Director, Security Engineering Research and Development New York City · San Francisco View role →
$200k - $250kJobleads-US
About InstaLILY
InstaLILY is an AI products and infrastructure company that puts execution at the frontier of enterprise AI. That work begins with Lily™, the world's first AI Forward Deployed Engineer, which learns how a business works, builds the software it needs, and goes live in days. It does not leave when the work ships; it stays and keeps the software working as the business changes. Lily runs wherever the work happens, in the cloud, on-premise, or at the edge, through InstaLILY's Small Data Center, built with NVIDIA technology. Founded in 2023 by Amit Shah and Sumantro Das, InstaLILY has raised nearly $100 million from Energize Capital, Insight Partners, and Home Depot Ventures. Headquartered in New York, with offices in San Francisco, London, and Toronto, InstaLILY serves leading companies across construction, industrial distribution, logistics, healthcare, and other operationally intensive industries. Learn more at
The Traction
Revenue grew 5x over the past year, and Lily has driven over $200M in new annual sales for a single customer. We serve some of the largest operators in our industries, including SRS Distribution (part of The Home Depot family), United Rentals, and Henry Schein, and we work closely with the Google DeepMind and NVIDIA ecosystems.
How We Work
We work in small teams with real ownership: clear problems, direct access to the customers whose work you're changing, and room to ship. Your code runs in live production systems inside billion-dollar operations, so you see your impact directly. People who do well here want that proximity to the work. We're growing fast, and the people who join now shape what this company becomes. Everything runs on three principles: Customers, Culture, and Code.
The Role: Own Security for Agents That Do Real Work
We're hiring our first dedicated security leader, reporting directly to the CEO. Lily operates inside the systems of some of the largest enterprises in distribution, construction, healthcare, and logistics. That makes security a core part of the product and a lever on every enterprise deal we close.
This isn't a cold start. We hold SOC 2 Type II and HIPAA, an Okta rollout is underway, and a CNAPP evaluation is in progress. What we need is one accountable owner who can take a strong foundation and turn it into a proactive, evidence-backed security program.
This is a player-coach role. You'll spend 30 - 50% of your time writing code (automation, infrastructure-as-code, security tooling, remediation PRs), and most of the rest threat-modeling, reviewing architecture and PRs, and hardening cloud and IAM. You'll also be the face of security to enterprise customers, spending roughly 25 - 30% of your time on CISO calls, audits, and security reviews.
What You'll Do
- Own Customer Trust: Run enterprise security reviews end to end. Build one source of truth for security answers, launch a trust center and security package, and lead CISO and InfoSec calls, audits, and RFP security sections, often on short notice.
- Run the Compliance Program: Keep SOC 2 Type II and HIPAA healthy in Drata: continuous control monitoring, policy refreshes, and access reviews. Lead us through our next audit window and stand up a GDPR program.
- Harden the Cloud: Partner with SRE to prioritize and close critical and high cloud findings. Make org-level guardrails the default: org policies, secrets management, and least-privilege IAM across GCP and AWS.
- Secure the Agents: Build security into Lily from the start: threat models, prompt-injection defenses, tenant isolation, agent authorization, and security checks in CI as part of a secure SDLC.
- Test and Respond: Commission and run our independent pen-test program and drive remediation. Refresh the incident response plan, run tabletop exercises, and serve as the escalation point for security incidents.
- Build Identity and Endpoint Foundations: Complete SSO (Okta) coverage for tier-1 apps, run quarterly access reviews, and put device management (MDM) in place.
- Set the Operating Model: Decide whether to partner with a vCISO or GRC service for paperwork-heavy work, complete the CNAPP evaluation, and deliver a 12-month security roadmap to the CEO and leadership.
- Grow the Function: Hire and lead 1 - 2 security or AppSec engineers as the program scales.
What Success Looks Like in Year One
- A clean SOC 2 Type II and HIPAA renewal with no exceptions, and >=95% of controls passing continuously.
- Standard security questionnaires returned in 3 business days or less, customer CISO calls covered within 1 business day, and every answer backed by evidence.
- An annual independent pen test completed, with critical findings remediated within SLA.
- Critical and high cloud findings closed, with secure-by-default guardrails enforced across the org.
- SSO on all tier-1 apps, quarterly access reviews, and MDM in place.
- AI and agent security built into the platform, not bolted on.
- A GDPR program running and a clear decision on ISO 27001 and HITRUST.
What You'll Need
- 8+ Years in Security Engineering: Including hands-on ownership of a security or compliance program at a SaaS company, ideally at the Series B - C stage.
