Lead Security Engineer
Job description
About the role
We are looking for a highly experienced Lead Security Engineer to help establish and strengthen the security foundation of our innovative entertainment platform. This is a hands-on technical leadership role where you will set the strategic direction for security across our product and infrastructure, work directly in the code and cloud environments, and lead the security team as it grows. You will be responsible for designing and implementing security measures that protect our platform, users, and data, ensuring that security best practices are embedded into every aspect of our development and operational processes. This role offers an exciting opportunity to influence the security posture of a rapidly growing company at the forefront of AI music and consumer entertainment, working closely with engineering, product, and executive teams to build a secure, scalable, and resilient platform.
Key facts
What you'll do
- Own the security architecture and develop the security roadmap for our product and cloud environments, including threat modeling to identify and prioritize areas of focus.
- Lead efforts to elevate our application security practices by securing the software development lifecycle, establishing code review guardrails, managing dependencies and secrets, and implementing pre-production security testing protocols.
- Drive cloud security initiatives, including defining and enforcing IAM policies, implementing least-privilege access controls, designing account structures, establishing network boundaries, and controlling data access to safeguard sensitive information.
- Lead incident response efforts by participating in an on-call rotation, acting as the senior responder during security incidents, and coordinating internal and external communications to mitigate risks and recover swiftly.
- Mentor and develop the security team, helping to shape operational processes, security policies, and best practices across the organization.
- Collaborate closely with engineering, product, and operations teams to embed security into product development, deployment, and maintenance workflows.
- Develop and maintain security policies, standards, and procedures aligned with organizational goals and industry best practices.
- Conduct regular security assessments, vulnerability scans, and audits to identify potential weaknesses and implement effective mitigation strategies.
- Stay informed about emerging security threats, vulnerabilities, and technological advancements to continuously improve our security posture.
- Drive security awareness initiatives, including training and education programs, to foster a security-conscious culture within the organization.
- Establish metrics and reporting mechanisms to monitor security performance and compliance, ensuring transparency and accountability.
- Lead efforts to implement security controls for cloud infrastructure, including network segmentation, identity management, and data protection measures.
- Work with legal and compliance teams to ensure adherence to relevant regulations and standards, including data privacy laws and industry-specific requirements.
- Participate in product design reviews to ensure security considerations are integrated from the outset.
- Manage relationships with external security vendors and consultants as needed to supplement internal capabilities.
- Contribute to the development of incident response plans, disaster recovery procedures, and business continuity strategies.
- Support the onboarding and training of new security team members, fostering a collaborative and high-performing security organization.
Requirements
- Over 10 years of experience in security engineering, with a proven track record of designing and implementing security solutions at scale.
- Deep expertise in at least two of the following areas: application security (AppSec), cloud/infrastructure security, and incident response (IR), with credible knowledge in the third area.
- Demonstrated ability to create security capabilities from scratch, set strategic security directions, and operationalize security programs effectively.
- Strong cross-functional partnership skills, with the ability to work collaboratively with engineering, product, legal, and executive teams to enable secure product development and deployment.
- Hands-on experience with security architecture, threat modeling, security testing, and vulnerability management.
- Experience leading incident response efforts, managing security incidents, and coordinating with internal teams and external partners.
- Excellent communication skills, capable of articulating complex security concepts to technical and non-technical audiences.
- Proven leadership in building, mentoring, and growing security teams in fast-paced environments.
- Familiarity with cloud platforms such as AWS, GCP, or Azure, and related security controls and best practices.
- Knowledge of identity and access management (IAM), network security, data protection, and encryption technologies.
- Ability to prioritize and manage multiple projects simultaneously while maintaining attention to detail.
- Strong problem-solving skills and a proactive approach to identifying and mitigating risks.
- Experience working in a startup or high-growth environment is a plus.
Nice to have
- Prior experience working on consumer products at scale, especially in entertainment or media.
- Knowledge of AI/ML security issues, including abuse mitigation and model security exposure.
- Previous experience as an early or founding security hire in a startup or emerging technology company.
- Familiarity with compliance standards such as SOC 2, ISO 27001, GDPR, or CCPA.
- Experience working with security tools such as SIEM, endpoint detection, and vulnerability scanners.
Skills & tools
- Security architecture and threat modeling
- Cloud security (IAM, network security, data access controls)
- Application security practices and secure SDLC implementation
- Incident response and management
- Vulnerability assessment and penetration testing
- Security testing tools and frameworks
- Cross-functional collaboration and communication
- Leadership and team development
- Familiarity with cloud platforms such as AWS, GCP, or Azure
- Knowledge of encryption, data protection, and identity management systems
Practical notes
- Applicants must be eligible to work in the US.
- This role requires working onsite at our Boston office.
- The position offers a competitive salary range of $275,000 to 395,000 along with a comprehensive benefits package, including equity, health insurance, paid time off, parental leave, and other perks.
- The company values diversity and is committed to equal opportunity employment practices.
- Candidates should be prepared to participate in an interview process that may include technical assessments, behavioral interviews, and team fit evaluations.
- The role involves working closely with multiple teams and requires strong collaboration skills.
- Candidates with a passion for music, entertainment, and innovative technology are encouraged to apply.