Spinwheel Solutions Inc.

Senior Security Engineer, Platforms & AI

Spinwheel Solutions Inc. Oakland, California, United States

Financial Services · 11-50 employees

Yesterday
Remote security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Senior Security Engineer will own the technical security posture of platform, infrastructure, and AI-driven systems. Responsibilities include hardening cloud environments, remediating vulnerabilities, and implementing security guardrails for AI workflows.

What they look for

Security engineering Cloud infrastructure Vulnerability management AWS AI security Incident response Penetration testing Threat modeling DevSecOps Application security Infrastructure hardening Secrets management Encryption Observability Adversarial testing CI/CD security

Requirements

Candidates must have 7+ years of experience in security engineering or related fields with exceptional knowledge of the AWS ecosystem. A self-starter mindset and the ability to communicate complex security issues to engineering stakeholders are essential.

Benefits

Competitive salary Equity opportunities Unlimited PTO Flexible schedule Paid holidays Health insurance Dental insurance Vision insurance

Full description

About the Role

We're looking for a hands-on Senior Security Engineer to own the technical security posture of our platform, infrastructure, and AI-driven systems. You'll spend most of your time in the systems themselves: hardening infrastructure, closing vulnerabilities, and building the guardrails that keep our AI-driven workflows safe.

Following our recent Series A, we're scaling rapidly and investing deeply in platform security, AI safety, and operational resilience. This is a builder's role, not a policy role. You'll work closely with Engineering to secure production systems, find weaknesses, and keep our monitoring and incident response sharp as we scale.

As a remote-first company, we welcome applicants based anywhere in the United States or Canada.

You'll join a high-ownership, high-trust engineering culture where self-starters thrive and autonomy is the natural state of work. 

Key Responsibilities

Security Engineering & System Hardening• Secure and harden cloud infrastructure, applications, APIs, internal systems, and operational workflows.

  • Implement and maintain security controls across production environments, CI/CD pipelines, cloud infrastructure, and internal tooling.
  • Work directly with engineering teams to remediate vulnerabilities and improve secure development practices.
  • Ensure encryption, secrets management, logging, monitoring, and access controls are properly implemented and continuously maintained.
  • Design and improve security architecture across cloud-native and distributed systems.
  • Build scalable security processes that integrate directly into engineering and operational workflows.

Vulnerability Management & Offensive Security• Continuously identify, assess, prioritize, and remediate security vulnerabilities across infrastructure, applications, APIs, and operational systems.

  • Proactively search for weaknesses through vulnerability scanning, penetration testing, adversarial testing, threat modeling, and manual security reviews.
  • Coordinate remediation efforts across engineering and operations teams, and validate fixes to ensure long-term mitigation.
  • Improve detection and prevention capabilities for emerging threats.
  • Help establish a culture of continuous security improvement and operational accountability.

AI Security & Emerging Threat Protection• Secure AI-driven systems and automated agents against prompt injection, adversarial inputs, unauthorized or unintended actions, unsafe outputs, and data leakage.

  • Design and implement guardrails and validation layers for AI-generated actions.
  • Ensure AI systems safely handle untrusted inputs from IVRs, web systems, APIs, and human interactions.
  • Monitor AI system behavior for anomalies, abuse attempts, or unsafe decision-making.
  • Partner with engineering teams to ensure AI systems are observable, auditable, bounded, and fail safely.
  • Help define operational and technical controls for responsible AI deployment.

Monitoring, Detection & Incident Response• Improve and maintain security monitoring, alerting, logging, and incident response capabilities.

  • Investigate suspicious activity, anomalies, and potential security incidents.
  • Lead or support incident response efforts, root cause analysis, and remediation planning.
  • Ensure operational visibility into system health, access patterns, and security events.
  • Recommend and implement preventative measures following incidents or security discoveries.

Required Qualifications• 7+ years of hands-on experience in security engineering, infrastructure security, application security, DevSecOps, or offensive security.

  • Exceptional knowledge of the AWS ecosystem.
  • Demonstrated experience identifying and remediating vulnerabilities in live production systems.
  • Self-starter mindset: able to drive projects, make decisions, and prioritize ruthlessly in a fast-moving environment.
  • Strong communication skills, with the ability to explain technical security issues clearly to engineering stakeholders.

Preferred Qualifications• Experience securing AI/LLM-powered systems or automated agents.

  • Familiarity with prompt injection attacks, adversarial AI techniques, AI guardrails, and behavioral anomaly detection.
  • Experience with cloud security tooling, SIEM and observability platforms, penetration testing tools, endpoint security platforms, and infrastructure-as-code security.
  • Prior experience in high-growth startup, fintech, banking, or payments environments.
  • Certifications such as CISSP, CISM, AWS Security Specialty, or similar.

What We Offer• 100% remote-first culture (work anywhere in the US or Canada)

  • Competitive salary and equity opportunities
  • Unlimited PTO, flexible schedule, and paid holidays
  • Comprehensive health, dental, and vision insurance
  • A culture built on ownership, transparency, autonomy, and craftsmanship
  • Real opportunities for architecture ownership and technical leadership

Similar roles