> Markdown version of [/jobs/ext/1886940-lead-security-engineer](https://www.wearedevelopers.com/jobs/ext/1886940-lead-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - **Company:** Pyle Sr, James R - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Cloud Computing, Cyber Security, Computer Programming, Databases, Continuous Delivery, Continuous Integration, Data Security, Distributed Systems, PostgreSQL, Node.Js, Information Technology Security Auditing, TypeScript, Web Applications, Pylon Synchronization Software, ReactJS, Software Security, Idris, Production Code, Build Tools, Graphql, NestJS, Glasgow Haskell Compiler - **Published:** July 31, 2026 - **Apply:** https://www.careerbuilder.com/job-details/lead-security-engineer-san-francisco-ca--56250a09-285f-47c0-959f-796cf7c2295c ## About the Role Experience: 6-10+ years in security engineering at high-growth tech companies, with significant time at companies known for strong security cultures. You've built security programs., Application Programming Interface (API), Applications Security, Cloud Computing, Computer Programming, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Distributed Computing, Embedded Systems, Establish Priorities, Financial Systems, High Tech Industry, Information/Data Security (InfoSec), Insurance, Machine Tool, Mortgage, Needs Assessment, Product Engineering, Regulatory Compliance, Risk Analysis, Security Analysis, Security Auditing, Security Infrastructure, Team Building, Technical Leadership, Underwriting ## Description * Hands-on security engineering: You'll write code. Lots of it. This isn't a policy or compliance role. You'll build security infrastructure, implement controls, and integrate security into our development workflow. * Technical leadership: You'll work directly with the CTO and engineering team to make security decisions that affect our architecture. You need to argue convincingly for security priorities while understanding the trade-offs. * End-to-end ownership: From application security to infrastructure hardening to incident response. You'll assess what needs attention, prioritize ruthlessly, and execute. * Building for scale: The security infrastructure you build needs to work today and scale as we grow. You'll set patterns that other engineers follow. * Embedded engineering: You're not a separate security team. You're an engineer who happens to specialize in security, working alongside the rest of engineering to ship secure systems., Technical: Strong systems and application security background. You can read and write code fluently across multiple languages. You understand distributed systems, APIs, databases, and cloud infrastructure well enough to secure them properly. Basics * Job title: Lead Security Engineer * Stock options: own a piece of the company and we all win together * Health insurance, 401K, dental, etc. Our technology stack: We don't require that you've worked with any of these technologies before, this is just our stack for your information: * TypeScript/Node.js (NestJS) * PostgreSQL * AWS infrastructure * Web components (Lit), React * GraphQL APIs About you You: Are dangerous with a keyboard. You write production code regularly. You can implement security controls, build tooling, automate checks, and integrate security into CI/CD. This is not a policy or architecture-only role. Think like an attacker and a builder. You can identify vulnerabilities and threat vectors, and you understand how to build systems that are secure by default. You know what actually reduces risk versus what just looks good. Can make the case. Security decisions often require trade-offs. You can articulate why something matters, what the actual risks are (not FUD), and convince engineers to do the right thing without being dogmatic. Prioritize ruthlessly. Not everything can be perfect on day one. You can assess risk, determine what's urgent versus what can wait, and focus effort where it matters most. Perfect is the enemy of shipped. Understand the domain deeply. You've worked in regulated industries or with sensitive data. You understand compliance requirements and know that passing an audit requires actual security. Build for engineers. Security controls that engineers route around are useless. You design systems that make the secure path the easy path. You understand developer experience matters. Have strong opinions that you're willing to defend. We have a culture of vigorous discussion and debate on technical decisions. We'll push you to defend your choices, and we want you to push back. Don't settle. Challenge yourself to frequently and consistently deliver exceptional work. If something could be more secure, take the initiative to improve it. Have great ideas, and lots of them. You should see opportunities all around you to make our systems more secure. We'll give you an environment where you can act on those ideas. Are self-motivated. You can take a goal and drive towards it without needing extensive hand-holding. The team is supportive and loves to share knowledge and advice, but there's no time for micromanaging your work. Are comfortable with ambiguity. There's a million ways to secure a system; you should feel at ease making a decision under uncertainty while balancing competing constraints. Are confident you can learn quickly. Mortgage is complex, our platform is complex, good security engineering is complex. You've got to have an attitude that you can absorb it, get on top of it, and build something better than what came before. Love strong typing. We're a team full of people who love Haskell and Rust (and Idris!) and take pride in pushing Typescript to its limits. Type safety is security. About the TeamWhat we're not: A compliance checkbox: * We're not looking for someone to run audits and fill out questionnaires. We need someone building actual security. * If you think security means following frameworks without understanding why, Pylon will be frustrating for you. A separate security organization: * You won't have a team of security analysts reporting to you. You'll be embedded with engineering, influencing how we build, not reviewing after the fact. * If you need organizational authority to get things done rather than technical credibility, this isn't the role. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [Putting the Graph In GraphQL With The Neo4j GraphQL Library](https://www.wearedevelopers.com/videos/257-putting-the-graph-in-graphql-with-the-neo4j-graphql-library) - [Why Security-First Development Helps You Ship Better Software Faster](https://www.wearedevelopers.com/videos/1568-why-security-first-development-helps-you-ship-better-software-faster) - [Streaming AI Responses in Real-Time with SSE in Next.js & NestJS](https://www.wearedevelopers.com/videos/1630-streaming-ai-responses-in-real-time-with-sse-in-next-js-nestjs) - [GraphQL + Apollo + Next.js: A Lovely Trio](https://www.wearedevelopers.com/videos/311-graphql-apollo-next-js-a-lovely-trio) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)