> Markdown version of [/jobs/ext/2652957-security-architecture-saas-cloud-engineer](https://www.wearedevelopers.com/jobs/ext/2652957-security-architecture-saas-cloud-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # security architecture saas cloud engineer - **Company:** Carry Technologies Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $180,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Software as a Service, Cloud Computing Security, Cyber Security, Customer Data Management, Data Infrastructure, Distributed Systems, Software Security, Multi-Cloud, Backend, Rate Limiting, Build Management - **Published:** August 5, 2026 - **Apply:** https://www.workingnomads.com/job/go/1772906/ ## About the Role You've been an early security hire at a SaaS company before and moved the needle on how they approach security. You can read application code, threat model a distributed system, and ship production fixes. You have significant distributed systems expertise so that you can understand and influence what is being built by the product teams and influence from a place of trust. Experience that's relevant: * Being an early security hire (first 1-3) at a SaaS or data infrastructure company * Securing multi-tenant platforms: tenant isolation, authorization models, etc * Cloud security on systems that span more than one cloud and operate against customer-owned accounts * Design and build of data infrastructure as an early engineer, not just a user. You helped secure it from early design or during major redesigns. You understand how it scales and how it's secured * Privacy-adjacent security (PII handling, data residency, GDPR/CCPA technical controls) ## Description This is our first dedicated security hire, and it's a rare chance to define the function from the ground up. You'll own Hightouch's application security posture end-to-end. We have strong engineering fundamentals and a solid foundation; now you'll shape what security looks like here as we scale from 70 to 140+ engineers. This is a hands-on, high-autonomy role. You'll spend most of your time in the codebase, not in meetings. You'll be solving hard problems at the intersection of security and distributed systems: * Multi-tenant isolation on a system running ~1M data syncs per day and ingesting 100K+ events/sec * Sub-tenant access control - for multi-team and multi-brand use cases, requiring differentiated access to configuration and data * Security architecture - Build and refine our frameworks for compute isolation and perform threat modeling and hardening of new products * Internet-facing APIs - Our high-throughput, internet-facing architecture services customer data at scale. You'll improve our rate limiting, abuse detection, and granularity of access control * Multi-Region and Multi-Cloud - Supporting our multi-region and multi-cloud backend, including extending it to launch Hightouch on in new regions to support data residency requirements of our global customer base You'll own your roadmap. We're not looking for someone to run a checklist - we're looking for someone who can look at our architecture, identify the highest-leverage problems, and go fix them., We are looking for talented, intellectually curious, and motivated individuals who are interested in tackling the problems above. This is a senior role, but we focus on impact and potential for growth more than years of experience. The salary range for this position is $180,000 - $400,000 USD per year, which is location independent in accordance with our remote-first policy. We also offer meaningful equity compensation in the form of ISO options, and offer early exercise and a 10 year post-termination exercise window., 4. Hiring Manager Interview [60m] - What you've built in the past, how you work 5. Security Program Interview [60m] with Head of Engineering - How you've run security programs in practice: bug bounty, pentest engagements, working with external researchers, and partnering across engineering to drive adoption. E-Verify Statement Hightouch participates in E-Verify. After you join the team, we'll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only - we never use E-Verify to pre-screen applicants. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)