Senior Security Engineer

Luxer OneUnited StatesHybridFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

SENIOR SECURITY ENGINEER

Own the security program — from cloud infrastructure to AI agents — at a hardware-meets-software IoT company moving fast.

About Luxer One

Luxer One builds and deploys smart locker and access systems across multifamily, commercial, retail, and enterprise markets in North America. An Assa Abloy company, our platform spans cloud infrastructure, mobile applications, IoT firmware, and a live AI operating system — Cortex — with more than twenty deployed autonomous AI agents running real operations across the company. We process millions of transactions annually and are trusted by enterprise customers who take security seriously.

We are not a software company that ships firmware on the side. We are not a hardware company trying to do software. We are both, fully, which makes the security surface broader and more interesting than most.

Why This Role Exists

We have built a lot. Cloud infrastructure running on AWS and GCP. Mobile apps. Embedded firmware on connected locker hardware deployed at thousands of sites. A growing AI operating system with autonomous agents that take real actions against real data. Enterprise customers with real compliance requirements — CCPA, CPRA, ISO 27001 — and a pipeline expanding into Canada and Europe.

What we need is one senior security engineer who owns the whole picture: designs the programs, runs the tools, executes incident response, and is the security authority for our AI systems. Not a team. Not a security analyst to hand off to. You.

If you have been the first or founding security hire somewhere before — or you are ready to be — this is a high-ownership, high-impact seat at a company that is genuinely ahead of most on AI adoption and needs someone who can help keep it that way.

Who You Are

You are a security practitioner who builds programs and runs them. The distinction between "architect" and "operator" is not interesting to you — you do both because both need to get done. You are hands-on with tooling, direct in incident response, and thoughtful in design reviews. You treat engineering teams as partners, not compliance risks to manage.

You are also someone who has thought seriously about AI security — not because it is a trend, but because you understand that LLM-based systems and autonomous agents introduce attack surfaces that traditional security tooling does not cover, and you want to be the person who figures that out in a production environment.

You are probably at a startup or growth-stage company right now — or you have been recently. You have had to make the program work with limited resources, build what did not exist, and be the person engineering leadership calls when something goes wrong. That is the profile.

You are:

- A builder who ships — you produce controls libraries, compliance evidence, playbooks, and threat models, not just recommendations
- An operator who runs it — SIEM tuning, alert triage, IR execution, vulnerability management with real patching accountability
- A product security partner — threat modeling alongside engineers, penetration test coordination, secure SDLC enforcement in CI/CD pipelines
- An AI security practitioner — you understand prompt injection, tool abuse, agent identity, and runtime monitoring for autonomous systems; you can design the guardrails and detect when they fail
- Low ego, high ownership — you take the 3am call, you close the finding, you write the post-mortem

And you bring:

- A track record at startup or growth-stage companies — you have operated where security is lean and the surface area is large
- Experience as the founding or first dedicated security hire somewhere, or effectively functioning as one
- Hands-on depth across IT security and product/application security in the same role
- Real AI or LLM security experience: securing model access, auditing agent actions, building monitoring for autonomous behavior, or applying AI governance frameworks to production systems
- End-to-end compliance ownership: you have run a compliance program to certification, not just contributed to one

Requirements

What We're Looking For

- Eight or more years of security experience with clear ownership across both IT and product security in the same role
- Demonstrated experience as a founding or first security hire — or the functional equivalent — at a startup or growth-stage company
- Hands-on security operations depth: SIEM, IR execution, vulnerability management, real incident ownership
- Product security experience: threat modeling, pen test coordination, secure SDLC enforcement alongside engineering teams
- AI or LLM security experience — securing model access, auditing agent actions, building guardrails for autonomous systems, or applying AI governance frameworks to production deployments
- End-to-end compliance program ownership: ISO 27001, SOC 2, or equivalent — not just participation, full ownership
- Familiarity with AI governance frameworks: NIST AI RMF, ISO 42001, or emerging regulatory requirements
- Cloud security depth — AWS or GCP, CSPM, IAM, cloud incident response
- Strong written and verbal communication — policy, post-mortems, executive briefings, customer-facing security conversations

Strongly Preferred

- Experience securing IoT, connected hardware, or firmware-based products
- Hands-on agentic AI security experience — MCP, tool-use APIs, multi-agent systems, autonomous agent monitoring
- Privacy engineering depth — CCPA/CPRA operational compliance, DSAR handling, consent management
- Relevant certifications: CISSP, GIAC (GCIH, GPEN, GCIA), CIPP/US or CIPP/E, ISO 27001 Lead Implementer, AIGP, or ISO 42001 Lead Implementer
- Experience with Wiz, Datadog Security, CrowdStrike, or similar modern security tooling

### Benefits
Location & Work Model

- Sacramento, CA. On-site or hybrid

### Benefits
Luxer Has Got You Covered!

- You will have a 401k with up to 4.5% matching, untracked vacation, and a hybrid work schedule.
- We promote education through tuition reimbursement.
- You will also have medical, dental, vision, and life insurance programs, as well as employee assistance programs.
- You’ll have opportunities to advance.
- We’re fans of helping our employees learn different aspects of the business, be challenged with new tasks, be mentored and grow.
- We promoted 42% of our employees last year!
Luxer One is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other legally protected status.

Compensation
​
The pay range for this role is $145,000-180,000 per year, depending on experience, skills, and location. This range reflects what we believe in good faith we'd pay for this position at the time of posting, and final offers may vary based on qualifications and business needs .