Security Engineer

HeyGen Technology Inc.
San Francisco, CA, United States
2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Cloud Computing Cyber Security Fraud Prevention and Detection Identity and Access Management Python (Programming Language) Key Management Network Security Software Engineering Software Vulnerability Management Virtual Agents
+1 more
Software Coding

Job description

At HeyGen, our mission is to make visual storytelling accessible to all. Over the last decade, visual content has become the preferred method of information creation, consumption, and retention. But the ability to create such content, in particular videos, continues to be costly and challenging to scale. Our ambition is to build technology that equips more people with the power to reach, captivate, and inspire audiences. Learn more at www.heygen.com. ., As a Security Engineer at HeyGen, you will own the security posture of one of the fastest-growing AI companies in the world. You will partner directly with engineering teams to ship secure features, harden our cloud infrastructure, and build the compliance and trust programs that unlock enterprise deals. This is a high-impact, high-autonomy role for an engineer who thinks in threat models and ships code., * Product & Infrastructure Security: Partner with engineering teams as an embedded security expert - writing code, reviewing architectures, and building secure application features and infrastructure components from the ground up.

  • Fraud Detection & Remediation: Design and implement automated fraud detection systems to mitigate platform abuse, credential stuffing, and payment fraud. Partner with product and engineering to build real-time monitoring and rapid-response remediation workflows.
  • Cloud & Vulnerability Management: Own the strategy and execution for hardening our AWS/Python infrastructure. Build and run a robust vulnerability management program, including network security, cloud configuration, and remediation workflows.
  • AI Security: Serve as HeyGen’s point person for AI and agentic system security. As we scale our agentic coding and AI agent products, you will ensure these rollouts are designed and deployed with strong security controls.
  • GRC & Compliance: Oversee our SOC 2 compliance operations (currently managed via Drata) and annual audit cycles. Evaluate and roadmap future certifications, including ISO 27001, as the business scales.
  • Trust & Safety Oversight: Provide high-level oversight for platform abuse and content moderation (in partnership with growth and avatar teams), and serve as the escalation point for IT security incidents.

Requirements

  • Strong software engineering background with hands-on Python and AWS experience; you write code, not just policies.
  • Demonstrated experience securing cloud infrastructure and applications - vulnerability management, network security, IAM, and secrets management.
  • Familiarity with GRC frameworks and compliance programs (SOC 2, ISO 27001, or equivalent).
  • Excellent communication skills: able to translate threat models for engineers, compliance requirements for auditors, and security architecture for enterprise CISOs.
  • Comfortable with ambiguity and rapid scale; you prioritize ruthlessly and know when to build vs. buy.
  • Experience with modern security tooling is a plus (Drata, Infisical, Bugcrowd, or equivalents).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:41 min

Protecting etcd databases using Key Management System plugins

Alex Soto Alex Soto · LIVE

3:21 min

Navigating the ethical integration of virtual colleagues

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all