About this role
Role : Founding Security Engineer
HRforGrowth® is engaged as the talent acquisition partner to conduct this search on behalf of a client organization that is hiring for this role. HRforGrowth is not the employer for this position. HRforGrowth identifies, evaluates, and presents top-tier candidates through its global talent acquisition practice; all employment decisions — including final selection, offer terms, compensation, and conditions of employment — are made solely by the hiring organization.
Our Client is seeking a Founding Security Engineer to own both internal and customer-facing security at a cloud infrastructure company where security is core to the product.
This is a software engineering role first. The ideal candidate will be a strong software engineer who enjoys thinking deeply about security in and around the cloud and is excited to build systems that protect hundreds of customers' production infrastructure.
This is a rare opportunity to become the first dedicated security hire at a company whose platform operates directly inside customers' AWS, GCP, and Azure environments. The role offers the opportunity to solve high-stakes, deeply technical security challenges, work directly with leading customers, shape the security roadmap from the ground up, and build security capabilities that allow engineering teams to confidently manage sensitive infrastructure.
.
. Location : New York, NY
Job Type : Full-Time
Compensation : $220,000 – $320,000 per year
Visa Sponsorship : Open to H-1B transfers
Relocation: Relocation support available
PTO: 30 days per year
Key Responsibilities
- Found and lead the Secure Engineering function, establishing the internal security roadmap and championing security best practices across a flat engineering organization of approximately 20 engineers.
- Build and ship customer-facing security products that improve the security posture of companies running on the platform.
- Write production-quality Go code to harden multi-cloud infrastructure across AWS, GCP, and Azure.
- Secure Kubernetes clusters deployed across hundreds of customer accounts.
- Own cloud and container security end-to-end, including IAM, network security, secret management, workload isolation, and security logging.
- Design and implement security systems that protect customer production infrastructure across multiple cloud environments.
- Work directly with customers' security engineering teams to build trust, understand security requirements, and ensure managed infrastructure meets or exceeds their security standards.
- Partner closely with engineering teams to integrate secure development practices throughout the software development lifecycle.
- Identify vulnerabilities, security risks, and infrastructure weaknesses and develop practical technical solutions to address them.
- Establish security standards, processes, and engineering practices as the company's first dedicated security engineer.
- Balance internal security needs with customer-facing security requirements while maintaining a high engineering standard.
Required Qualifications
Experience
- Minimum 4+ years of experience as an infrastructure or platform engineer.
- Currently working as a software engineer writing production application code, rather than exclusively in a DevOps or SRE capacity.
- Experience building or contributing to core infrastructure at an infrastructure-focused company such as a PaaS, IaaS, cloud platform, or internal developer platform company.
- Alternatively, experience at a company with an exceptionally high engineering bar, such as Stripe, Ramp, or Databricks.
- Demonstrated experience working on technically complex infrastructure and security challenges.
Technical Skills
- Strong proficiency in Go and experience writing production software.
- Hands-on experience with cloud and container security, including areas such as AWS IAM, Kubernetes, security logging, secret management, and network security.
- Application security experience, including authentication/authorization, vulnerability research, and secure software development practices.
- Experience working with at least one major cloud platform: AWS, GCP, or Azure.
- Experience securing or operating infrastructure across multiple cloud environments.
- Strong understanding of Kubernetes and containerized infrastructure.
- Experience with infrastructure and security technologies such as Terraform, Docker, IAM, and SQL.
Candidate Profile
- Strong software engineering fundamentals with the ability to build production systems rather than simply configure infrastructure.
- Ability to operate as the first dedicated security engineer and take ownership of the security function from the ground up.
- Comfortable working directly with customers and their security teams.
- Strong technical judgment and the ability to make practical security and engineering tradeoffs.
- Comfortable operating in a small, fast-moving engineering organization with significant autonomy.
Dealbreakers
The following are critical requirements for this position:
- Candidates must currently write production application code as a software engineer.
- Pure DevOps/SRE profiles without significant software engineering experience will not be considered.
- Candidates whose experience primarily consists of infrastructure setup without writing software to manage or secure that infrastructure are not a fit.
- Resumes heavily focused on tools and buzzwords such as Helm, Terraform, or CI/CD without demonstrated depth in software engineering, infrastructure, or security are not a fit.
- Contractors or consultants are not preferred for this role.
- Candidates from non-infrastructure companies generally will not be considered unless they come from an organization with an exceptionally high engineering bar.
Preferred Qualifications
- Experience serving as a founding security engineer or security-focused engineer.
- Experience building customer-facing security products or security features.
- Experience establishing security practices and programs from the ground up.
- Experience securing large-scale multi-cloud infrastructure.
- Experience working directly with customer security teams.
- Bachelor's degree in Computer Science or an equivalent technical discipline.
Technology Stack
Go | Kubernetes | AWS | GCP | Azure | Terraform | Docker | SQL | IAM
Ideal Candidate Profile
The ideal candidate is a software engineer first and a security engineer second — someone who enjoys writing production code while thinking deeply about how software, cloud infrastructure, and security intersect.
This person should have strong infrastructure and platform engineering experience, deep hands-on knowledge of cloud and container security, and the ability to work across AWS, GCP, and Azure environments.
As the first dedicated security hire, this individual will have significant ownership and influence. They should be comfortable defining the security roadmap, establishing engineering practices, building customer-facing security capabilities, and working directly with sophisticated customer security teams.
The ideal candidate will be highly technical, pragmatic, and hands-on, with a strong bias toward building secure systems rather than simply implementing security processes or managing infrastructure.
About HRforGrowth:
HRforGrowth is a full-service HR and talent partner built to support companies that are scaling, transforming, or navigating change. HRFG is globally recognized for delivering quality, speed, and cost-effective talent solutions across every level of the workforce. Through its global talent acquisition practice, HRforGrowth applies world class rigor and precision to identifying exceptional professional and executive talent on behalf of its clients — from temporary staffing to permanent hourly workers through to placing C-suite executives. HRforGrowth is presenting this opportunity in its capacity as the retained search partner and does not serve as the employer of record for this position.
Equal Employment Opportunity:
In its recruiting and search practices, HRforGrowth does not discriminate on the basis of race, color, religion, national origin, age, marital status, physical or mental disability, sex, sexual orientation, gender, or gender identity, and welcomes applications from all qualified individuals. HRforGrowth evaluates and presents candidates to its clients without regard to any protected characteristic.
HRforGrowth endeavors to advise the hiring organization to comply with all applicable federal, state, and local equal employment opportunity laws — including those enforced by the U.S. Equal Employment Opportunity Commission (EEOC) — in its hiring decisions, terms of employment, and workplace practices .