Lead Security Engineer
Job Description
Salient is looking for a Lead Security Engineer to help build a repeatable security operating system. This is a staff-level individual contributor role where you will own security outcomes end to end, combining engineering execution with compliance and operational rigor. If you enjoy shipping tested automation and tightening controls across cloud, identity, and application boundaries, this onsite San Francisco position gives you the scope to drive measurable improvements.
Location: San Francisco, CA (onsite)
Salary: USD $200,000 - $300,000 per year
Hours: typically around 60 hours per week, beginning at 8:00 AM; four days collaborating in person at the San Francisco office
What you’ll do
Own the operating procedure and execution for security and compliance programs, while keeping implementation, approval, submission, and acceptance clearly separated. You will be responsible for SOC 2 and PCI, enterprise security questionnaires, and bank-specific security requirements.
- Run security testing across cloud/IAM, application, payment, and AI boundaries, including synthetic tests for recordings, transcripts, logs, tools, storage, and providers
- Investigate access anomalies and improve visibility where it matters
- Strengthen IAM/PAM controls and monitoring
- Perform network and vulnerability scanning, ensuring every finding is tracked through service-owner remediation and retesting, or handled via an authorized exception
- Develop incident runbooks, useful detections, and handoffs between security, service teams, and backup personnel
- Automate security controls and evidence with tested evidence connectors, asset reconciliation, obligation tracking, and claim-review workflows
What we’re looking for
- You take ownership of outcomes end to end and can ship weekly with a small team, making decisions with incomplete information
- You are a software engineer first, producing production-quality code and building tested tooling and automation
- You have hands-on experience securing cloud infrastructure and identity and access (IAM/PAM), including investigating suspicious access
- You prioritize by real risk, are clear about what is not covered, and can explain security tradeoffs to leadership
Benefits
- Medical, dental, and vision coverage
- Generous 401(k)
- Catered lunches
Nice to have
- Experience operating SOC 2, PCI, or bank security controls and producing audit evidence
- Experience leading SOC 2 or PCI audits with external auditors
- Experience with detection engineering, incident response, or vulnerability management
- Interest or experience in threat-modeling AI systems, LLM tool use, or data flows through model providers
- Clear writing for runbooks, questionnaires, and customer security reviews, plus a track record partnering with engineering teams
- Experience with financial services, payment data, or other regulated consumer data