D

Senior Security Engineer (Founding Role) – AI Governed Identity Agent Security

david joseph & company United State
Visa Sponsorship
Apply
AI Summary

Own the end-to-end security architecture for a novel AI 'coworker' agent in enterprise IT, designing secure governance, threat modeling, and compliance frameworks. Lead secure product development, incident response, and external validations while setting internal security standards. Requires senior-level expertise in application, cloud, and identity security with hands-on coding in Python/Go/Rust/TypeScript.

Key Highlights
Founding security role for a pioneering AI agent in enterprise IT with novel governance mechanisms
End-to-end ownership of security architecture, threat modeling, and compliance for a product category with minimal prior art
High autonomy in a fast-moving startup environment with direct collaboration with founders and enterprise partners
Key Responsibilities
Lead end-to-end security posture for application, cloud, network, and the AI agent itself
Conduct secure design reviews and threat modeling for a governed-identity, approval-gated agent
Build security primitives into the product, including per-customer isolation, credential handling, approval gates, and audit trails
Own the security architecture documentation for enterprise buyer review and deployment
Oversee external validation through penetration testing, compliance frameworks, and enterprise security reviews
Manage incident readiness and response with breach notification measured in hours
Integrate security scanning, secret detection, and compliance checks into CI/CD pipelines
Set internal standards for credential handling and data egress
Technical Skills Required
Application Security Cloud Security Identity and Access Management (IAM)
Benefits & Perks
$200,000–$300,000 annual base salary
1–2% meaningful equity
Visa sponsorship (H-1B, O-1, OPT)
On-site work in San Francisco, CA
Nice to Have
Experience securing agentic or code-execution systems
Depth in modern isolation techniques (containers, microVMs)
Offensive security or penetration-testing background
Experience running a bug bounty or vulnerability disclosure program
Familiarity with enterprise IT identity standards (e.g., directory services, SSO, PAMA)

Job Description


About The Company

Our client is an early-stage, seed-funded startup building an AI "coworker" for enterprise IT teams — an agent that operates as a governed identity inside a customer's directory, requests scoped access for each task, and acts only under human approval. They're backed by well-known operators and investors from across the IT and security world, already have live design partners, and are building a product category with very little prior art.

Founded 2026

  • 1–10 people
  • Industry: AI Tools / Enterprise IT & Security


The Role

You'll own the security posture of the company and its product end-to-end — application, cloud, network, and the agent itself. Because there's limited prior art for securing a governed-identity agent that requests scoped access and acts under human approval, the work is genuinely novel: leading secure design reviews, building security primitives into the product, and owning the security story that enterprise buyers read before they deploy.

What you'll be doing

  • Own the end-to-end security posture: application, cloud, network, and the agent itself
  • Lead secure design reviews and threat modeling for a governed-identity, approval-gated agent
  • Build security primitives into the product: per-customer isolation, credentials the agent uses but never sees, approval gates on write actions, a customer-controlled capability dial, and replayable audit trails
  • Own the written security architecture that enterprise buyers review before deploying
  • Run external validation: penetration testing, compliance frameworks, and enterprise security reviews
  • Own incident readiness and response, with breach notification measured in hours
  • Push scanning, secret detection, and compliance checks into CI
  • Set the internal bar for credential handling and data egress


Tech stack: Python / Go / Rust / TypeScript; cloud + infrastructure-as-code; identity & workload IAM; container / microVM isolation; CI security tooling

Requirements

  • Senior/Staff-level, hands-on experience across both application and infrastructure security
  • Writes production-quality code in at least one of Python, Go, Rust, or TypeScript
  • Strong practical threat-modeling and vulnerability-identification skills
  • Real depth in network and identity security — identity-based controls, policy enforcement, and workload IAM
  • Cloud security expertise on at least one major provider, including identity federation and infrastructure-as-code
  • Communicates risk trade-offs clearly to both hands-on engineers and executive stakeholders
  • Thrives with high autonomy in an ambiguous, fast-moving environment
  • Able to work on-site in San Francisco, Monday–Friday, at startup intensity


Nice to Haves

  • Experience securing agentic or code-execution systems
  • Depth in modern isolation techniques — container security, kernel-level hardening, microVMs
  • Offensive security or penetration-testing background
  • Have run or owned a bug bounty or vulnerability disclosure program
  • Have carried a company through compliance frameworks and enterprise security reviews
  • Familiarity with enterprise IT and identity — directory services, SSO, PAM
  • A standout track record of excellence, whether a top-tier CS/engineering education, strong competition results, or building and leading at a high-growth company
  • High agency — former founders or engineers who've owned large, ambiguous scope


Why Join

  • Own security end-to-end as the founding security hire, on a genuinely novel problem
  • Help define a new category — securing governed-identity AI agents for enterprise IT
  • Meaningful equity (1–2%) and strong backing from respected IT and security operators
  • Work directly with the founders and live enterprise design partners


Details

  • Location — San Francisco, CA
  • Work policy — On-site, Monday–Friday
  • Compensation — $200,000–$300,000 + 1–2% equity
  • Visa sponsorship — Available (H-1B, O-1, OPT)
  • Employment type — Full-time

Similar Jobs

Explore other opportunities that match your interests

Vehicle Cybersecurity Engineer

Cyber Security
8h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

systems technology group, inc....

United State

Senior Capabilities Researcher, AI Security (Claude Security Team)

Cyber Security
11h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

anthropic

United State

PERSEC Management Specialist (Contract Program Security Officer) - Industrial Security Team

Cyber Security
1d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

anthropic

United State

Subscribe our newsletter

New Things Will Always Update Regularly