- Hands-On Cloud and AppSec Depth: Strong in GCP and AWS IAM, Kubernetes, and infrastructure-as-code (Terraform/OpenTofu). You can threat-model a multi-tenant, multi-cloud architecture and review code, not just run scanners.
- A Builder, Not Just a Reviewer: You write production-quality Python or TypeScript and ship your own automation, tooling, and fixes. You'd rather build and harden systems than monitor alerts or manage checklists.
- End-to-End SOC 2 Type II Ownership: You've run the program yourself: audits, controls, evidence, and GRC tooling. You treat compliance as real risk reduction. HIPAA experience is a strong plus.
- Credibility With Enterprise CISOs: You've led customer security reviews, questionnaires, and audits, and can hold your own in a room with a Fortune 5,000 security team.
- Real LLM Experience: You've built something real with LLMs and understand how agentic systems change the threat model.
- Player-Coach Mindset: You're energized by doing the work yourself. Tech‑lead or program‑lead experience is enough; formal people management is a plus, not a requirement.
- In-person availability. 5 days/week in our New York or San Francisco office.
Bonus Points
- You've built a security function from scratch at a Series B/C SaaS company and taken it through SOC 2 Type II.
- You've secured an LLM or agent product in production (prompt injection, agent authorization, OWASP Top 10 for LLMs).
- You've led a real incident response.
- Experience with multi-tenant isolation, pen-test programs, Okta or IdP rollouts, and CNAPP tooling such as Wiz or Aikido.
- Familiarity with GDPR, ISO 27001, HITRUST, NIST CSF, or the EU AI Act.
- Certifications such as CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Security Specialty, or OSCP. None are required.
- Public work: talks, writing, or open-source security tooling.
Our Stack
- Cloud: GCP primary (Cloud Run, Cloud SQL, GKE), AWS secondary (EKS); customer deployments also run in AWS and Azure
- Infra and code: Kubernetes, OpenTofu, Postgres, TypeScript/Next.js, Python
- Identity and compliance: Okta, WorkOS, Drata
- Observability and edge: Datadog, Grafana, Sentry, Cloudflare
You’ll secure a multi-tenant platform with hundreds of cloud services across multiple clouds, at a company of roughly 100 - 150 people.
Why InstaLILY?
- Greenfield Ownership: You’re the first dedicated security leader, reporting to the CEO, with real influence over how the company builds.
- Frontier Agent Security: AI agents that do real work inside enterprise operations create a new kind of attack surface. This is not another CRUD app.
- Security Is a Revenue Lever: Enterprise deals move on security, so your work is visible and valued across the company.
- A Foundation to Build On: SOC 2 Type II and HIPAA are in place, and core identity and cloud tooling work is already underway.
- Well Funded and Scaling: Fresh off a $60M Series B, with offices in New York, San Francisco, London, and Toronto.
Location, Travel, and On-Call
- Location: New York strongly preferred; San Francisco considered for exceptional candidates.
- Travel: Minimal. Occasional customer onsites or audits, plus periodic trips to New York if based in San Francisco.
- On-call: You'll be the escalation point for security incidents. This is not part of a routine ops rotation.
Compensation and Benefits
- Salary Range: $200,000 - $250,000 per year, commensurate with experience
- Equity: Generous stock option awards and refreshers for top performers
- Benefits: Medical, Dental, Vision, 401K, in-office lunch reimbursement, Wellness Stipend, generous parental leave, PTO and 10 US Federal Holidays, and more!
Quality Over Quantity
To ensure a focused, high-quality hiring experience, we kindly ask candidates to limit their applications to 3 open requisitions at any given time . Applying strategically to roles that best align with your skills and career goals gives you the highest chance of standing out. Have you interviewed with us in the past 12 months? We encourage you to reach out directly to your previous interviewer rather than submitting a new application.
InstaLILY is committed to providing an inclusive and barrier-free recruitment process. If you require an accommodation, please let us know, and we will work with you to meet your needs.
