Senior Security Engineer, Platforms & AI
Spinwheel Solutions Inc. Oakland, California, United States
Financial Services · 11-50 employees
About the role
The Senior Security Engineer will own the technical security posture of platform, infrastructure, and AI-driven systems. Responsibilities include hardening cloud environments, remediating vulnerabilities, and implementing security guardrails for AI workflows.
What they look for
Requirements
Candidates must have 7+ years of experience in security engineering or related fields with exceptional knowledge of the AWS ecosystem. A self-starter mindset and the ability to communicate complex security issues to engineering stakeholders are essential.
Benefits
Full description
About the Role
We're looking for a hands-on Senior Security Engineer to own the technical security posture of our platform, infrastructure, and AI-driven systems. You'll spend most of your time in the systems themselves: hardening infrastructure, closing vulnerabilities, and building the guardrails that keep our AI-driven workflows safe.
Following our recent Series A, we're scaling rapidly and investing deeply in platform security, AI safety, and operational resilience. This is a builder's role, not a policy role. You'll work closely with Engineering to secure production systems, find weaknesses, and keep our monitoring and incident response sharp as we scale.
As a remote-first company, we welcome applicants based anywhere in the United States or Canada.
You'll join a high-ownership, high-trust engineering culture where self-starters thrive and autonomy is the natural state of work.
Key Responsibilities
Security Engineering & System Hardening• Secure and harden cloud infrastructure, applications, APIs, internal systems, and operational workflows.
- Implement and maintain security controls across production environments, CI/CD pipelines, cloud infrastructure, and internal tooling.
- Work directly with engineering teams to remediate vulnerabilities and improve secure development practices.
- Ensure encryption, secrets management, logging, monitoring, and access controls are properly implemented and continuously maintained.
- Design and improve security architecture across cloud-native and distributed systems.
- Build scalable security processes that integrate directly into engineering and operational workflows.
Vulnerability Management & Offensive Security• Continuously identify, assess, prioritize, and remediate security vulnerabilities across infrastructure, applications, APIs, and operational systems.
- Proactively search for weaknesses through vulnerability scanning, penetration testing, adversarial testing, threat modeling, and manual security reviews.
- Coordinate remediation efforts across engineering and operations teams, and validate fixes to ensure long-term mitigation.
- Improve detection and prevention capabilities for emerging threats.
- Help establish a culture of continuous security improvement and operational accountability.
AI Security & Emerging Threat Protection• Secure AI-driven systems and automated agents against prompt injection, adversarial inputs, unauthorized or unintended actions, unsafe outputs, and data leakage.
- Design and implement guardrails and validation layers for AI-generated actions.
- Ensure AI systems safely handle untrusted inputs from IVRs, web systems, APIs, and human interactions.
- Monitor AI system behavior for anomalies, abuse attempts, or unsafe decision-making.
- Partner with engineering teams to ensure AI systems are observable, auditable, bounded, and fail safely.
- Help define operational and technical controls for responsible AI deployment.
Monitoring, Detection & Incident Response• Improve and maintain security monitoring, alerting, logging, and incident response capabilities.
- Investigate suspicious activity, anomalies, and potential security incidents.
- Lead or support incident response efforts, root cause analysis, and remediation planning.
- Ensure operational visibility into system health, access patterns, and security events.
- Recommend and implement preventative measures following incidents or security discoveries.
Required Qualifications• 7+ years of hands-on experience in security engineering, infrastructure security, application security, DevSecOps, or offensive security.
- Exceptional knowledge of the AWS ecosystem.
- Demonstrated experience identifying and remediating vulnerabilities in live production systems.
- Self-starter mindset: able to drive projects, make decisions, and prioritize ruthlessly in a fast-moving environment.
- Strong communication skills, with the ability to explain technical security issues clearly to engineering stakeholders.
Preferred Qualifications• Experience securing AI/LLM-powered systems or automated agents.
- Familiarity with prompt injection attacks, adversarial AI techniques, AI guardrails, and behavioral anomaly detection.
- Experience with cloud security tooling, SIEM and observability platforms, penetration testing tools, endpoint security platforms, and infrastructure-as-code security.
- Prior experience in high-growth startup, fintech, banking, or payments environments.
- Certifications such as CISSP, CISM, AWS Security Specialty, or similar.
What We Offer• 100% remote-first culture (work anywhere in the US or Canada)
- Competitive salary and equity opportunities
- Unlimited PTO, flexible schedule, and paid holidays
- Comprehensive health, dental, and vision insurance
- A culture built on ownership, transparency, autonomy, and craftsmanship
- Real opportunities for architecture ownership and technical leadership
Similar roles
-
Senior Security Engineer
Commonwealth Bank Bengaluru, Karnataka, India
-
Security Engineer, Vulnerability Management (ACAS/Tenable.sc) - Secret clearance
PGTEK Ogden, Utah, United States · $130K–$160K/yr
-
Security Engineer, GKE
Google Seattle, Washington, United States · $174K–$252K/yr
-
Cybersecurity Incident Response Triage Analyst
Accenture Federal Services Careers Marketplace Arlington, Virginia, United States · $57K–$109K/yr
-
Cybersecurity Incident Response Triage Analyst
Accenture Federal Services Arlington, Virginia, United States · $57K–$109K/yr
-
Information Security Engineer
EverBank Jacksonville, Florida, United States