Software Engineer, Security
Job description
Software Engineer, Security at Pylon Labs.
About the role
You will own application and product security across what we have already shipped and across every line of work that is still in development, defining the security posture for the platform. You will build tooling that scales security practices past a single practitioner, creating supply chain security, vulnerability management, and secure-by-default libraries that other engineers can use without thinking. You will run the vulnerability lifecycle from initial discovery through triage, validation, prioritization, and remediation while helping to mature the bug bounty and responsible disclosure programs. You will design and implement AI-assisted security workflows, such as agents that scan code, propose fixes, and surface real risk, along with the guardrails that let the rest of the organization use coding agents safely. You will work hand-in-hand with product and engineering teams to ship fixes and to build securely by default, clearly distinguishing between theoretical risk and risk that materially impacts our customers. You will take projects from initial customer request through design, implementation, and production rollout, owning the work end to end. You will help with incident response, including triage, investigation, and coordination of the remediation effort. As the organization grows, you will flex into broader infrastructure work, tackling the same scaling, reliability, and developer velocity challenges that the infrastructure team owns.
Key facts
What you'll do
- Own application and product security across what we have deployed and what is planned, including threat modeling, secure design reviews, and code review focused on authentication, access control, and other high-risk areas.
- Build tooling that scales security past one person, including work in supply chain security, vulnerability management, secure-by-default libraries, and developer-friendly guardrails.
- Run the vulnerability lifecycle end to end, handling triage, validation, prioritization, remediation, and the maturation of bug bounty and disclosure programs.
- Build AI-assisted security workflows, such as agents that scan code, propose fixes, and surface real risk, along with the controls that let the rest of the team use coding agents safely.
- Work hands-on with engineers to ship fixes and help them build securely by default, telling the difference between theoretical risk and risk that actually matters so effort is spent where it counts.
- Take projects from customer request through design and implementation all the way to production deployment, owning the work the entire way.
- Help with incident response, including triage, investigation, and coordination of the fix.
- Flex into broader infrastructure work as we grow, addressing the same scaling, reliability, and developer-velocity problems owned by the infra team.
- Define and drive security standards and best practices that integrate smoothly into the development lifecycle.
- Partner closely with product managers and engineers to ensure security requirements are baked into product specifications from the start.
- Evaluate new technologies and tools to determine how they can improve the security posture without sacrificing developer experience.
- Mentor other engineers on security principles and contribute to the security culture across the organization.
- Track and report on security metrics and key indicators to measure the effectiveness of controls and improvements over time.
- Participate in on-call rotations to respond to security-related incidents and support production systems.
- Continuously learn and adapt to new threat landscapes, feeding insights back into the design and implementation of future features.
Requirements
- You have 3+ years of building production software with security at the center of your work, or you are a strong infrastructure or backend engineer who is transitioning to make security your primary focus.
- You like to build rather than only advise, and you are comfortable turning risk into actual engineering work and shipping fixes to production.
- You know application security fundamentals deeply, including authentication, session management, APIs, secrets handling, and the common vulnerability classes and how to design them out of systems.
- You have practical experience with vulnerability triage, bug bounty programs, responsible disclosure processes, and incident response, and you can balance urgency with pragmatism.
- You are highly effective with AI tools for software development and can manage multiple workstreams at the same time without losing quality.
- You have worked at startups before and are experienced navigating ambiguous environments while still delivering high-quality results.
- You have a growth mindset, actively seek feedback, and are committed to constant self-improvement.
- You are based in San Francisco or you are willing to relocate, you enjoy working in-person with a collaborative team, and you are serious about joining us to build a culture we will all love.
- You are comfortable making technical decisions and taking ownership of complex problems from discovery through resolution.
- You communicate clearly and persuasively, both in writing and verbally, with both technical and non-technical stakeholders.
Nice to have
- You have direct experience with our current technology stack, including React, Golang, GraphQL, and AWS.
- You have shipped agentic products in production and understand the unique security and operational challenges they introduce.
Practical notes
This role is based in San Francisco and requires in-person presence. You must be willing to relocate to San Francisco if you are not already located there.