{"schemaVersion":"jobsearcher.job.v1","id":"6fc721f93cb672c3a6d6cc6c","url":"https://jobsearcher.com/jobs/6fc721f93cb672c3a6d6cc6c","canonicalUrl":"https://jobsearcher.com/jobs/6fc721f93cb672c3a6d6cc6c","title":"Founding Security Engineer","description":"About Schemata\n\nAt Schemata, we are transforming the $400 B virtual‑training and simulation market by fusing 3D computer vision, neural rendering and large multimodal models inside highly regulated industries. Our platform delivers photorealistic, intelligent 3D experiences, demanding robust spatial reasoning, high‑performance data pipelines and seamless integration between traditional graphics and AI‑driven perception.\n\nCore Responsibilities\n\nOwn the security architecture: define and implement how identity, authorization, tenancy isolation, encryption and audit logging work across our platform, and review designs before they become expensive to change\n\nRed team our AI systems: probe the LLM and spatial reasoning surfaces the way an adversary would through prompt injection, jailbreaks, tool-use and agent abuse, retrieval and training data poisoning, model extraction, and the failure modes specific to grounding models in customer documents and 3D scenes..\n\nImplement continuous security monitoring: own the security pipeline (SAST/DAST, dependency and container scanning, secrets detection, IaC policy checks) and the vulnerability management that follows from it.\n\nRun detection and response: own the security monitoring pipeline day to day. Triage, investigation, containment and post-incident review. Be the person who gets paged, and make each incident produce a durable change: a new detection, a closed gap, a corrected runbook.\n\nMake sure we’re compliant: implement and evidence NIST SP 800-53 and SOC 2 controls, support FedRAMP and ATO efforts, and manage POA&M tracking and remediation.\n\nEssential Skills & Experience\n\nStrong experience in security engineering, application security or cloud security with hands-on implementation ownership, not purely policy or GRC.\n\nDeep AWS security expertise: IAM design, VPC and network controls, KMS, GuardDuty/Security Hub, and least-privilege at scale.\n\nStrong applied knowledge of application security: authN/authZ design, common vulnerability classes, secure code review, threat modeling.\n\nAbility to write real code (Python) to automate controls, evidence collection and tooling.\n\nWorking knowledge of at least one major compliance framework (NIST 800-53/RMF, FedRAMP, SOC 2, or ISO 27001) and the practical work of evidencing controls.\n\nContainer and Kubernetes security experience: image hardening, runtime policy, supply chain integrity.\n\nEnough backend or infrastructure ability to be a genuine extra pair of hands outside security: shipping a service, writing a Terraform module, fixing a CI pipeline.\n\nClear communication with non-security engineers and with customer security teams alike.\n\nNice to Have\n\nFederal authorization experience: running or supporting an ATO, working with AOs and ISSOs, FISMA continuous monitoring.\n\nCertifications such as CISSP, OSCP, CCSP, CAP, or GIAC equivalents.\n\nExperience securing ML/AI systems: model supply chain, data governance, prompt injection and inference abuse.\n\nFamiliarity with DISA STIGs, NIST 800-171, CMMC or CUI handling requirements.\n\nExperience being the first security hire at a startup and building the function from zero.\n\nDefense, aerospace, energy or other regulated‑industry experience; active or ability to obtain U.S. security clearance.\n\nWhy Join Us?\n\nCompetitive salary that reflects your experience and track record\n\nMeaningful equity stake in a high-growth, venture-backed defense tech startup, so you share in the upside you help create\n\nComprehensive health coverage: medical, dental, and vision insurance\n\n401(k) plan\n\nPaid parental leave\n\nHigh visibility and real impact: Collaborate with world-class engineers and researchers in a high-ownership environment.","company":"Schemata","rawCompany":"schemata","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-09-10T11:19:39.592Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Founding Security Engineer","description":"About Schemata\n\nAt Schemata, we are transforming the $400 B virtual‑training and simulation market by fusing 3D computer vision, neural rendering and large multimodal models inside highly regulated industries. Our platform delivers photorealistic, intelligent 3D experiences, demanding robust spatial reasoning, high‑performance data pipelines and seamless integration between traditional graphics and AI‑driven perception.\n\nCore Responsibilities\n\nOwn the security architecture: define and implement how identity, authorization, tenancy isolation, encryption and audit logging work across our platform, and review designs before they become expensive to change\n\nRed team our AI systems: probe the LLM and spatial reasoning surfaces the way an adversary would through prompt injection, jailbreaks, tool-use and agent abuse, retrieval and training data poisoning, model extraction, and the failure modes specific to grounding models in customer documents and 3D scenes..\n\nImplement continuous security monitoring: own the security pipeline (SAST/DAST, dependency and container scanning, secrets detection, IaC policy checks) and the vulnerability management that follows from it.\n\nRun detection and response: own the security monitoring pipeline day to day. Triage, investigation, containment and post-incident review. Be the person who gets paged, and make each incident produce a durable change: a new detection, a closed gap, a corrected runbook.\n\nMake sure we’re compliant: implement and evidence NIST SP 800-53 and SOC 2 controls, support FedRAMP and ATO efforts, and manage POA&M tracking and remediation.\n\nEssential Skills & Experience\n\nStrong experience in security engineering, application security or cloud security with hands-on implementation ownership, not purely policy or GRC.\n\nDeep AWS security expertise: IAM design, VPC and network controls, KMS, GuardDuty/Security Hub, and least-privilege at scale.\n\nStrong applied knowledge of application security: authN/authZ design, common vulnerability classes, secure code review, threat modeling.\n\nAbility to write real code (Python) to automate controls, evidence collection and tooling.\n\nWorking knowledge of at least one major compliance framework (NIST 800-53/RMF, FedRAMP, SOC 2, or ISO 27001) and the practical work of evidencing controls.\n\nContainer and Kubernetes security experience: image hardening, runtime policy, supply chain integrity.\n\nEnough backend or infrastructure ability to be a genuine extra pair of hands outside security: shipping a service, writing a Terraform module, fixing a CI pipeline.\n\nClear communication with non-security engineers and with customer security teams alike.\n\nNice to Have\n\nFederal authorization experience: running or supporting an ATO, working with AOs and ISSOs, FISMA continuous monitoring.\n\nCertifications such as CISSP, OSCP, CCSP, CAP, or GIAC equivalents.\n\nExperience securing ML/AI systems: model supply chain, data governance, prompt injection and inference abuse.\n\nFamiliarity with DISA STIGs, NIST 800-171, CMMC or CUI handling requirements.\n\nExperience being the first security hire at a startup and building the function from zero.\n\nDefense, aerospace, energy or other regulated‑industry experience; active or ability to obtain U.S. security clearance.\n\nWhy Join Us?\n\nCompetitive salary that reflects your experience and track record\n\nMeaningful equity stake in a high-growth, venture-backed defense tech startup, so you share in the upside you help create\n\nComprehensive health coverage: medical, dental, and vision insurance\n\n401(k) plan\n\nPaid parental leave\n\nHigh visibility and real impact: Collaborate with world-class engineers and researchers in a high-ownership environment.","datePosted":"2026-09-10T11:19:39.592Z","dateModified":"2026-09-10T11:19:39.592Z","hiringOrganization":{"@type":"Organization","name":"Schemata","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"6fc721f93cb672c3a6d6cc6c"},"url":"https://jobsearcher.com/jobs/6fc721f93cb672c3a6d6cc6c"}}