Lead Security Engineer
8090
- Location
- Redwood City
- Employment
- Full Time
- Work model
- On-Site
- Level
- Senior
- Salary
- $180k – $350k/yr
- Posted
- 1h ago
Skills
About this role
About 8090 The Software Industrial Complex has evolved into a bloated, expensive ecosystem that burdens enterprises with unnecessary complexity and inefficiency. Co-founded and led by Chamath Palihapitiya, we are building a Software Factory that delivers fully-managed and hosted software purpose-built for each customer.
About the Role
We are hiring our first Lead Security Engineer to own application security, cloud security posture, and compliance at 8090. You will report to the CEO and work daily with the CTO and the engineering team. You will secure the 8090 Software Factory and the custom-built applications we deliver through 8090 Enterprise, and you will be the technical counterpart to customer CISOs, CIOs, and system architects in regulated industries. This is a hands-on role. You will write the CI/CD security gates, run the internal penetration tests, design the AWS controls, and take the call with the customer's CISO yourself. You will not manage a team at the start. You will direct the vendors that extend your reach: penetration testing firms, managed service providers, our managed detection and response partner, our compliance automation platform, and our auditors. We expect you to automate the manual work of security with agent harnesses and with the Software Factory itself, so that a very small team runs a program that would otherwise take a large team. Location You will work in person 5 days a week from our Redwood City, CA office. You will partner closely with our lean, top-notch engineering teams and sales while leading complex security engagements for large enterprises.
Responsibilities
Application Security and DevSecOps: Own the secure development lifecycle for the Software Factory and every 8090 Enterprise application. Build and operate SAST, DAST, software composition analysis, secrets detection, and infrastructure-as-code scanning in our GitHub Actions pipelines, with gates that stop critical and high vulnerabilities before release. Set remediation SLAs and drive findings to closure with engineering, prioritizing by exploitability, reachability, data sensitivity, and customer impact rather than scanner severity alone. Penetration Testing and Disclosure: Perform internal penetration testing of 8090 web applications, APIs, and cloud environments using internally built and custom-off-the-shelf agent harnesses. Scope and direct independent third-party penetration tests, bounty programs, and stand up a vulnerability disclosure channel. Cloud Infrastructure Security: Own the security posture of our production environments: primarily AWS, with some GCP and occasional Azure deployments. Implement least-privilege IAM, network segmentation, encryption and key management, secrets management, centralized logging assessment and threat detection, backups and recovery, and infrastructure-as-code guardrails in AWS CDK and Terraform so that every customer environment meets CIS Benchmarks and NIST baselines and is isolated from every other. Run continuous posture monitoring and drive remediation. Security Architecture: Act as the principal advisor in the security design of the Software Factory and 8090 Enterprise applications: authentication and authorization, tenant isolation, data classification and the handling of PII, PHI and other regulated data, audit logging, third-party integrations, customer-specific deployments, and the controls that govern AI agents, including tool-use permissions, prompt injection defenses, and data boundaries. Lead threat modeling and security design reviews. Compliance Program: Own the controls behind our SOC 1 Type II and SOC 2 Type II reports and keep them audit-ready year round on our compliance automation platform. Design controls for GDPR, HIPAA, and FedRAMP. Select, direct, and hold accountable auditors, assessors, and managed service providers to complete compliance work on schedule, while retaining ownership of scope, evidence accuracy, remediation, and risk decisions. Set the roadmap