Lead Security Engineer
Alembic
About UsAlembic is the pioneering Causal AI platform. We help the world's largest enterprises move past correlation to prove what actually drives business outcomes — the question marketing and growth teams have never been able to answer with confidence. Fortune 100 companies including Nvidia, Delta Air Lines, and Mars use Alembic to make multimillion-dollar decisions on trusted, causal evidence.We're backed by a $145M Series B from WndrCo (founded by Jeffrey Katzenberg), Jensen Huang, Joe Montana, Prysm Capital, and Accenture. Our models run on our own NVIDIA DGX SuperPOD built on Grace Blackwell infrastructure — one of the fastest private supercomputers in the world. (We've melted GPUs getting here.)About the RoleWe're looking for a lead-level Security Engineer and Architect to own system, network, and host security end-to-end for a rapidly growing on-prem, Kubernetes-based AI factory. This is a hands-on, high-impact role reporting directly to our CTO/CISO and working side-by-side with Technical Operations, Corp IT, Platform Engineering, and our scientific teams. It's not a compliance seat that exists to satisfy published controls — it's the chance to shape our security posture from the ground up, secure high-value client data, and build the team and tooling to do it.Two things make this role distinctive. First, Alembic is "Default to Open" by design: security here must respect that maximum information sharing is basic to how we operate, while still protecting customer data and the IP — patents and trade secrets — our applied-science work generates. Balancing those is the core intellectual challenge of the job. Second, we're an AI-first company that uses many kinds of AI across everything we do; deciding which AIs operate in which containers is one of the more interesting problems you'll own.What You'll DoDesign and implement security controls across all environments — network segmentation and firewalling, IDS/IPS, and traffic analysis on our on-prem Kubernetes platform.Build and enforce host security: EDR, kernel telemetry, hardening, and baseline implementation across the fleet.Own identity and access — AuthN/AuthZ, RBAC, and service identity — grounded in OIDC, SAML, and mTLS.Stand up incident-detection pipelines (SIEM, metrics, endpoint telemetry) tuned to surface high-signal threats over noise, and lead incident response end to end: triage, containment, recovery, root-cause analysis, and forensics.Keep the focus on enablement over restriction — effective security, not compliance for its own sake — while balancing IP protection, customer-data protection, and broad internal information sharing.Partner with Legal and the CISO to obtain the compliance certifications we need and to answer customer questions about the security of our systems; hire and mentor as the security function grows.What Will Help You Succeed8+ years in security engineering, infrastructure, or related roles.Strong Linux system security and networking (SSH certificates, directory-based authentication) and strong Kubernetes security (RBAC, tenant isolation, admission control).Real experience securing on-prem environments, not only public cloud.A proven track record leading real-world incidents, with familiarity with attacker techniques (lateral movement, persistence, exfiltration) and hands-on depth in EDR, IDS/IPS, and SIEM.Strong command of OIDC, SAML, mTLS, and cryptography-based storage security.Comfort writing code, automation, and tooling in Python or similar, plus configuration management via IaC (Terraform, Ansible).The judgment to distinguish high-signal threats from noise, make pragmatic tradeoffs in a fast-moving company, and communicate effectively with technical stakeholders.Nice to have: high-performance or distributed-compute experience (HPC, GPU clusters); identity-aware proxies or zero-trust architectures; offensive security (red teaming, exploit development); secure application development and secure-code training; responsible-disclosure/bug-bounty programs; AI controls, MCP security, agent security, and AI governance; and a background in corporate IT security.The role is right for you if:You want to shape a security posture from first principles rather than administer someone else's control framework — and you see "Default to Open" as a design constraint worth solving, not a threat to route around.You'd rather be in the terminal doing root-cause analysis and building detection pipelines than managing