Founding Security Infrastructure Engineer
As the Founding Security Infrastructure Engineer, you will be the company's first dedicated security hire, responsible for building and owning the entire security and privacy program from the ground up.This is a true 0-to-1 role spanning cloud infrastructure security, identity and access management, compliance, AI system controls, and protection of sensitive consumer data across a complex AI voice platform.You will be deeply hands-on — implementing systems and controls yourself, not only defining policy — and will use strong judgment to prioritize high-impact work without slowing down a rapidly scaling engineering team.You will partner closely with engineering leadership and serve as the security voice in enterprise customer conversations.Key ResponsibilitiesBuild and own the security program end-to-end, including cloud infrastructure security, IAM, secrets management, encryption, and data isolation across AWS.Lead SOC 2 Type II compliance — manage the observation period, coordinate with auditors and external vendors, and ensure adherence to internal security policies.Design and implement controls governing how internal AI agents access systems, including auditing, protection against unauthorized access, and company-wide AI use policies.Define and enforce permission controls and data protection for sensitive customer data — determining what is tokenized or anonymized and who has access to what — without impeding development velocity.Secure infrastructure-as-code and deployment pipelines, embedding security guardrails into Terraform, Kubernetes, and CI/CD workflows.Drive application security practices across the AI voice platform, including secure design reviews and remediation of identified vulnerabilities.Lead customer-facing security reviews, questionnaires, and due-diligence conversations with enterprise buyers.Scope and manage third-party penetration testing, and track findings through to resolution.Evaluate and approve external tools and vendors based on their security posture.Establish the security roadmap and clearly communicate risk, trade-offs, and decisions to engineering and executive stakeholders.