Haystack
← Back to Jobs
Full time
Technology
HU

Senior Security Engineer

HudSan Francisco🇺🇸United StatesPosted Sep 9, 2026

Why This Role Stands Out

This is an exceptional opportunity to establish and lead the security program at a rapidly growing AI infrastructure company, directly impacting the security of billions in data assets. If you are a proactive Security Engineer eager to own a comprehensive security roadmap and drive customer trust, you will thrive in this impactful role. Apply now to shape the future of AI security!

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
On Site
Location
San Francisco, United States
Posted
3 weeks ago
AWSSOC 2REST

Job Description

About HUD

HUD's mission is to build reliable, fair and open infrastructure for AI data. We want data to be valuable for the people who create it and trustworthy for the labs that train on it. Our team is a quickly growing group of researchers, engineers and operators building the economy that shapes what AI will become. Backed by $16M from top VCs and YC (W25), our marketplace and platform are used by startups, Fortune 500 companies and frontier labs.

About the role

We’re looking for a Security Engineer to own and build HUD’s security program as our first full-time security hire. You will work closely with the rest engineering to secure our product, cloud infrastructure, data workflows, and internal systems. You’ll also lead incident response, SOC 2, and customer trust.

We are securing up to billions in data assets and are looking for someone who can lead security such that our infrastructure is never compromised.

Responsibilities

  • Lead detection and incident response from signal to alert to postmortem

  • Own HUD’s security roadmap across product security, cloud and infrastructure security, corporate security, incident response, and compliance

  • Secure HUD’s APIs, platform, and data systems through threat modeling, design and code reviews, authentication and authorization controls, secrets management, etc.

  • Build monitoring, detection, and incident-response capabilities; lead investigations and postmortems; and turn incidents and emerging threats into durable improvements

  • Own SOC 2 and customer trust, including control design, security questionnaires, policy management, vendor reviews, and audits

  • Partner with legal, commercial, engineering, and operations to translate customer contracts and data-license requirements into enforceable controls for data access, provenance, permitted use, retention, deletion, isolation, and auditability

Experience

You may be a good fit if you have:

  • Strong security engineering fundamentals and hands-on experience across multiple areas such as infrastructure security, detection and response, identity, etc.

  • Experience leading security incidents end-to-end, from detection and containment through root-cause analysis and follow-up engineering work

  • Experience implementing or operating SOC 2 or a comparable security framework, including translating requirements into real technical and operational controls

  • High agency and sound judgment—you can identify and prioritize the risks that matter, make pragmatic decisions under uncertainty, and personally drive implementation

  • Strong communication skills for working with founders, engineers, operations, legal, auditors, customers, and external partners

Strong candidates may also:

  • Experience as an early security hire or building a security program from scratch at a fast-growing startup

  • Experience securing AI/ML infrastructure, agent execution environments, data platforms, developer tools, or other systems that run untrusted code or process sensitive data

  • Experience protecting licensed, proprietary, or customer-provided data and operationalizing contractual requirements around access, use, retention, and deletion

  • Experience finding CVEs, creating security tooling on GitHub, or with bug bounty programs

  • CVEs, or have created security tooling on GitHub, have conference talks, bug bounty history, or blog posts about incidents/something security related they've done that would also be good

  • OSCP, AWS Security Specialist, OSWE, CKS, or GIAC hands on certifications

We prioritize technical aptitude and learning potential over years of experience. Motivated candidates are encouraged to apply even if they don't meet all criteria.

Team & company details

  • Team Size: ~25 people currently, mostly full-time in-person, but some remote.

  • Our team: Our team includes 4 International Olympiad medalists (IOI, ILO, IPhO), serial AI startup founders, and researchers with publications at ICLR, NeurIPS, etc.

  • Company stage: We have 8 figures in funding and are scaling profitably and quickly to meet very strong demand.

Logistics

  • Employment: Full-time.

  • Location: We have offices in San Francisco or Singapore but are open to remote candidates who can work hours that 70-80% overlap with either San Francisco or Singapore time zones.

  • Visa Sponsorship: We provide support for relocation and visas for strong full-time candidates to the US or Singapore.

  • Timeline: Applications are rolling. The process is 2 technical interviews and a 2-3 day work trial.

What we offer

  • Competitive compensation

  • 100% covered top-of-the-line medical, dental, and vision from Blue Shield of CA (US employees)

  • Lunch and dinner when you’re in the office (in-office employees)

  • Company-wide holiday break (Christmas Eve to New Year’s Day) on top of PTO and paid holidays

  • Other perks including an Equinox membership, 401k, and commuter benefits (US employees)

  • Unlimited* access to tokens for ChatGPT, Claude Code, Cursor, etc. *By unlimited, we mean no one on our token usage leaderboard has ever hit a limit. So we have no idea what the limit is.

Compensation

Actual offers are adjusted for experience and location, but our base salary bands are

  • San Francisco (and other major US cities): $175,000 - $260,000

  • Singapore: $130,000 - $195,000

  • Rest of world: $105,000 - $195,000

Due to high volume, we may not actively respond to every application, but feel free to contact us at recruiting@hud.so or elsewhere if we missed your application!

Similar jobs