> Markdown version of [/jobs/ext/2942718-security-engineer](https://www.wearedevelopers.com/jobs/ext/2942718-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Y Combinator - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $100,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, User Authentication, Cloud Computing, Cloud Computing Security, Cloud Engineering, Code Review, Identity and Access Management, Key Management, Linux Kernel, Cloud Services, Security Information and Event Management, System Programming, Data Logging, Software Security, Data Management, Machine Learning Operations, Terraform, Vulnerability Analysis - **Published:** September 16, 2026 - **Apply:** https://www.thejobnetwork.com/job/90e9e4da-3078-4fc4-b3ce-1baf5e98a791/security-engineer ## About the Role Core Experience: * 5-10 years of deeply hands-on security experience across offensive security, infrastructure or cloud security, application security, and incident response * Experience building a security program from zero at least once, ideally as an early security hire at a fast-growing startup * Strong AWS and cloud-engineering depth, including infrastructure as code with Terraform * Current hands-on ability to review code, find vulnerabilities, design controls, deploy tooling, and personally lead investigations * Experience implementing or operating SOC 2 or a comparable security framework * Sound judgment and the ability to prioritize the risks that matter in a fast-moving environment Preferred: The following are considered strong signals: * Bug bounty work, penetration testing, vulnerability research, published CVEs, security tooling, conference talks, or substantive technical writing * OSCP or OSWE; AWS, cloud engineering, CKS, or hands-on GIAC certifications * Systems programming, operating systems, Linux kernel work, low-level networking, or experience building infrastructure from the ground up * Experience securing AI/ML infrastructure, agent execution environments, data platforms, or other systems that run untrusted code This role requires current hands-on technical depth and broad security ownership. It is not designed for candidates whose recent experience has been exclusively people leadership or limited to a narrow specialty within an already mature security organization. Offensive-security experience alone is insufficient without demonstrated cloud engineering and program-building ability. ## Description Our client is seeking its first full-time Security Engineer to own and build the security program. This is a hands-on, senior individual-contributor role spanning product security, cloud infrastructure, internal systems, incident response, compliance, and customer trust. The immediate mandate is to bring security up to the standard required of a rapidly scaling data company, strengthen controls as the supplier footprint grows, and take SOC 2 from in progress through completion. Proactive controls, detection, and attack-surface management are central priorities., * Own the security roadmap across product, cloud and infrastructure, corporate systems, incident response, and compliance * Harden AWS infrastructure and accounts, including IAM, networking, logging, Terraform, secrets management, and automated guardrails * Establish stronger monitoring, SIEM/XDR, detection engineering, alerting, and incident-response workflows that identify and stop problems before they become incidents * Secure applications, APIs, the platform, and data workflows through threat modeling, design reviews, code reviews, vulnerability research, authentication and authorization controls, and remediation * Improve container and workload isolation for systems that execute untrusted code or process sensitive data * Own abuse, fraud, and incident response end to end, including containment, investigation, postmortems, and durable follow-up engineering * Build continuous attack-surface management across domains, cloud services, third-party hosting, vendors, and externally exposed assets * Complete SOC 2 and own customer trust work, including control design, evidence, policy management, security questionnaires, vendor reviews, and audits * Translate contractual and data-license requirements into enforceable controls for access, permitted use, retention, deletion, isolation, provenance, and auditability ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)