As the Lead Security Engineer at Samaya, you will build the security foundation that enables us to win and retain the world's most security-conscious financial institutions as customers. We run Python and Kubernetes workloads on GCP that process sensitive financial data at scale — and this is our first dedicated security hire. You'll own everything: building controls, running compliance programs, and representing security externally to enterprise customers. Security Infrastructure: You will design and implement cloud security controls across our GCP environment — including IAM, KMS/CMEK, DLP, network controls, single-tenant isolation, secrets management, and audit logging. You'll own our security operations stack (SIEM, endpoint, alerting) and vulnerability management program, ensuring our platform meets the standards of the most demanding financial institutions in the world. Compliance Ownership: You will own our end-to-end compliance programs — SOC 2 Type II, ISO 27001, and what comes next — including evidence collection, auditor management, and our compliance tooling stack. You'll turn compliance findings into engineering work and customer-facing artifacts, maintaining policies and governance docs aligned with standards and regulators. Customer Trust: You will be Samaya's security face to enterprise customers. You'll support sales and customer success in security conversations with bank and hedge fund InfoSec teams, build scalable processes to handle DDQs and security questionnaires, and translate technical controls into business language that builds trust. In this role, you will be the sole security owner at a high-growth Series A company — and will have a clear path to building a small security team as Samaya scales.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed