Lead the security operations at Salient, building a repeatable security operating system in a fast-paced AI-driven environment.
Posted by employer 3 days ago
First seen on Joblaze 1 day ago
Last verified on the company career page 1 day ago
Skills & Technologies
What you'll build
Must have
Nice to have
Practical constraints
AI in the day-to-day
We are building modern AI into regulated industries where precision, reliability, and performance matter.
Not disclosed in this posting: compensation, years of experience, visa sponsorship.
Benefits
Joblaze summary
The Lead Security Engineer at Salient is responsible for developing a comprehensive security operating system, focusing on compliance operations, vulnerability management, and incident response. This role requires strong software engineering skills, particularly in securing cloud infrastructure and identity access management. Ideal candidates are experienced professionals who can navigate risk and communicate effectively with leadership, particularly those with a background in financial services or regulated environments. Salient emphasizes a fast-paced work culture, with a commitment to integrating AI into financial services.
Joblaze insights
Quick facts
From the original posting
We are:
Backed by a16z and Y Combinator, with $75M raised in Series A funding
Actively expanding into new financial services segments
Building together in person in San Francisco
We're hiring a hands-on Lead Security Engineer to build a repeatable security operating system for Salient. This is a Staff-level individual contributor role reporting to senior leadership. You will be our single dedicated security hire, with reserved support from infrastructure, IT, and People Operations.
You will own compliance operations, boundary testing, access and vulnerability management, detection and response, and the automation that makes all of it repeatable and provable. We'll sequence this work by risk together. We don't expect anyone to arrive as an expert in every area below.
• The operating procedure for SOC 2, PCI, enterprise security questionnaires, and bank-specific security requirements, keeping implementation, approval, submission, and acceptance separate.
• Security testing across cloud/IAM, application, payment, and AI boundaries, including synthetic tests covering recordings, transcripts, logs, tools, storage, and providers.
• Investigation of access anomalies.
• Stronger IAM/PAM controls and monitoring.
• Network and vulnerability scanning, with every finding tracked through service-owner remediation and retest, or an authorized exception.
• Incident runbooks, useful detections, and proven handoffs between security, service teams, and backup personnel.
• Automation for security controls and evidence: tested evidence connectors, asset reconciliation, obligation tracking, and claim-review workflows.
• You own outcomes end to end and ship weekly with a small team, deciding with incomplete information.
• You're a software engineer first: you write production-quality code and build tested tooling and automation.
• You have hands-on experience securing cloud infrastructure and identity and access (IAM/PAM), including investigating suspicious access.
• You prioritize by real risk, are clear about what isn't covered, and can explain tradeoffs to leadership.
• Experience operating SOC 2, PCI, or bank security controls and producing audit evidence.
• Experience leading SOC 2 or PCI audits with external auditors.
• Experience with detection engineering, incident response, or vulnerability management.
• Interest or experience in threat-modeling AI systems, LLM tool use, or data flows through model providers.
• Clear writing for runbooks, questionnaires, and customer security reviews, and a track record of partnering with engineering teams.
• Experience with financial services, payment data, or other regulated consumer data.
Standard company text repeated across Salient's postings is omitted here.