Security Engineer, Full Stack
Job description
-automation.
About the role
Join Hadrian as a founding member of our security team, shaping the platform's security as we expand to external customers and partners. This full-stack role involves securing application code, cloud infrastructure, Kubernetes, identity management, and factory operational technology. You will establish security standards from the ground up, tackling complex challenges in unique manufacturing environments. The position requires deep collaboration with engineering, product, and design teams to embed security into the development lifecycle from day one. You will be responsible for defining and driving the security roadmap in a fast-paced, high-growth setting. This role is ideal for a hands-on leader who thrives on solving ambiguous problems and building security programs from scratch. You will balance the need for rapid innovation with the strict requirements of regulated defense manufacturing. Your work will directly impact the security posture of critical infrastructure and autonomous factory systems.
Key facts
What you'll do
- Manage security across the entire technology stack, including application code, AWS/GCP cloud infrastructure, Kubernetes workloads, identity and authorization systems, and factory-floor operational technology.
- Enhance security through automation by developing agentic tooling, AI-driven checks, and self-enforcing guardrails to scale coverage without increasing headcount.
- Investigate unfamiliar systems, including new technologies and specialized manufacturing equipment, to identify risks and design appropriate controls.
- Transform compliance requirements like CMMC 2.0 / NIST 800-171 and ITAR into practical, auditable engineering solutions.
- Lead incident response, including investigation, containment, and resolution, then implement systemic fixes to prevent recurrence.
- Design and implement security controls for CI/CD pipelines, ensuring that secure coding practices and vulnerability scanning are integrated into every deployment.
- Conduct threat modeling and risk assessments for new features and infrastructure changes, translating technical findings into actionable security requirements.
- Develop security playbooks and runbooks that standardize responses to threats, incidents, and misconfigurations across cloud and on-premises environments.
- Partner with product managers to define security acceptance criteria for new products, ensuring that privacy and regulatory requirements are considered early in the design phase.
- Evaluate emerging security technologies and frameworks, conducting proof-of-concept exercises to determine their applicability to manufacturing systems.
- Collaborate with site reliability engineering teams to ensure that security monitoring, logging, and alerting are robust and scalable.
- Provide technical leadership in securing industrial protocols and equipment used in factory-floor operational technology environments.
- Mentor engineers on secure coding practices, code review standards, and the importance of security hygiene in automated systems.
- Drive the adoption of security tools within development workflows, ensuring that security is a contributor enabler rather than a bottleneck.
Requirements
- Ability to develop and implement security solutions through code (Go, Python, or similar), creating guardrails, SDKs, CLIs, and CI/CD checks.
- At least 4 years of experience in security engineering, software engineering, or infrastructure/platform engineering, with direct security ownership.
- Familiarity with agentic systems, including building with or on LLM agents and automation.
- Capability to quickly understand ambiguous missions, make sound decisions under uncertainty, and rapidly learn new technologies.
- Skill in evaluating and communicating the trade-offs between risk aversion and innovation in decision-making.
- Demonstrated history of streamlining security controls or processes by replacing them with effective automated solutions.
- Broad understanding and curiosity across application security, cloud and Kubernetes security, identity/authorization, and networking.
- Strong written and verbal communication skills for collaborating with technical and non-technical stakeholders.
Nice to have
- Experience with GCC High administration or migration.
- Security experience within manufacturing or operational technology environments.
- Knowledge of ITAR/EAR regulations and CUI marking/handling.
- Capacity to mentor and guide a growing team, setting technical direction for other engineers.
Practical notes
To comply with U.S. Government export regulations (ITAR), applicants must be a U.S. citizen, lawful permanent resident, protected individual, or eligible for required authorizations. Benefits include medical, dental, vision, and life insurance, 401k, flexible vacation, and potential relocation support. Hadrian uses AI-assisted tools in recruiting for efficiency, but all hiring decisions are made by humans.
About the company
Hadrian is a manufacturing technology company that builds autonomous factories for precision aerospace and defense parts. The company uses AI and robotics to automate CNC machining.