#J-18808-Ljbffr Jobleads-US$190k - $225k
...Staff Security Engineer, Threat Intelligence Houston; New York; San Francisco; Seattle About Nscale Nscale is the GPU cloud... ...reducing the complexity of AI development. Our GPU cloud bolsters technical... ...the future. About the Role We’re hiring a Staff Security...SuggestedFlexible hours- ...top of it. The role Blacksmith is building... ..., customer development, go-to-market, pricing... ...’s founders and engineering team to make... ...feel like building a new infrastructure company... ...Develop a clear view of the sandbox... ...reliability, and security. This role is not...SuggestedShift work
$175k - $210k
...Senior Product Marketing Manager, Trust & Security San Francisco or New York Full-time $175,000 – $210,000 About the role Regulated brands don't buy AI support on demos alone. They buy it once their CISO, DPO and general counsel agree. You'll own how Pazau tells...SuggestedFull time$218.4k - $365.2k
## Senior Director, Security Engineering - SlackApply: Office -... ...Flexible: California - San Francisco: California - Palo Alto: New York - New York:... ...a maximum of 3 roles within 12 months... ..., published researcher, or contributor... ...annually. In select cities within the San Francisco...SuggestedFull timeWork at officeFlexible hoursShift work$130k - $230k
...healthcare, yet both are often harder to secure than they should be. By integrating... ...to accelerate this mission. About The Role In this role, you will drive scaling... ...subject to applicable law. Pursuant to the San Francisco Fair Chance Ordinance, we will consider...SuggestedWork at officeLocal areaRelocation$118.7k - $243.7k
Position Summary New Ventures Technology &... ...priority programs. The role provides structured analysis... .... Professional development From entry-level... ...Ordinance for Employers, City of Los Angeles’s Fair Chance... ...for Hiring Ordinance, San Francisco Fair Chance Ordinance,...Local area$209.5k - $239.1k
...Director, Product Management - Security & Data Intelligence Solutions... ...the Team & Role At... ...leader who views security... ...Innovation: Define new ways to... ...Scalable Engineering Oversight:... ...Management New York, NY: $251,4... ...Law; San Francisco, California... ...; New York City’s Fair Chance...Full timePart timeLocal area$10 per hour
...play a pivotal role in how goods move... .... Own security configuration for... ...or IT security engineering — we care more... ...A point of view on how agentic... ...We're in the San Francisco office regularly... ...maximum target for new hire salaries for... ...688 USD New York City Pay Range $14...Work at officeImmediate startFlexible hours- ...looking for a Senior Application Security Engineer to work with our engineering... ...an integral part of our Software Development Lifecycle (SDLC). In this role, you’ll have the chance to use your... ...three days a week in our San Francisco office. What You’ll Do: Partner...Work at officeLocal areaWorldwideRelocation3 days per week
$134.5k - $265.1k
...proactively manage to secure success.Recruiting for this role ends on 12/31/2... ...team Saviynt Engineering Manager, you... ...full system development lifecycle.Ability... ...to build new skills, take on... ...for Employers, City of Los Angeles’... ...Hiring Ordinance, San Francisco Fair Chance Ordinance...Local areaVisa sponsorship- ...Hex is seeking its first leader for the AI engineering team to shape research strategy across post-training, model evaluation... ...quality technical content. Based out of our San Francisco or New York office, this full-time role blends research and product engineering with...Full timeWork at office
$285k - $295k
...Principal Information Security Engineer, Identity... ...to a new industry, join... ...controls. The role will provide knowledge... ...application development teams to implement... ...data, please view our Candidate... ...including the City of Los Angeles... ...to the San Francisco Fair Chance Ordinance...Daily paidFull timeLocal areaRemote work$265k - $310k
Director, Securities & Corporate Counsel Kikoff: The Fintech Powering Financial... ...and corporate counsel role. You will drive corporate and... ...to. You will need to build new structure, not inherit it. Preferred... ...and requires being in the San Francisco, CA office three times a...Work at officeLocal area$2,000 per month
...unstructured data — securing and... ...is The Role: Elastic... ...a Senior Director of Product... ...most senior engineering leader, a... ...point of view on how a challenger... ...launch a new career or... ...Software Development Framework... ...CA, the San Francisco Bay Area... ...the New York City Metro Area...Local areaFlexible hoursShift work$163.4k - $322.1k
...Summary AI Security Senior... ...enterprises. This role sits at the... ..., and development of future leaders... ...Science, Engineering, Information... ...points of view in AI security... ...to build new skills, take... ...Employers, City of Los Angeles... ...Ordinance, San Francisco Fair Chance...Local areaWorldwideVisa sponsorship$175k - $275k
...consensus. About the Role DRW is building out its offensive security capability, and we’re... ...Offensive Security Engineer to lead the charge.... ...discovery, and exploit development, and evaluate new AI‑powered offensive... ...applicants' data, please view DRW's Privacy Notice....Contract workTemporary workFlexible hours$138.87k - $173.59k
...re acquiring new skills and... ...Principal Presales Engineer on Twilio’s... ...Engineer role is a... ...Previous software development experience in... ...Center, or Security Experience... ...areas of San Francisco, CA, Oakland... ...Jersey, New York, Vermont, Washington... ..., political views or activity,...Remote jobLocal areaWorldwide$180k - $230k
...industries and beyond. Security at Valon Our... ...closely with Product and Engineering to design and deliver... ...are located in New York City and San Francisco, but we fully support... ...remote work! About the Role We are seeking an experienced... ...other learning & development opportunities...Local areaRemote workFlexible hours$82.6k - $162.8k
...proactively manage to secure success.Recruiting for this role ends on 12/31/2... ...a Security Engineer on the Deloitte... ...Professional development From entry-... ...opportunities to build new skills, take on... ...for Employers, City of Los Angeles’... ...Ordinance, San Francisco Fair Chance...Local areaVisa sponsorship- ...InstaLILY is seeking a senior security leader to own the security program for Lily, our multi-tenant AI platform. You will shape... ...relations, reporting directly to the CEO. Based in New York or San Francisco, you’ll spend time coding, designing security controls, and...
