Security Engineer

San Francisco, Palo Alto, Toronto

Posted 2mo ago

Job Location

San Francisco, Palo Alto, Toronto

Tech Stack

Remote Work Policy

On-site

Categories

Applied AI Engineer

About the job

As a Security Engineer at HeyGen, you will own the security posture of one of the fastest-growing AI companies in the world. You will partner directly with engineering teams to ship secure features, harden our cloud infrastructure, and build the compliance and trust programs that unlock enterprise deals. This is a high-impact, high-autonomy role for an engineer who thinks in threat models and ships code.

Responsibilities

  • Partner with engineering teams as an embedded security expert, writing code, reviewing architectures, and building secure application features and infrastructure components.
  • Design and implement automated fraud detection systems to mitigate platform abuse, credential stuffing, and payment fraud, building real-time monitoring and rapid-response remediation workflows.
  • Own the strategy and execution for hardening AWS/Python infrastructure, building and running a robust vulnerability management program.
  • Serve as the point person for AI and agentic system security, ensuring strong security controls for AI agent products.
  • Oversee SOC 2 compliance operations and annual audit cycles, evaluating and roadmapping future certifications like ISO 27001.
  • Provide oversight for platform abuse and content moderation, and serve as the escalation point for IT security incidents.

Requirements

  • Strong software engineering background with hands-on Python and AWS experience.
  • Demonstrated experience securing cloud infrastructure and applications, including vulnerability management, network security, IAM, and secrets management.
  • Familiarity with GRC frameworks and compliance programs (SOC 2, ISO 27001, or equivalent).
  • Excellent communication skills, able to translate technical and compliance requirements effectively.
  • Comfortable with ambiguity and rapid scale, with strong prioritization skills.
  • Experience with modern security tooling such as Drata, Infisical, or Bugcrowd is a plus.

Benefits

  • Opportunity to work on novel security engineering challenges at a fast-growing SaaS company.
  • A security philosophy focused on building guardrails for rapid development.
  • Mature tooling from day one, including Drata, Infisical, and a private bug bounty program.
  • Autonomy and ownership to shape the company's security roadmap.

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.