Lead Security Engineer

AngelListSan Francisco, CaliforniaOn-siteFull-timeSenior, 5–8 yearsListed 5 hours ago

Apply now

About this role

About the role:
The strongest security programs are built by designing systems where the secure path is the easiest path. We're hiring someone to build those systems.
You'll be a hands-on engineer who designs and builds the systems that make security a property of our infrastructure: a unified identity and access layer, cloud security, automated provisioning and revocation, and the guardrails that let teams ship fast. You will work directly with Infrastructure, Engineering, IT, and Product to roll them out.
We want someone who sees AI as a way to change how security engineering operates. Instead of triaging alerts faster, this person will work toward systems that understand context, make decisions, and remediate autonomously. You’ll report to the Head of Security, on a small team with a large scope.

Responsibilities:

- Own AngelList’s security foundations across AWS infrastructure, identity, access control, authentication, authorization, and secrets management.

- Design and build security architecture and guardrails into infrastructure-as-code, CI/CD, and developer workflows so secure defaults are automatic.

- Build IAM systems and least-privilege access models that scale across employees, services, and machine identities — including access reviews and privileged access.

- Write security tooling and automation that finds weaknesses and remediates them without human intervention, harnessing AI where it raises decision quality.

- Solve security risks at the platform and architectural level, and contribute to application security through threat modeling, secure design, and vulnerability remediation.

You may be a good fit if you have:

- 7+ years across security engineering, cloud security, infrastructure security, or identity — including deep hands-on AWS/GCP security architecture and IAM.

- Write real software. You build automation and internal tooling to solve security problems rather than relying on commercial products, and you know when buying is the better call.

- Have driven security changes across engineering teams that didn't report to you, through influence and better tooling rather than mandates.

- Fluent in infrastructure-as-code, CI/CD, and modern DevOps. You have shipped security controls into engineering platforms that developers actually adopted.

- Reason about systems, not findings. You spot systemic weaknesses and fix the class of problem rather than the instance.

- Built something with AI that changed how you work and have opinions about where human judgment still belongs.

Working Here
If you don’t meet every requirement above, we still encourage you to apply. We value complementary strengths and operators who learn by doing.
AngelList has offices in a few cities, with our engineering hub in San Francisco. We’re building our engineering and product teams around this hub to make the most of in-person collaboration. We have a hybrid in-office model: teammates come in at least 2 days per week (Tuesdays and either Wednesday or Thursday). 
Strong preference for SF; may consider NYC.
Compensation:The compensation for this role consists of a competitive base salary, benefits, and equity package. The base salary for this role is $240,000+ annually but actual will vary based on a number of factors including a candidate’s professional background, experience, and location. Additional details about our Total Rewards package will be provided during the recruitment process.
Benefits:We support your life both in and outside of work.
Explore our benefits
Learn about Funders & Founders