8090 Solutions Inc

Lead Security Engineer

8090 Solutions Inc Redwood City, California, United States · $180K–$350K/yr

Technology, Information and Internet · 11-50 employees

8 h ago
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Lead Security Engineer will own application security, cloud security posture, and compliance for the 8090 Software Factory. This hands-on role involves designing security controls, performing penetration tests, and acting as the primary technical security advisor for customers.

What they look for

Application Security Cloud Security DevSecOps AWS Python TypeScript Terraform Infrastructure as Code Penetration Testing Compliance SOC 2 Threat Modeling Incident Response Identity and Access Management Security Architecture Risk Management

Requirements

Candidates must have 7 to 10 years of professional IT, DevOps, or application development experience with at least 3 years in a primary security role. Proficiency in Python, TypeScript, AWS, and infrastructure-as-code tools is required, along with experience in regulated industries.

Benefits

Medical Dental Vision 401k Stock options

Full description

About 8090

The Software Industrial Complex has evolved into a bloated, expensive ecosystem that burdens enterprises with unnecessary complexity and inefficiency. Co-founded and led by Chamath Palihapitiya, we are building a Software Factory that delivers fully-managed and hosted software purpose-built for each customer.

About the Role

We are hiring our first Lead Security Engineer to own application security, cloud security posture, and compliance at 8090. You will report to the CEO and work daily with the CTO and the engineering team. You will secure the 8090 Software Factory and the custom-built applications we deliver through 8090 Enterprise, and you will be the technical counterpart to customer CISOs, CIOs, and system architects in regulated industries.

This is a hands-on role. You will write the CI/CD security gates, run the internal penetration tests, design the AWS controls, and take the call with the customer's CISO yourself. You will not manage a team at the start. You will direct the vendors that extend your reach: penetration testing firms, managed service providers, our managed detection and response partner, our compliance automation platform, and our auditors. We expect you to automate the manual work of security with agent harnesses and with the Software Factory itself, so that a very small team runs a program that would otherwise take a large team.

Location

You will work in person 5 days a week from our Redwood City, CA office. You will partner closely with our lean, top-notch engineering teams and sales while leading complex security engagements for large enterprises.

Responsibilities

  • Application Security and DevSecOps: Own the secure development lifecycle for the Software Factory and every 8090 Enterprise application. Build and operate SAST, DAST, software composition analysis, secrets detection, and infrastructure-as-code scanning in our GitHub Actions pipelines, with gates that stop critical and high vulnerabilities before release. Set remediation SLAs and drive findings to closure with engineering, prioritizing by exploitability, reachability, data sensitivity, and customer impact rather than scanner severity alone.
  • Penetration Testing and Disclosure: Perform internal penetration testing of 8090 web applications, APIs, and cloud environments using internally built and custom-off-the-shelf agent harnesses. Scope and direct independent third-party penetration tests, bounty programs, and stand up a vulnerability disclosure channel.
  • Cloud Infrastructure Security: Own the security posture of our production environments: primarily AWS, with some GCP and occasional Azure deployments. Implement least-privilege IAM, network segmentation, encryption and key management, secrets management, centralized logging assessment and threat detection, backups and recovery, and infrastructure-as-code guardrails in AWS CDK and Terraform so that every customer environment meets CIS Benchmarks and NIST baselines and is isolated from every other. Run continuous posture monitoring and drive remediation.
  • Security Architecture: Act as the principal advisor in the security design of the Software Factory and 8090 Enterprise applications: authentication and authorization, tenant isolation, data classification and the handling of PII, PHI and other regulated data, audit logging, third-party integrations, customer-specific deployments, and the controls that govern AI agents, including tool-use permissions, prompt injection defenses, and data boundaries. Lead threat modeling and security design reviews.
  • Compliance Program: Own the controls behind our SOC 1 Type II and SOC 2 Type II reports and keep them audit-ready year round on our compliance automation platform. Design controls for GDPR, HIPAA, and FedRAMP. Select, direct, and hold accountable auditors, assessors, and managed service providers to complete compliance work on schedule, while retaining ownership of scope, evidence accuracy, remediation, and risk decisions. Set the roadmap for the frameworks our customers will require next.
  • Customer Trust and Sales Support: Partner with sales and go-to-market on customer security reviews, questionnaires, due-diligence requests, RFPs, and procurement reviews. Own the security questionnaire answer library (SIG, CAIQ, and custom) and build our trust center. Present to customer CISOs, CIOs, security teams, and system architects, handle their technical objections with precise explanations of architecture, controls, residual risk, and mitigation, and work with legal on security addenda, DPAs, and BAAs. Feed recurring customer requirements into the product and security roadmaps.
  • Security Automation with AI: Use AI agents and DevOps automation to remove manual work from application and infrastructure security across customer workloads: evidence collection, vulnerability triage and remediation, questionnaire drafting, posture checks, and detection. Build these automations with the Software Factory and treat them as products. Evaluate every automation before relying on it, and apply least privilege, isolation, logging, tests, and human approval to consequential changes.
  • Detection and Incident Response: Own the incident response plan and runbooks, run tabletop exercises, and meet the breach notification obligations in our customer contracts and under HIPAA. Run 24x7 monitoring through our managed detection and response partner, own the escalation path, and lead technical response to material events through closure of corrective actions.
  • Third-Party and AI Supply Chain Risk: Maintain the vendor and subprocessor inventory, run vendor security reviews, and manage the risk from LLM providers, models, and open-source dependencies. Keep an accurate view of assets, attack surface, and privileged access, and partner with IT and Engineering to close high-impact gaps.
  • Corporate Security Partnership: Partner with the Head of IT on identity and access, endpoint security, zero-trust access, and quarterly access reviews so that corporate controls and production controls hold to the same standard.
  • Program Leadership: Set the security roadmap, risk register, budget, and metrics. Report material risks, decisions, and progress to the CEO and the leadership team. Make explicit risk decisions that protect customers without creating unnecessary release friction; escalate material exceptions and give every accepted risk an owner and a review date. Build security champions across Engineering and delivery teams, and decide when the function needs its next hire.
  • Hands-on Engineering: Work directly in the codebase to validate findings, ship fixes, and build secure defaults, reusable libraries, developer tooling, and lightweight internal web applications. Script DevSecOps pipelines and write infrastructure-as-code.

