> Markdown version of [/jobs/ext/3551631-security-engineer](https://www.wearedevelopers.com/jobs/ext/3551631-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Luxer One - **Location:** McClellan Park, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Adobe InDesign, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Cloud Computing, Cloud Computing Security, Cyber Security, Embedded Software, Firmware, Identity and Access Management, Mobile Application Software, Security Information and Event Management, Software Deployment, Software Vulnerability Management, Privacy Controls, Datadog, Large Language Models, Multi-Agent Systems, Software Security, Generative AI - **Published:** October 2, 2026 - **Apply:** https://www.thejobnetwork.com/job/e22ce2d2-4302-4f0c-95ce-4dd3b33705ac/senior-security-engineer ## About the Role * A track record at startup or growth-stage companies - you have operated where security is lean and the surface area is large * Experience as the founding or first dedicated security hire somewhere, or effectively functioning as one * Hands-on depth across IT security and product/application security in the same role * Real AI or LLM security experience: securing model access, auditing agent actions, building monitoring for autonomous behavior, or applying AI governance frameworks to production systems * End-to-end compliance ownership: you have run a compliance program to certification, not just contributed to one RequirementsWhat We're Looking For * Eight or more years of security experience with clear ownership across both IT and product security in the same role * Demonstrated experience as a founding or first security hire - or the functional equivalent - at a startup or growth-stage company * Hands-on security operations depth: SIEM, IR execution, vulnerability management, real incident ownership * Product security experience: threat modeling, pen test coordination, secure SDLC enforcement alongside engineering teams * AI or LLM security experience - securing model access, auditing agent actions, building guardrails for autonomous systems, or applying AI governance frameworks to production deployments * End-to-end compliance program ownership: ISO 27001, SOC 2, or equivalent - not just participation, full ownership * Familiarity with AI governance frameworks: NIST AI RMF, ISO 42001, or emerging regulatory requirements * Cloud security depth - AWS or GCP, CSPM, IAM, cloud incident response * Strong written and verbal communication - policy, post-mortems, executive briefings, customer-facing security conversations Strongly Preferred * Experience securing IoT, connected hardware, or firmware-based products * Hands-on agentic AI security experience - MCP, tool-use APIs, multi-agent systems, autonomous agent monitoring * Privacy engineering depth - CCPA/CPRA operational compliance, DSAR handling, consent management * Relevant certifications: CISSP, GIAC (GCIH, GPEN, GCIA), CIPP/US or CIPP/E, ISO 27001 Lead Implementer, AIGP, or ISO 42001 Lead Implementer * Experience with Wiz, Datadog Security, CrowdStrike, or similar modern security tooling ## Description We have built a lot. Cloud infrastructure running on AWS and GCP. Mobile apps. Embedded firmware on connected locker hardware deployed at thousands of sites. A growing AI operating system with autonomous agents that take real actions against real data. Enterprise customers with real compliance requirements - CCPA, CPRA, ISO 27001 - and a pipeline expanding into Canada and Europe. What we need is one senior security engineer who owns the whole picture: designs the programs, runs the tools, executes incident response, and is the security authority for our AI systems. Not a team. Not a security analyst to hand off to. You. If you have been the first or founding security hire somewhere before - or you are ready to be - this is a high-ownership, high-impact seat at a company that is genuinely ahead of most on AI adoption and needs someone who can help keep it that way. Who You Are You are a security practitioner who builds programs and runs them. The distinction between "architect" and "operator" is not interesting to you - you do both because both need to get done. You are hands-on with tooling, direct in incident response, and thoughtful in design reviews. You treat engineering teams as partners, not compliance risks to manage. You are also someone who has thought seriously about AI security - not because it is a trend, but because you understand that LLM-based systems and autonomous agents introduce attack surfaces that traditional security tooling does not cover, and you want to be the person who figures that out in a production environment. You are probably at a startup or growth-stage company right now - or you have been recently. You have had to make the program work with limited resources, build what did not exist, and be the person engineering leadership calls when something goes wrong. That is the profile. You are: * A builder who ships - you produce controls libraries, compliance evidence, playbooks, and threat models, not just recommendations * An operator who runs it - SIEM tuning, alert triage, IR execution, vulnerability management with real patching accountability * A product security partner - threat modeling alongside engineers, penetration test coordination, secure SDLC enforcement in CI/CD pipelines * An AI security practitioner - you understand prompt injection, tool abuse, agent identity, and runtime monitoring for autonomous systems; you can design the guardrails and detect when they fail * Low ego, high ownership - you take the 3am call, you close the finding, you write the post-mortem