them from a slide deck, and you want to build the team around you as scope grows.Why You Might Be Excited About AlembicHard problems with real impact: You'll secure a one-of-a-kind on-prem AI factory and protect the high-value data behind multimillion-dollar decisions at Fortune 100 companies.Technical autonomy: Direct access to the CTO/CISO and decision-makers, ownership over the security architecture, and the freedom to solve problems your way.Cutting-edge environment: Secure our own NVIDIA DGX SuperPOD on Grace Blackwell — one of the fastest private supercomputers in the world — and take on genuinely novel work in AI, agent, and MCP security.Elite team: Join top engineers and scientists who thrive on hard problems, and build the security team from a front-row seat in the culture.Series B momentum, real ownership: Meaningful equity at a Series B company that's raised $145M, with proven product-market fit and Fortune 100 traction.Why You Might Not Be ExcitedYou want a compliance-first role focused on satisfying published controls — this job is about effective security and enablement, and treats certifications as a byproduct, not the point.You need a fully built-out program, tooling, and process to step into, rather than the mandate to define them.You're uncomfortable with "Default to Open" — if your instinct is to lock everything down by default, the constant balance of IP protection, customer-data protection, and broad internal sharing will feel like friction rather than the interesting part.You prefer static over dynamic — priorities and scope shift as we grow. We have real paying customers and a playbook, and we still move at startup speed at Series B scale.Compensation Range: $210K - $240KLocationSan Francisco HQAddressSan Francisco, CaliforniaEmployment TypeFull timeLocation TypeOn-siteDepartmentEngineeringCompensationOur compensation philosophy ensures new hires earn 50%+ current benchmarks. We'll discuss further with you. Most recent San Francisco benchmark data: $210K – $240KOur Compensation Philosophy:Market-based: Our formula ensures new hires earn at or above real-time benchmarks. Ownership: Our generous equity program ensures new hires are owners, not just employees.Transparent: We openly discuss salary expectations to avoid surprises later in the process. Data-driven: We use objective data to remove bias and ensure consistency in compensation decisions.
$275k - $395k
...entertainment company and the leader in AI music. We are backed by leading investors including Bond Capital, Menlo Ventures, Lightspeed... ...arm of NVIDIA). About the Role We’re looking for a Lead Security Engineer to help build the security foundation. This is a hands-on...SuggestedFull timeWork at officeLocal area$140k - $180k
...is headquartered in New York City with offices around the world. To learn more, go to .About the RoleWe’re seeking a Lead Application Security Engineer to help advance Zeta Global’s application and platform security posture through AI-native security practices, intelligent...Suggested$180k - $240k
...Lead Security Engineer Boston or Bay Area, hybrid preferred (2x/week in office) About Us Liberate builds AI agents to automate manual tasks for the $2.7T insurance industry. We started with voice — the hardest and most valuable channel in insurance — and are...SuggestedWork at officeShift work$11 per hour
...transformed how consumer companies transact, we aim to do the same for B2B companies. About the Role We are looking for a lead security engineer to stand up and own security at a company building category-defining products. Our problems span safe deployment of AI agents...Suggested- ...advanced algorithms that significantly outperforms individual engineers. We combine language models with human ingenuity to push the... ...do the threats. That's why we're looking for a battle-tested Lead Security Engineer who’s been in the trenches and can architect, harden...SuggestedRemote workShift work
- ...An innovative tech company in San Francisco is seeking a Lead Security Engineer to architect, harden, and defend its infrastructure. In this role, you'll lead security initiatives and embed security practices into the product lifecycle. Ideal candidates have over 8 years...
- ...Job Description Job Description Lead Security Engineer (Series A Fintech) We are a $20M Series A startup We are seeking a Lead Security Engineer to serve as an autonomous unit within our engineering team. Reporting directly to the CTO , you will own...
