Lead Security Engineer
Job Description
Salient is hiring a Lead Security Engineer in San Francisco to help build a repeatable security operating system. This is a staff-level individual contributor role focused on compliance operations, boundary testing, access and vulnerability management, detection and response, and security automation.
Key Responsibilities
- Own the operating procedure for SOC 2, PCI, enterprise security questionnaires, and bank-specific security requirements, keeping implementation, approval, submission, and acceptance clearly separated.
- Perform security testing across cloud and IAM, application, payment, and AI boundaries, including synthetic testing for recordings, transcripts, logs, tools, storage, and providers.
- Investigate access anomalies and drive follow-through on findings.
- Improve IAM and PAM controls and associated monitoring.
- Conduct network and vulnerability scanning, ensuring every finding is tracked through service-owner remediation and retest, or handled via an authorized exception.
- Build and maintain incident runbooks, develop useful detections, and document proven handoffs between security, service teams, and backup personnel.
- Automate security controls and evidence, including tested evidence connectors, asset reconciliation, obligation tracking, and claim-review workflows.
Required Qualifications
- End-to-end ownership of outcomes and the ability to ship weekly with a small team, making decisions with incomplete information.
- Software engineering foundation: ability to write production-quality code and develop tested tooling and automation.
- Hands-on experience securing cloud infrastructure and identity and access (IAM/PAM), including investigating suspicious access.
- Risk-based prioritization, clarity about what is not covered, and the ability to explain tradeoffs to leadership.
Preferred / Nice to Have
- Experience operating SOC 2, PCI, or bank security controls and producing audit evidence.
- Experience leading SOC 2 or PCI audits with external auditors.
- Experience with detection engineering, incident response, or vulnerability management.
- Interest or experience in threat-modeling AI systems, LLM tool use, or data flows through model providers.
- Clear writing for runbooks, questionnaires, and customer security reviews, including a track record of partnering with engineering teams.
- Experience with financial services, payment data, or other regulated consumer data.
Compensation
USD 200,000 - 300,000 per year
Benefits
- Medical, dental, and vision coverage
- Generous 401(k)
- Catered lunches
Location and Work Hours
- Location: San Francisco, CA (onsite)
- Typical hours: around 60 hours per week
- Start time: 8:00 AM
- In-person collaboration: four days per week at the San Francisco office