Founding Security Engineer

SchemataSan Francisco, CA
Hybrid

About The Position

At Schemata, we are transforming the $400 B virtual‑training and simulation market by fusing 3D computer vision, neural rendering and large multimodal models inside highly regulated industries. Our platform delivers photorealistic, intelligent 3D experiences, demanding robust spatial reasoning, high‑performance data pipelines and seamless integration between traditional graphics and AI‑driven perception.

Requirements

  • Strong experience in security engineering, application security or cloud security with hands-on implementation ownership, not purely policy or GRC.
  • Deep AWS security expertise: IAM design, VPC and network controls, KMS, GuardDuty/Security Hub, and least-privilege at scale.
  • Strong applied knowledge of application security: authN/authZ design, common vulnerability classes, secure code review, threat modeling.
  • Ability to write real code (Python) to automate controls, evidence collection and tooling.
  • Working knowledge of at least one major compliance framework (NIST 800-53/RMF, FedRAMP, SOC 2, or ISO 27001) and the practical work of evidencing controls.
  • Container and Kubernetes security experience: image hardening, runtime policy, supply chain integrity.
  • Enough backend or infrastructure ability to be a genuine extra pair of hands outside security: shipping a service, writing a Terraform module, fixing a CI pipeline.
  • Clear communication with non-security engineers and with customer security teams alike.

Nice To Haves

  • Federal authorization experience: running or supporting an ATO, working with AOs and ISSOs, FISMA continuous monitoring.
  • Certifications such as CISSP, OSCP, CCSP, CAP, or GIAC equivalents.
  • Experience securing ML/AI systems: model supply chain, data governance, prompt injection and inference abuse.
  • Familiarity with DISA STIGs, NIST 800-171, CMMC or CUI handling requirements.
  • Experience being the first security hire at a startup and building the function from zero.
  • Defense, aerospace, energy or other regulated‑industry experience; active or ability to obtain U.S. security clearance.

Responsibilities

  • Own the security architecture: define and implement how identity, authorization, tenancy isolation, encryption and audit logging work across our platform, and review designs before they become expensive to change
  • Red team our AI systems: probe the LLM and spatial reasoning surfaces the way an adversary would through prompt injection, jailbreaks, tool-use and agent abuse, retrieval and training data poisoning, model extraction, and the failure modes specific to grounding models in customer documents and 3D scenes.
  • Implement continuous security monitoring: own the security pipeline (SAST/DAST, dependency and container scanning, secrets detection, IaC policy checks) and the vulnerability management that follows from it.
  • Run detection and response: own the security monitoring pipeline day to day. Triage, investigation, containment and post-incident review. Be the person who gets paged, and make each incident produce a durable change: a new detection, a closed gap, a corrected runbook.
  • Make sure we’re compliant: implement and evidence NIST SP 800-53 and SOC 2 controls, support FedRAMP and ATO efforts, and manage POA&M tracking and remediation.

Benefits

  • Competitive upside
  • meaningful equity
  • top‑tier benefits
  • whatever gear you need to excel
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service