Director, Security Engineering

INSTALILY.AI•San Francisco, CA
•$200,000 - $250,000•Onsite

About The Position

InstaLILY is seeking its first dedicated security leader, reporting directly to the CEO, to own security for their AI agents that operate within sensitive enterprise systems. This role is crucial as security is a core part of the product and a key factor in closing enterprise deals. The company has a strong foundation with existing SOC 2 Type II and HIPAA compliance, and an ongoing Okta rollout. The ideal candidate will take this foundation and build a proactive, evidence-backed security program. This is a player-coach role, requiring a blend of hands-on coding (30-50%), threat modeling, architecture review, cloud hardening, and customer-facing security engagements (25-30%).

Requirements

  • 8+ Years in Security Engineering, including hands-on ownership of a security or compliance program at a SaaS company (ideally Series B-C stage).
  • Hands-On Cloud and AppSec Depth: Strong in GCP and AWS IAM, Kubernetes, and infrastructure-as-code (Terraform/OpenTofu). Ability to threat-model multi-tenant, multi-cloud architectures and review code.
  • A Builder, Not Just a Reviewer: Proficient in writing production-quality Python or TypeScript for automation, tooling, and fixes.
  • End-to-End SOC 2 Type II Ownership: Experience running SOC 2 Type II programs, including audits, controls, evidence, and GRC tooling.
  • Credibility With Enterprise CISOs: Experience leading customer security reviews, questionnaires, and audits.
  • Real LLM Experience: Experience building with LLMs and understanding agentic systems' threat models.
  • Player-Coach Mindset: Energized by hands-on work; tech-lead or program-lead experience is sufficient.
  • In-person availability: 5 days/week in New York or San Francisco office.

Nice To Haves

  • Experience building a security function from scratch at a Series B/C SaaS company and taking it through SOC 2 Type II.
  • Experience securing an LLM or agent product in production (prompt injection, agent authorization, OWASP Top 10 for LLMs).
  • Experience leading a real incident response.
  • Experience with multi-tenant isolation, pen-test programs, Okta or IdP rollouts, and CNAPP tooling (e.g., Wiz, Aikido).
  • Familiarity with GDPR, ISO 27001, HITRUST, NIST CSF, or the EU AI Act.
  • Certifications such as CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Security Specialty, or OSCP.
  • Public work: talks, writing, or open-source security tooling.

Responsibilities

  • Own Customer Trust: Run enterprise security reviews end to end. Build one source of truth for security answers, launch a trust center and security package, and lead CISO and InfoSec calls, audits, and RFP security sections.
  • Run the Compliance Program: Maintain SOC 2 Type II and HIPAA in Drata, including continuous control monitoring, policy refreshes, and access reviews. Lead the next audit and establish a GDPR program.
  • Harden the Cloud: Partner with SRE to prioritize and remediate cloud findings. Implement org-level guardrails for policies, secrets management, and least-privilege IAM across GCP and AWS.
  • Secure the Agents: Integrate security into Lily from the start, including threat models, prompt-injection defenses, tenant isolation, agent authorization, and CI security checks.
  • Test and Respond: Commission and manage the independent pen-test program and drive remediation. Refresh the incident response plan, conduct tabletop exercises, and act as the escalation point for security incidents.
  • Build Identity and Endpoint Foundations: Complete SSO (Okta) for tier-1 apps, conduct quarterly access reviews, and implement device management (MDM).
  • Set the Operating Model: Determine the need for vCISO or GRC services, complete CNAPP evaluation, and deliver a 12-month security roadmap.
  • Grow the Function: Hire and lead 1-2 security or AppSec engineers as the program scales.

Benefits

  • Medical, Dental, Vision
  • 401K
  • in-office lunch reimbursement
  • Wellness Stipend
  • generous parental leave
  • PTO and 10 US Federal Holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service