{"schemaVersion":"jobsearcher.job.v1","id":"4cf61f273959d7edc5d858c4","url":"https://jobsearcher.com/jobs/4cf61f273959d7edc5d858c4","canonicalUrl":"https://jobsearcher.com/jobs/4cf61f273959d7edc5d858c4","title":"Principal Security Engineer","description":"Head of SecuritySan Francisco (On-site, 5 days/week) · Full-timeAbout the roleCode Red Partners is exclusively partnering with a San Francisco investment firm on its first dedicated security hire.In just a few years they've scaled from launch to managing billions, powered by a very small and exceptionally technical team. Their edge is a research environment built for speed: highly autonomous, permissive by design, and increasingly built and deployed by AI agents rather than by hand. This is a builder's role first and a leadership role second. You will architect and implement the security of their infrastructure yourself. Title and level are flexible for the right person, from senior individual contributor through CISO; what isn't flexible is that this is a hands-on seat.What you'll ownSecure cloud infrastructure on AWS from the ground up: account architecture, IAM and least-privilege at scale, network boundaries, and secrets managementA CI/CD and deployment pipeline that researchers actually want to use, where the secure path is the fast pathInfrastructure-as-code guardrails (Terraform or Pulumi) and policy-as-code, so researchers self-serve inside safe boundariesThe security model for agent-driven development: sandboxing and isolation of code that AI agents generate and deploy, with least-privilege execution and egress controlProtection of the firm's most sensitive intellectual property against exposure and exfiltrationVendor and tooling selection, with a genuine budget to bring in what you needWhat we're looking forYou have personally built and owned secure cloud infrastructure, not just reviewed or assessed it. You've authored the IaC others build on and configured IAM at real scaleDeep AWS, and fluency with modern platform tooling (Terraform/Pulumi, containers, CI/CD)Experience isolating untrusted or agent-generated code (containers, gVisor, Firecracker, egress controls, or similar), or a clear, considered view of how you'd approach itYou've been the sole or founding security owner somewhere, with a budget and no team to hide behindYou work well with researchers and engineers who won't change how they work, and you make security the path of least resistance rather than a gateHigh learning velocity. Securing agent-driven development is a new problem everywhere; we're hiring for how you think, not for a matching résuméDetailsOn-site in San Francisco, five days a week. Relocation supportedCompensation is set at fund level and is highly competitive 7-figures TC annually for the right personThis is a foundational hire with significant autonomy, budget, and direct exposure to firm leadership","company":"Code Red Partners","rawCompany":"code red partners","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-07-23T13:46:13.151Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Principal Security Engineer","description":"Head of SecuritySan Francisco (On-site, 5 days/week) · Full-timeAbout the roleCode Red Partners is exclusively partnering with a San Francisco investment firm on its first dedicated security hire.In just a few years they've scaled from launch to managing billions, powered by a very small and exceptionally technical team. Their edge is a research environment built for speed: highly autonomous, permissive by design, and increasingly built and deployed by AI agents rather than by hand. This is a builder's role first and a leadership role second. You will architect and implement the security of their infrastructure yourself. Title and level are flexible for the right person, from senior individual contributor through CISO; what isn't flexible is that this is a hands-on seat.What you'll ownSecure cloud infrastructure on AWS from the ground up: account architecture, IAM and least-privilege at scale, network boundaries, and secrets managementA CI/CD and deployment pipeline that researchers actually want to use, where the secure path is the fast pathInfrastructure-as-code guardrails (Terraform or Pulumi) and policy-as-code, so researchers self-serve inside safe boundariesThe security model for agent-driven development: sandboxing and isolation of code that AI agents generate and deploy, with least-privilege execution and egress controlProtection of the firm's most sensitive intellectual property against exposure and exfiltrationVendor and tooling selection, with a genuine budget to bring in what you needWhat we're looking forYou have personally built and owned secure cloud infrastructure, not just reviewed or assessed it. You've authored the IaC others build on and configured IAM at real scaleDeep AWS, and fluency with modern platform tooling (Terraform/Pulumi, containers, CI/CD)Experience isolating untrusted or agent-generated code (containers, gVisor, Firecracker, egress controls, or similar), or a clear, considered view of how you'd approach itYou've been the sole or founding security owner somewhere, with a budget and no team to hide behindYou work well with researchers and engineers who won't change how they work, and you make security the path of least resistance rather than a gateHigh learning velocity. Securing agent-driven development is a new problem everywhere; we're hiring for how you think, not for a matching résuméDetailsOn-site in San Francisco, five days a week. Relocation supportedCompensation is set at fund level and is highly competitive 7-figures TC annually for the right personThis is a foundational hire with significant autonomy, budget, and direct exposure to firm leadership","datePosted":"2026-07-23T13:46:13.151Z","dateModified":"2026-07-23T13:46:13.151Z","hiringOrganization":{"@type":"Organization","name":"Code Red Partners","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"4cf61f273959d7edc5d858c4"},"url":"https://jobsearcher.com/jobs/4cf61f273959d7edc5d858c4"}}