. The role requires strong communication, ability...
- Apono Inc. is seeking a Senior Product Marketing Manager to define the narrative for agentic identity security as part of 1Password. The role is remote in the United States with NYC as a key context, reporting to the Head of Marketing and collaborating with product, marketing...Remote work
- Allied Universal is hiring a Security Shift Supervisor to oversee a Corporate Office in Downtown Brooklyn. This full-time position operates on an overnight shift with Thursday-Sunday flexibility, demanding excellent customer service and strong communication with clients...Full timeWork at officeShift workNight shift
- ...firms in high-trust environments—where reliability, accuracy, and security are as critical as product functionality—by automating complex... ...on ownership and outcomes. The Role We're seeking a Partnership Lead to drive and execute Clark's partnership strategy. In this high-...Work at officeNight shift
- Ll Oefentherapie is seeking a Lead Engagement Owner with over 10 years of experience in healthcare project management. This role focuses... ...ensuring successful project delivery while adhering to federal security protocols. Candidates must be US citizens willing to travel 100%...
- Thrive is seeking a Director to lead and supervise our Security Operations Center, elevating service quality and incident response. You will mentor Tier 1/2 analysts, drive threat detection, and manage resources to meet client needs. Ideal candidates bring leadership, technical...
- BibliU seeks a Procurement Lead to own end-to-end sourcing, negotiate with suppliers, and manage spend across categories. In Finance,... ...develop sourcing strategies, run RFPs, manage vendor risk with Security/Legal, and drive cost savings while improving processes in a remote...Remote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Lead. Be the first to apply!


