Security Engineer (Senior/Staff) - VC Backed Startups at Signalfire — Remote
Full job description
# Join SignalFire’s Talent Network for Security Engineer (Senior/Staff) Roles at VC-Backed Startups
🛑 This is not an application for a specific job. Instead, this is a way to get on the radar of VC-backed startups that are actively hiring Security Engineering talent. If you have any questions, please direct inquiries to talentnetwork@signalfire.com.
We’re looking to connect with exceptional Senior and Staff Security Engineers who are excited about building secure products, protecting critical systems, and establishing scalable security practices at high-growth startups.
## Who Should Join?
We’re looking for engineers who are:
✔ Passionate about building secure, resilient products and infrastructure ✔ Experienced in identifying vulnerabilities and translating security risks into practical engineering solutions ✔ Excited to establish security programs and technical standards in fast-moving startup environments ✔ Comfortable partnering across engineering, product, infrastructure, and business teams ✔ Interested in balancing strong security controls with product velocity and customer needs
## Typical Roles & Responsibilities
- Design and implement security controls across applications, cloud infrastructure, internal systems, and development environments
- Conduct architecture reviews, threat modeling, code reviews, and security assessments for new products and features
- Identify, prioritize, and remediate vulnerabilities across the technology stack
- Embed security into the software development lifecycle through secure coding standards, automated testing, and developer tooling
- Build and improve detection, monitoring, incident response, and vulnerability management capabilities
- Partner with engineering and infrastructure teams to strengthen cloud, container, network, identity, and access security
- Lead or support the investigation and remediation of security incidents
- Develop reusable security tooling, automation, documentation, and technical guardrails
- Evaluate third-party technologies, integrations, and vendors for potential security risks
- Support customer security reviews, enterprise diligence, and technical compliance requirements
- Help establish security policies and controls aligned with frameworks such as SOC 2, ISO 27001, HIPAA, or PCI DSS
- Mentor engineers and promote shared ownership of security across the organization
## Common Qualifications
While each startup has its own hiring criteria, many Senior and Staff Security Engineer roles in our network look for:
- 5+ years of experience across security engineering, application security, cloud security, infrastructure security, or related disciplines
- Strong software engineering or systems engineering foundation, with proficiency in languages such as Python, Go, Java, JavaScript, TypeScript, or Rust
- Experience securing cloud-native applications and infrastructure on AWS, GCP, or Azure
- Knowledge of common application and infrastructure vulnerabilities, attack techniques, and mitigation strategies
- Experience with threat modeling, secure design reviews, penetration testing, or vulnerability research
- Familiarity with identity and access management, secrets management, encryption, and network security
- Experience building security automation and integrating controls into CI/CD pipelines
- Ability to communicate technical risks and recommendations to engineering teams and business stakeholders
- Strong judgment around risk prioritization, remediation, and balancing security with execution speed
- Experience in venture-backed startups, security-sensitive industries, or rapidly scaling technology companies
## 💡 Technologies You Might Work With:
- Languages & Development: Python, Go, Java, JavaScript, TypeScript, Rust, Bash
- Cloud & Infrastructure: AWS, GCP, Azure, Kubernetes, Docker, Terraform, Linux
- Application Security: SAST, DAST, software composition analysis, dependency scanning, API security, penetration testing
- Detection & Response: SIEM, EDR, intrusion detection, log analysis, incident response, security orchestration
- Identity & Data Security: IAM, SSO, OAuth, SAML, secrets management, key management, encryption
- Security Platforms & Tools: Wiz, Snyk, Semgrep, Burp Suite, CrowdStrike, Okta, Datadog, Splunk
## What Happens Next?
- Submit your application to join SignalFire’s Talent Ecosystem.
- We review applications on an ongoing basis to identify strong candidates.
- If there’s a match, a SignalFire talent partner or a leader from one of our startups may reach out directly.
- No match yet? We’ll keep your profile on file for future Security Engineering roles across our portfolio.
Required skills
- amazon web services
- hipaa
- python
- terraform
- kubernetes
- java
- bash
- ci/cd
- google cloud platform
- rust