Required Skills

  • 7 to 10 years of professional IT, DevOps, or application development experience, including at least 3 years in a role where application, cloud, or infrastructure security was a primary responsibility.
  • Has led security and compliance functions at a technology startup (Series A, B, or C stage).
  • Hands-on engineer who builds web applications and DevSecOps pipelines and writes infrastructure-as-code. You can read, write, review, test, and ship production web and API code, and you build security tooling rather than only administer vendor products. We use Python, TypeScript, React, GitHub Actions, Docker, AWS CDK, Terraform and AWS.
  • Application security depth: SAST, DAST, dependency and secrets scanning, CI/CD security gates, threat modeling, vulnerability management, and internal penetration testing.
  • Cloud, networking, systems architecture, and release-engineering fundamentals, with depth in AWS and the ability to secure or direct work in GCP and Azure.
  • Experience with infrastructure as code, containers, identity and access management, secrets and key management, logging, detection, and incident response.
  • Working knowledge of SOC 2, GDPR security requirements, HIPAA safeguards, and FedRAMP mechanics. You have directly implemented and operated controls for SOC 2 and at least one regulated or government environment.
  • Experience working in a regulated industry (healthcare, financial services, or GovTech) as an IT professional, software engineer, platform engineer, or security engineer.
  • Experience directing external auditors, security assessors, managed service providers, penetration testers, and compliance or security tooling vendors.
  • Comfortable in front of customer CISOs, CIOs, security teams, and system architects. You can work credibly with engineers and explain architecture, controls, risk, and tradeoffs to customers and executives.
  • A record of owning ambiguous problems, learning missing context quickly, and driving work to verified completion, with small internal teams and large, demanding customer organizations.

What Sets a Candidate Apart

  • Has been the first security hire at a Series A to Series C startup and built the program from nothing.
  • Has personally led a startup through a SOC 2 Type II examination, with direct experience of HIPAA-regulated data, GDPR-scoped processing, or a FedRAMP assessment or continuous-monitoring program.
  • Has secured LLM-based applications and AI agents in production: prompt injection, tool-use permissions, sandboxing of agent execution, and the model and data supply chain, with working knowledge of the OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Has built AI-assisted security workflows, including with AI coding agents, that improved signal, remediation time, audit evidence, or customer-review turnaround without weakening human oversight.
  • Has designed security for enterprise SaaS, dedicated customer environments, legacy modernization, or other systems with complex data and deployment boundaries.
  • Has delivered security for healthcare (HIPAA and PHI), federal, or financial services customers.
  • Has supported SOC 1 or SOX-relevant controls for publicly traded customers.
  • FedRAMP experience, including the FedRAMP 20x certification paths, or GovRAMP, TX-RAMP, HITRUST, ISO 27001, or ISO 42001.
  • Has run a compliance automation platform (Vanta, Drata, or Secureframe) and a customer-facing trust center.
  • Offensive security evidence such as OSCP, bug bounty findings, CVEs, or published research; CISSP, CCSP, or CISM.

We'd Love to Hear from You

Tell us about a security program or DevSecOps pipeline you built from scratch at a startup. What did you automate, what did you deliberately leave out, and how did it hold up in a customer security review or an audit?

Expected Compensation (US-based employees)

$180,000 - $350,000 annual salary + stock and/or stock option awards + benefits. We offer competitive pay and benefits. Compensation may vary depending on many individualized factors, including location, job-related knowledge, skills, and experience. Details of the compensation package, including benefits (medical, dental, vision, 401K, ...), will be provided if and when a candidate receives an offer of employment.

Employment Eligibility- This position is only open to candidates who can provide sufficient documentation establishing employment eligibility in the United States of America and to provide satisfactory proof of your identity as required by U.S. law. A further condition of your employment is satisfactory completion of a credit and/or criminal background check.

We do not provide new work visa sponsorship.

Equal Opportunity Statement - 8090 is an Equal Opportunity employer. All qualified applicants will be considered for employment without regard to any factor, including veteran status and disability status, protected by applicable federal, state, or local laws.

Similar roles