$146.3k - $257.7k
About WRITERWRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to... ...of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the...Full timeWork at officeLocal area$200k - $220k
...employees, their laptops, their identities, and the SaaS apps they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our workforce and corporate environment safe. This is a security engineering...Work at officeLocal area$237.6k - $297k
We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity... ...data and full-stack technologies that power the world's leading models, and help enterprises and governments build, deploy,...Full time$234.4k - $385k
...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are... ...engaging a robust security culture. About the RoleAs a Security Engineer, Application Security you will be responsible for identifying and...Work at officeRemote workRelocation packageFlexible hours$230k - $385k
...that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products. We are... ...security culture.About the RoleOpenAI is seeking a Security Engineer to join our Infrastructure Security (InfraSec) team. InfraSec protects...Work at officeLocal areaFlexible hours$189k - $303k
...efficient and accessible for all. We’re searching for a Staff Security Engineer, Enterprise Security Architecture.This position is open to... ...person work increases collaboration, empathy and our ability to lead effectively. As a result, we operate in a hybrid work...Work at officeLocal area3 days per week- ...Corporate Security Engineer Millions of people rely on Notion to do their most important work. Protecting that trust starts with protecting the people who build Notion: our employees, their laptops, their identities, and the SaaS apps they rely on every day. We are...Local area
- ...why we're able to serve a wide range of leading companies. For example, Reddit relies on... ...identity verification infrastructure where security isn't a layer we add later, it's core to... ...'ll work alongside experienced security engineers to defend Persona's people, devices, and...Full timeFor contractorsInternshipWork at officeWork from homeRelocation packageMonday to FridayFlexible hours
$300k - $405k
...growing group of committed researchers, engineers, policy experts, and business leaders working... ...will have the opportunity to shape our security capabilities from the ground up alongside... ...and security teams. Responsibilities: Lead cybersecurity Incident Response efforts covering...Full timeWork at officeVisa sponsorshipFlexible hours$148.5k - $260.1k
...it all.Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re... ...of Salesforce.The ExperienceSalesforce Enterprise Security is hiring a Senior and Lead Security Engineer for our Secure AI team to help assess and maintain...Full time$189k - $303k
...and make mobility more efficient and accessible for all.We're searching for a Staff Security Engineer to join our Enterprise Security Engineering team, reporting to the Technical Lead Manager of Security Engineering.This position is open to the following office locations...Work at officeLocal area3 days per weekEarly shift$347k
...intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people... ...is seeking a Principal Security Engineer to join our Infrastructure Security (InfraSec... ...sophisticated adversaries and insider threats.Lead cross-functional programs to deploy...Work at officeLocal areaFlexible hours$175k - $220k
About the RoleWe are looking for a highly technical Senior Security Engineer who is passionate about protecting data across modern SaaS, cloud, endpoint, and analytics environments.This role is ideal for someone who enjoys solving complex data security challenges through...Full timeWork at office$188.75k - $242.68k
...Francisco with offices in New York, Washington D.C., London and Amsterdam.Security Engineering is the engineering function inside the Plaid security org that focuses on developing the industry-leading security systems and infrastructure. Security Engineering owns most of...Work experience placementLocal area- ...Valued at US$6.2 billion and backed by world-leading investors including Visa, Airtree,... ...About the team The Airwallex Information Security Team is a high calibre and highly... ...app security, Corporate IT and broader engineering functions. What you’ll do As a Senior...Full timeWorldwide
$220k
...AreAt Pave, we're building the industry’s leading compensation platform, combining the... ...Venture Partners, and Craft Ventures.The Security Team @ PaveSecurity at Pave protects the... ...across domains. As Pave's Corporate Security Engineer, you'll own the corporate side of that...Work at officeFlexible hours3 days per week$170k - $205k
...be part of a high-performing team that believes in each other, come build with us at Crusoe.About the Role:Crusoe is seeking a Security Engineer to join the Security Engineering team as the primary driver for implementing security defaults and endpoint visibility. This...Temporary work$146.3k - $257.7k
About WRITERWRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand... ...of work with AI. About the roleJoin WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's transforming...Full timeWork at officeLocal area$208k - $312k
...products that help builders move from idea to production with speed, security, and exceptional developer experience.Now, software is entering... ...what comes next.About the Role:We are looking for a Security Engineer to join our Detection Response team. In this role, you will be...Work at officeRemote workWork from homeWorldwideMonday to FridayFlexible hoursShift work$150k - $220k
...the globe. Valued at US$11 billion and backed by world-leading investors including T. Rowe Price, Visa, Mastercard,... ...what’s next.About the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems, data...Temporary workLocal areaWorldwide- Factory is seeking a talented Security Engineer to join our team. In this role, you will play a critical role in developing and maintaining... ....Document security processes, procedures, and best practices.Lead security awareness and training programs, empowering all team...Work at office
$165k - $200k
Merge is the leading provider of agentic tools and customer-facing integrations for frontier... ...Handler, which empowers AI agents with secure access to thousands of third-party tools... ...sales, reduce customer churn, and save engineering resources—allowing them to focus on...Full timeWork at officeHome office- ...offices in New York, Washington D.C., London and Amsterdam.The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s... ..., and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code...Work experience placementWork at officeLocal areaShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Security Engineer. Be the first to apply!
- lead operating engineer San Francisco, CA
- lead network engineer San Francisco, CA
- lead web developer San Francisco, CA
- lead engineer San Francisco, CA
- lead infrastructure engineer San Francisco, CA
- staff security engineer San Francisco, CA
- network security engineer San Francisco, CA
- product security engineer San Francisco, CA
- senior application security engineer San Francisco, CA
- sr security engineer San Francisco, CA


