Forge
Security Engineer
San Francisco · Vp
Sponsorship not specifiedDetected 77 days ago
Code ReviewRESTData EngineeringLLMsComplianceValuation
About the role
- You'll be Poetic's first dedicated security-focused owner - the person who takes end-to-end ownership of our security posture across the company - in our core product, corporate security, and information security.
- We need to move as fast as possible as securely as possible, and this role is the core of ensuring we can do both at once.
Responsibilities
- Lead product security: threat modeling, secure code review, vulnerability management, and building security into the development lifecycle - not bolting it on after the fact.
- Build internal security tooling that makes secure-by-default behavior the path of least resistance for the rest of the engineering team. Automate the guardrails so engineers don't have to think about them.
- Be the internal voice on security: help the team understand tradeoffs, find paths that satisfy both security and velocity, and communicate clearly with stakeholders at all levels. You'll build trust by being helpful, not by being a gate.
- Work closely with our external IT and Security partners, ensuring smooth day-to-day operations and appropriate controls.
- Own day-to-day compliance programs - including SOC 2 and PCI - as the internal DRI, working closely with our external compliance and audit partners.
- An engineering background - you were a software engineer first and know your way around security. You build things, not just advise on them.
- The soft skills to be a trusted security partner across the company: telling people no with a path forward, finding alternatives that work, and building credibility through helpfulness rather than gatekeeping.
Requirements
- 4+ years of experience spanning product security and other areas.
- Hands-on experience with compliance programs (SOC 2, PCI, or similar) in a fast-moving environment where you couldn't hide behind process alone.
- You May Be a Good Fit If You Have
Nice to have
- Familiarity with the security challenges of multi-tenant AI systems: prompt injection, data isolation, output validation, or the broader trust surface of LLM-powered products.
- Experience with infrastructure security in distributed environments - container orchestration, cross-VPC networking, secrets management at scale, or securing customer-deployed runtimes.
- Familiarity with managing outsourced IT or vendor relationships.
- Experience at an early-stage startup where you built security programs from scratch rather than inheriting them.
- Series A at a $500mm valuation from Founders Fund, Kleiner Perkins, OpenAI, and other investors.
- We're a tight-knit team that works hard because we believe that the nature of how computers work for people will finally change
Skills
- Processes that once took hours can now be completed in a fraction of the time at superhuman quality.
- internal tooling, secure-by-default workflows, and a more secure product from the inside out.
- We see security as enabling us to move faster
Company info
- telling people no with a path forward, finding alternatives that work, and building credibility through helpfulness rather than gatekeeping.
- Comfort operating as a generalist across product security, corporate security, and security tooling - you don't need a narrow specialization to do your best work.
- Nice to Have
- Experience securing systems that handle sensitive data in regulated verticals - banking, insurance, fintech, healthcare - where compliance requirements are especially demanding and customers audit you seriously.
- We are in-person only in San Francisco, CA or New York City, NY
- We have a very talent-dense team: engineers that have built multiple products 0 to 1 at prior fastest growing startups, Financial Services vertical lead at Palantir, Ramp Growth Lead, #1 enterprise AE from Retool, multiple past founders.
- Communicate with customer security teams - ensure and communicate our security posture and architecture to ensure they are at the standards our enterprise customers expect.
This listing is sourced directly from Forge's careers page and normalized into a canonical job model.