Product Security Engineer

Posted Yesterday
Hiring Remotely in USA
Remote
180K-400K Annually
Entry level
Artificial Intelligence • Marketing Tech • Software • Analytics
The Role
Own Hightouch’s application security posture as the first dedicated security hire. Secure multi-tenant systems, sub-tenant access controls, distributed architecture, internet-facing APIs, and multi-region, multi-cloud infrastructure. Lead threat modeling, compute isolation, rate limiting, abuse detection, authorization, privacy controls, and security program initiatives. The role is highly hands-on, emphasizing code-level fixes, architecture influence, roadmap ownership, and collaboration with engineering teams.
Summary Generated by Built In
About the Role

This is our first dedicated security hire, and it's a rare chance to define the function from the ground up. You'll own Hightouch's application security posture end-to-end. We have strong engineering fundamentals and a solid foundation; now you'll shape what security looks like here as we scale from 70 to 140+ engineers.

This is a hands-on, high-autonomy role. You'll spend most of your time in the codebase, not in meetings. You’ll be solving hard problems at the intersection of security and distributed systems:

  • Multi-tenant isolation on a system running ~1M data syncs per day and ingesting 100K+ events/sec

  • Sub-tenant access control - for multi-team and multi-brand use cases, requiring differentiated access to configuration and data

  • Security architecture - Build and refine our frameworks for compute isolation and perform threat modeling and hardening of new products

  • Internet-facing APIs - Our high-throughput, internet-facing architecture services customer data at scale. You’ll improve our rate limiting, abuse detection, and granularity of access control

  • Multi-Region and Multi-Cloud - Supporting our multi-region and multi-cloud backend, including extending it to launch Hightouch on in new regions to support data residency requirements of our global customer base

You'll own your roadmap. We're not looking for someone to run a checklist — we're looking for someone who can look at our architecture, identify the highest-leverage problems, and go fix them.

We are looking for talented, intellectually curious, and motivated individuals who are interested in tackling the problems above. This is a senior role, but we focus on impact and potential for growth more than years of experience. The salary range for this position is $180,000 - $400,000 USD per year, which is location independent in accordance with our remote-first policy. We also offer meaningful equity compensation. 

About You

You’ve been an early security hire at a SaaS company before and moved the needle on how they approach security. You can read application code, threat model a distributed system, and ship production fixes. You have significant distributed systems expertise so that you can understand and influence what is being built by the product teams and influence from a place of trust.

Experience that's relevant:

  • Being an early security hire (first 1-3) at a SaaS or data infrastructure company

  • Securing multi-tenant platforms: tenant isolation, authorization models, etc

  • Cloud security on systems that span more than one cloud and operate against customer-owned accounts

  • Design and build of data infrastructure as an early engineer, not just a user. You helped secure it from early design or during major redesigns. You understand how it scales and how it’s secured

  • Privacy-adjacent security (PII handling, data residency, GDPR/CCPA technical controls)

We don't care about certifications. We care about what you've built.

Interview Process
  1. Recruiter Screen [30m] - Introductory mutual fit assessment

  2. Security Architecture Interview [60m] - Threat model discussion of a real-ish system, followed by a systems design exercise

  3. Core interview [90m] - deep dive on distributed systems knowledge

  4. Hiring Manager Interview [60m] - What you've built in the past, how you work

  5. Security Program Interview [60m] with Head of Engineering — How you've run security programs in practice: bug bounty, pentest engagements, working with external researchers, and partnering across engineering to drive adoption.

Skills Required

  • Experience as an early security hire, ideally among the first one to three security employees, at a SaaS or data infrastructure company
  • Ability to read application code, threat model distributed systems, and ship production security fixes
  • Significant distributed systems expertise
  • Experience securing multi-tenant platforms, including tenant isolation and authorization models
  • Cloud security experience across multiple clouds and customer-owned accounts
  • Experience designing and building data infrastructure as an early engineer
  • Understanding of data infrastructure scalability and security
  • Experience with privacy-adjacent security, including PII handling, data residency, and GDPR or CCPA technical controls
  • Experience running security programs, including bug bounty programs, penetration testing engagements, external researcher collaboration, and cross-engineering adoption
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
400 Employees
Year Founded: 2018

What We Do

Hightouch provides a warehouse-native customer data and AI marketing platform for enterprise teams. It lets data teams retain control of their data, access, and infrastructure, while marketers and business users build audiences, launch campaigns, and personalize customer experiences. Its composable customer data platform brings together behavioral events, customer profiles, and integrations with marketing destinations to activate data and support data-driven campaigns.

Similar Jobs

Cleo Logo Cleo

Security Engineer

Cloud • eCommerce • Information Technology • Professional Services • Software
Remote or Hybrid
US
500 Employees
160K-180K Annually

DigitalOcean Logo DigitalOcean

Security Engineer

Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
In-Office or Remote
Seattle, WA, USA
1400 Employees
141K-176K Annually

DigitalOcean Logo DigitalOcean

Security Engineer

Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Remote
United States
1400 Employees
141K-176K Annually

CrowdStrike Logo CrowdStrike

Engineer II, Software Assurance, Product Security (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
100K-145K Annually

Similar Companies Hiring

Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account