$122.57k - $184k
...Start Location: San Jose Employment Type... ...global partners, including Engineering teams based in Mandarin... ...in the selected city is $122574 - $184000 annually... ...their work, and this role may be eligible for additional... ...also have offices in New York City, London, Dublin,...Temporary workLocal areaWorldwide$140k - $235.4k
...skills across engineering, sales, product... ...In this pivotal role, you will define... ...of design and research practices, and... ...on the Product Development AI Transformation... ...programs for new Product and Design... ...in 8 major cities: Atlanta, Lisbon, London, San Francisco, Santiago, Sydney...Work at officeLocal area2 days per week$122k - $240.5k
...As a Full Stack Engineer Senior... ...interactions.This role is designed for... ...with business, security, privacy, legal... ...into software development and deployment... ...opportunities to build new skills, take on... ...for Employers, City of Los Angeles’... ...Ordinance, San Francisco Fair Chance Ordinance...Local areaVisa sponsorship$183.1k - $340k
...of America, New York, New York:... ...Principal Software Engineer – CoCounsel... ...reliable, secure, production... ...day.This role sits at the... ...engineers, researchers, product,... ...point of view on what “AI... ...* **Career Development and Growth:... ...: New York City, San Francisco, Los...Work at officeLocal areaFlexible hours2 days per week3 days per week$134.5k - $265.1k
...Summary AI Security ManagerOur... ...Recruiting for this role ends on 05/31/... ...Science, Engineering, Information... ...or secure AI development practicesExperience... ...to build new skills, take on... ...for Employers, City of Los Angeles... ...Hiring Ordinance, San Francisco Fair Chance...Local areaWorldwideVisa sponsorship$179.4k - $204.7k
...are seeking **Security Engineers** who are passionate... ...and integrate new security... ...security and software development in one or more... ...for this role are listed below... ...3-A of the New York Correction Law; San Francisco, California Police... ...4920; New York City’s Fair Chance Act...Full timePart timeH1bLocal area$168.75k - $270k
...United States; San Francisco, California, United... ...- Principal Security Operations Engineer Our mission is to... ...will play a key role in building secure... ...existing and new environments. Drive... ...Security, and development teams to influence... ...a long‑term view because we want...Work at office$132.23k - $242.43k
...The Role As Alkira continues... ...networking platform, security remains a... ...Principal Security Engineer to serve as a... ...to the Director of Platform Engineering... ...teams, and researcher communication.... ...you from the new position or... ...Pursuant to the San Francisco Fair Chance...H1b$156.8k - $196k
## Senior Security Engineer - Fuze HealthApplylocations:... ...requirements for this role include the ability... ...Missouri, Nevada, New Hampshire, New... ...Jersey, New Mexico, New York, North Carolina,... ...Los Angeles County, San Francisco, Philadelphia, and New York City Fair Chance laws. We...Full timeTemporary workWork experience placementRemote workVisa sponsorshipFlexible hours$134.5k - $265.1k
...Forward Deployed Engineer (FDE), you will... ...for this role ends on 12/31/2... ...Engineering is a new team that is spearheading... ...in full stack development across frontend... ...., application security, cloud security... ...for Employers, City of Los Angeles’... ...Ordinance, San Francisco Fair Chance...Local areaVisa sponsorship
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Security Engineering Research and Development New York City · San Francisco View role →. Be the first to apply!
- senior director information security Kentucky
- program manager with security clearance Kentucky
- security operations manager Kentucky
- physical security manager Kentucky
- director information security Kentucky
- corporate security manager Kentucky
- product security manager Kentucky
- security manager Kentucky
- senior security manager Kentucky
- surveillance manager Kentucky


