Job Closed
This listing is no longer active.
Powering the future of trust with modern software for assurance & advisory firms.
Lead Security Engineer
Location
California
Posted
114 days ago
Salary
$210K - $260K / year
Seniority
Senior
Job Description
Lead Security Engineer
Fieldguide
• Lead secure design reviews, threat modeling, and security-focused code reviews across the product and platform. • Ensure security is ingrained into the SDLC so that the secure path is the easy path for engineers with secure-by-default libraries, patterns, and guardrails. • Own authentication, authorization, API security, and data protection architecture for a multi-tenant SaaS platform. • Architect and maintain security tooling integrated into CI/CD pipelines: static analysis, dependency scanning, secrets detection. • Evaluate and mitigate risks specific to Fieldguide's AI Agents — prompt injection, data leakage through LLM contexts, unauthorized tool use, and unintended agent behaviors. • Partner with Agent and Platform teams to define security boundaries for agent execution: sandboxing, least-privilege tool access, and runtime policy enforcement. • Build and run Fieldguide’s vulnerability management program: scanning, triage, SLA-driven remediation tracking, and engineering coordination. • Ensure visibility into vulnerability posture across application code, dependencies, and infrastructure. • Manage external penetration testing engagements, bug bounty programs, and coordinate remediation of findings. • Partner with infrastructure engineering to review and improve cloud security across our AWS environment: IAM, network architecture, secrets management, and logging. • Establish runbooks, communication protocols, and post-incident review practices in coordination with a 24/7 MDR team. • Collaborate with engineers on incident response processes and playbooks. • Partner with Compliance to ensure technical controls satisfy framework requirements (SOC 2, ISO 27001, ISO 42001, FedRAMP).
Job Requirements
- 8+ years in security with a primary background in application security, product security, or security-focused software engineering.
- Track record of building or significantly maturing a security program, ideally at a growth-stage SaaS company.
- Strong programming skills with demonstrated experience writing production software.
- Familiarity with AWS security services and patterns: IAM, VPC, CloudTrail, KMS.
- Experience with threat modeling methodologies and secure design review processes.
- Experience managing external penetration tests and coordinating remediation.
- Familiarity with AI/LLM security considerations and emerging risks in agentic AI systems is a plus.
- Experience supporting compliance frameworks (SOC 2, ISO 27001, NIST, FedRAMP) from the technical controls side is a plus.
Benefits
- Competitive compensation packages with meaningful ownership
- Flexible PTO
- 401k
- Wellness benefits
- Technology & Work from Home reimbursement
- Flexible work schedules
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Ensure that clients' security infrastructures and systems remain operational. • Monitor, identify, investigate, and resolve technical incidents and problems. • Handle client requests or tickets with technical expertise, ensuring they are resolved within the agreed service level agreement (SLA). • Actively manage work queues, perform operational tasks, and update tickets with resolution actions. • Log incidents promptly and provide second-level support. • Execute changes responsibly, flagging risks and mitigation plans. • Collaborate closely with automation teams to optimize efforts and automate routine tasks. • Audit incident and request tickets for quality, recommending improvements.
Senior Cybersecurity Lead
GuidehouseSolving big problems, building trust in society, and empowering our clients to shape the future.
• Apply fundamental cybersecurity principles and concepts for a large DoD IT program • Develop and implement a plan to achieve cybersecurity and RMF objectives across the lifecycle of the program, to include close coordination across program workstreams and Government stakeholders • Maintain cybersecurity implementation plans, milestones, schedules, and resourcing requirements across cross-functional teams • Apply NIST Risk Management Framework (RMF), NIST SP 800-53 controls, Assessment and Authorization processes for both on-prem and cloud-based systems, POA&M management, and System Security Plan development and maintenance • Work with senior members of the program and client organization to ensure that overall cybersecurity program and project direction, strategy and expectations are met • Understand of Governance Risk and Compliance (GRC) requirements, standards, and guidelines governing security within the Federal Government (e.g., NIST publications, FISMA, and OMB memoranda) and aligning IT with business objectives to effectively manage risk • Design and implement system security plans and policies, such as account management policies or auditing policies • Perform cybersecurity risk management, research and development, and leading practices • Gather and organize technical information about an organization's mission goals and needs, existing security products, and ongoing programs in cybersecurity • Develop strategies, roadmaps, assessments, and policies • Work with solution architects for security requirements on network architecture • Conduct and lead risk assessments and managing risks • Develop and implement cybersecurity policies and procedures
• Lead the charge in building secure, resilient, and high-performing IT infrastructure across the nationwide healthcare network. • Ensure seamless connectivity for clinics, HQ, and remote teams while safeguarding sensitive data and maintaining regulatory certifications. • Be deeply involved in day-to-day operations, personally architecting solutions, troubleshooting complex issues, and driving key initiatives. • Solve critical challenges and deliver tangible results, ensuring the network and security posture remains robust and responsive.
• Work with clients to assess and improve their cybersecurity posture, design practical solutions aligned with business objectives, and support the deployment and implementation of security strategies, frameworks, and concrete measures to improve protection and resilience. • Conduct risk assessments and security reviews to identify vulnerabilities, recommend improvements, and assist in defining roadmaps and action plans for cybersecurity initiatives. • Collaborate with multidisciplinary teams to deliver projects that combine business, technology, and regulatory perspectives. • Stay informed about cybersecurity trends, regulations, and technologies to provide relevant insights.




