> Markdown version of [/jobs/ext/2718374-lead-security-engineer](https://www.wearedevelopers.com/jobs/ext/2718374-lead-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - **Company:** Hinge Inc. - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Programming, Cursor (Graphical User Interface Elements), Monitoring of Systems, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Machine Learning, Networking Basics, OAuth, Reliability Engineering, Security Assertion Markup Language (SAML), TypeScript, Software Vulnerability Management, Okta, Software Security, Cyber Threat Analysis, Machine Learning Operations, Terraform, Data Pipelines, Api Management - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/lead-security-engineer-hingehealth-com-8084189 ## About the Role * Bachelor's degree in a technical, engineering, or scientific field - or comparable education/experience * 3+ years in cybersecurity, with 3+ years focused on security operations or IAM * 2+ years of experience in cloud security operations, specifically AWS * 2+ years of coding experience (e.g., Python, Go, or TypeScript) with hands-on experience developing Terraform and infrastructure-as-code * Hands-on experience securing AI/ML systems, including data pipelines, model deployments, API integrations, and their security challenges, * AWS Solutions Architect or Security Specialty certification * AI/ML security certifications or familiarity with adversarial machine learning threats and mitigation strategies * Experience building or integrating security controls into CI/CD pipelines and AI-assisted development workflows * Experience managing an Enterprise IdP, especially Okta, with deep understanding of OAuth 2.0 and SAML * SOC 2, PCI, or HIPAA audit/training certifications * Knowledge of low-level networking principles ## Description * A Security-First Thinker: You instinctively design systems that are secure by default, and you know how to balance security rigor with engineering velocity. * An AI-Savvy Engineer: You're energized (not intimidated) by the rapid adoption of AI-assisted development and see it as an opportunity to build novel security frameworks. * A Trust Builder: You communicate effectively across engineering, compliance, and leadership teams - authoring clear, plain-spoken technical proposals that drive alignment. * A Learn-it-all: You stay ahead of emerging threats and continuously evolve your approach - from adversarial ML to supply chain attacks on AI pipelines. * A Leader at All Levels: You're hands-on in code and architecture, but you also mentor others and help the team self-organize around measurable outcomes., * Audit current cloud security posture and IAM architecture across our AWS environment; build relationships with key stakeholders in Application Security, SRE, and R&D Engineering. * Assess existing AI-assisted development tooling (Claude Code, Cursor, MCP gateway) for security risks and begin developing a governance framework. In your first 6 months: * Design and implement AI-driven tools and workflows to enhance security monitoring, threat detection, incident response, and IAM governance. * Develop and enforce policies and protocols to protect AI tools and platforms from misuse, data breaches, and external threats - including secure agent sandboxing and MCP server governance. * Deliver IAM solutions enabling secure, granular access controls that enforce least privilege principles, utilizing automation and AI for privilege escalation and approvals. In your first year: * Own the security strategy for AI-enabled development and cloud infrastructure, acting as the primary subject matter expert for security engineering across the organization. * Ensure all compliance regulations - including HIPAA, privacy, and relevant security frameworks - are met for new services, AI tooling, and infrastructure. * Develop and drive cybersecurity initiatives related to incident response, threat intelligence, vulnerability management, and monitoring tools. * Mentor team members in adopting new security tools and processes; educate the broader organization through knowledge-sharing sessions and author clear technical proposals with measurable security OKRs. ## Related Videos - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [What is Software Engineering in the Age of AI?](https://www.wearedevelopers.com/magazine/640-what-is-software-engineering-in-the-age-of-ai) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)