Дар бораи ҷойи кор
The role covers security architecture, application and cloud security, vulnerability management, responsible AI security, and the development of Fieldguide’s security program.
Responsibilities
- Lead secure design reviews, threat modeling, and security-focused code reviews across the product and platform.
- Integrate security into the SDLC through secure-by-default libraries, patterns, and guardrails.
- Own authentication, authorization, API security, and data protection architecture for a multi-tenant SaaS platform.
- Architect and maintain security tooling in CI/CD pipelines, including static analysis, dependency scanning, and secrets detection.
- Evaluate and mitigate risks in Fieldguide’s AI Agents, including prompt injection, LLM context data leakage, unauthorized tool use, and unintended agent behaviors.
- Define security boundaries for agent execution with the Agent and Platform teams, including sandboxing, least-privilege tool access, and runtime policy enforcement.
- Contribute to Fieldguide’s responsible AI approach and protect customer data throughout the AI pipeline from ingestion through inference.
- Build and run the vulnerability management program, including scanning, triage, SLA-driven remediation tracking, and engineering coordination.
- Ensure visibility into vulnerabilities across application code, dependencies, and infrastructure.
- Manage external penetration testing engagements and bug bounty programs, and coordinate remediation of findings.
- Partner with infrastructure engineering to review and improve AWS cloud security across IAM, network architecture, secrets management, and logging.
- Ensure detection and monitoring capabilities for security-relevant events through SIEM.
- Partner with Compliance to ensure technical controls satisfy SOC 2, ISO 27001, ISO 42001, and FedRAMP requirements.
- Help GTM teams articulate Fieldguide’s security posture to enterprise customers.
- Start as an individual contributor, then hire and mentor security engineers as the security program matures, setting its culture and standards.
Requirements
- 8+ years of experience in security, primarily in application security, product security, or security-focused software engineering.
- Track record of building or significantly maturing a security program, ideally at a growth-stage SaaS company.
- Strong programming skills and demonstrated experience writing production software.
- Familiarity with AWS security services and patterns, including IAM, VPC, CloudTrail, and KMS; ability to identify misconfigurations and security gaps without necessarily writing Terraform.
Conditions
- Remote work in the USA.
- Salary: $210K–$260K.