About The Position

We are seeking an experienced Security Engineer with broad expertise across AWS infrastructure security, application security, and identity/access management. The ideal candidate will have owned security end-to-end as the first or sole security hire at a fast-moving startup. You should be comfortable operating with high autonomy in a small team, building security programs from scratch, and have a track record of making the secure path the easy path rather than gatekeeping. Bonus points if you have experience securing AI/agent systems or working in financial services.

Requirements

  • AWS infrastructure security experience (VPC, VPN peering, network segmentation, IAM, secrets management)
  • Application security experience (threat modeling, dependency/supply-chain controls, secure code review)
  • Identity and access management (SSO, RBAC, least-privilege design) for both humans and non-human actors
  • IT security (endpoint security, device management, access controls)
  • Compliance and auditability program experience (SOC2, pentest coordination, vulnerability management)
  • Experience operating with high autonomy in a small team
  • Experience building security programs from scratch
  • Track record of making the secure path the easy path

Nice To Haves

  • Experience securing AI/agent systems
  • Experience working in financial services

Responsibilities

  • