Director, Security Engineering

Instalily.Ai•New York City, NY
•Onsite

About The Position

InstaLILY is an AI products and infrastructure company that puts execution at the frontier of enterprise AI. That work begins with Lily™, the world's first AI Forward Deployed Engineer, which learns how a business works, builds the software it needs, and goes live in days. It does not leave when the work ships; it stays and keeps the software working as the business changes. Lily runs wherever the work happens, in the cloud, on-premise, or at the edge, through InstaLILY's Small Data Center, built with NVIDIA technology. Founded in 2023 by Amit Shah and Sumantro Das, InstaLILY has raised nearly $100 million from Energize Capital, Insight Partners, and Home Depot Ventures. Headquartered in New York, with offices in San Francisco, London, and Toronto, InstaLILY serves leading companies across construction, industrial distribution, logistics, healthcare, and other operationally intensive industries. The Traction Revenue grew 5x over the past year, and Lily has driven over $200M in new annual sales for a single customer. We serve some of the largest operators in our industries, including SRS Distribution (part of The Home Depot family), United Rentals, and Henry Schein, and we work closely with the Google DeepMind and NVIDIA ecosystems. How We Work We work in small teams with real ownership: clear problems, direct access to the customers whose work you're changing, and room to ship. Your code runs in live production systems inside billion-dollar operations, so you see your impact directly. People who do well here want that proximity to the work. We're growing fast, and the people who join now shape what this company becomes. Everything runs on three principles: Customers, Culture, and Code. The Role: Own Security for Agents That Do Real Work We're hiring our first dedicated security leader, reporting directly to the CEO. Lily operates inside the systems of some of the largest enterprises in distribution, construction, healthcare, and logistics. That makes security a core part of the product and a lever on every enterprise deal we close. This isn't a cold start. We hold SOC 2 Type II and HIPAA, an Okta rollout is underway, and a CNAPP evaluation is in progress. What we need is one accountable owner who can take a strong foundation and turn it into a proactive, evidence-backed security program. This is a player-coach role. You'll spend 30–50% of your time writing code (automation, infrastructure-as-code, security tooling, remediation PRs), and most of the rest threat-modeling, reviewing architecture and PRs, and hardening cloud and IAM. You'll also be the face of security to enterprise customers, spending roughly 25–30% of your time on CISO calls, audits, and security reviews.

Requirements

  • 8+ Years in Security Engineering: Including hands-on ownership of a security or compliance program at a SaaS company, ideally at the Series B–C stage.
  • Hands-On Cloud and AppSec Depth: Strong in GCP and AWS IAM, Kubernetes, and infrastructure-as-code (Terraform/OpenTofu). You can threat-model a multi-tenant, multi-cloud architecture and review code, not just run scanners.
  • A Builder, Not Just a Reviewer: You write production-quality Python or TypeScript and ship your own automation, tooling, and fixes. You'd rather build and harden systems than monitor alerts or manage checklists.
  • End-to-End SOC 2 Type II Ownership: You've run the program yourself: audits, controls, evidence, and GRC tooling. You treat compliance as real risk reduction. HIPAA experience is a strong plus.
  • Credibility With Enterprise CISOs: You've led customer security reviews, questionnaires, and audits, and can hold your own in a room with a Fortune 500 security team.
  • Real LLM Experience: You've built something real with LLMs and understand how agentic systems change the threat model.
  • Player-Coach Mindset: You're energized by doing the work yourself. Tech-lead or program-lead experience is enough; formal people management is a plus, not a requirement.
  • In-person availability. 5 days/week in our New York or San Francisco office.

Nice To Haves

  • You've built a security function from scratch at a Series B/C SaaS company and taken it through SOC 2 Type II.
  • You've secured an LLM or agent product in production (prompt injection, agent authorization, OWASP Top 10 for LLMs).
  • You've led a real incident response.
  • Experience with multi-tenant isolation, pen-test programs, Okta or IdP rollouts, and CNAPP tooling such as Wiz or Aikido.
  • Familiarity with GDPR, ISO 27001, HITRUST, NIST CSF, or the EU AI Act.
  • Certifications such as CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Security Specialty, or OSCP. None are required.
  • Public work: talks, writing, or open-source security tooling.

Responsibilities

  • Own Customer Trust: Run enterprise security reviews end to end. Build one source of truth for security answers, launch a trust center and security package, and lead CISO and InfoSec calls, audits, and RFP security sections, often on short notice.
  • Run the Compliance Program: Keep SOC 2 Type II and HIPAA healthy in Drata: continuous control monitoring, policy refreshes, and access reviews. Lead us through our next audit window and stand up a GDPR program.
  • Harden the Cloud: Partner with SRE to prioritize and close critical and high cloud findings. Make org-level guardrails the default: org policies, secrets management, and least-privilege IAM across GCP and AWS.
  • Secure the Agents: Build security into Lily from the start: threat models, prompt-injection defenses, tenant isolation, agent authorization, and security checks in CI as part of a secure SDLC.
  • Test and Respond: Commission and run our independent pen-test program and drive remediation. Refresh the incident response plan, run tabletop exercises, and serve as the escalation point for security incidents.
  • Build Identity and Endpoint Foundations: Complete SSO (Okta) coverage for tier-1 apps, run quarterly access reviews, and put device management (MDM) in place.
  • Set the Operating Model: Decide whether to partner with a vCISO or GRC service for paperwork-heavy work, complete the CNAPP evaluation, and deliver a 12-month security roadmap to the CEO and leadership.
  • Grow the Function: Hire and lead 1–2 security or AppSec engineers as the program scales.

Benefits

  • Medical, Dental, Vision, 401K, in-office lunch reimbursement, Wellness Stipend, generous parental leave, PTO and 10 US Federal Holidays, and more!
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service