Clera
Security Engineer
- Location
- San Francisco, CA, US
- Arrangement
- On-site
- Employment type
- Full-time
- Posted
- 30 September 2026 (today)
Checked todayApplications go to the employer, never to RoleSprint
About this role
ABOUT THE ROLE
This is a founding security engineering position at a fast-growing AI/ML infrastructure company, giving you the opportunity to build the entire security program from scratch. You will work across product, cloud infrastructure, compliance, and incident response to protect a platform used by leading AI labs and large enterprises. This role is critical to maintaining customer trust and safeguarding significant data assets.
WHAT YOU'LL DO
- Lead detection and incident response end-to-end, from initial signal and alert through investigation, postmortem, and durable improvements.
- Own the security roadmap spanning product security, cloud infrastructure, corporate security, incident response, and compliance.
- Secure APIs, platforms, and data systems through threat modeling, design and code reviews, authentication and authorization controls, and secrets management.
- Build and operate monitoring, detection, and incident-response capabilities, and turn emerging threats into engineering improvements.
- Own SOC 2 compliance and customer trust, including control design, security questionnaires, policy management, vendor reviews, and audits.
- Partner with legal, commercial, engineering, and operations to translate data-license requirements into enforceable controls for access, provenance, use, retention, deletion, and auditability.
WHAT WE'RE LOOKING FOR
- 5+ years of hands-on security engineering experience across infrastructure, detection and response, identity, and related domains.
- Proven ability to lead security incidents end-to-end, from containment through root-cause analysis and follow-up engineering work.
- Experience implementing or operating SOC 2 or a comparable security framework and translating requirements into technical controls.
- Experience setting up and operating SIEM and/or XDR tooling for proactive detection.
- Experience securing AI/ML infrastructure, agent execution environments, data platforms, or systems handling untrusted or sensitive data.
- Experience with attack surface management, abuse and fraud detection, and solo incident response.
- Background building a security program or function from scratch, not only working within a large established security organization.
- Experience working with legal, auditors, and customers on security questionnaires, policy management, and audit processes.
- Strong communication skills across engineering, operations, legal, auditors, and customers, with high agency and sound judgment under uncertainty.
- Relevant certifications such as OSCP, AWS Security Specialist, OSWE, CKS, or GIAC, or demonstrated expertise through CVEs, security tooling, or bug bounty work.
- Offensive security experience (bug bounty, pentesting, or red-team work) is a strong plus, as is a systems programming or low-level engineering background.
COMPENSATION & BENEFITS
Very competitive compensation and benefits package, including full medical, dental, and vision coverage for US employees, 401k, commuter benefits, and access to leading AI productivity tools. Visa sponsorship and relocation support are available for strong candidates.
LOCATION
On-site in San Francisco, CA or Singapore. Visa sponsorship and relocation support are provided for strong candidates.
Work location
- San Francisco, CA, US
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Published on Ashby under the board identifier Clera, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 30 September 2026, last checked today. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.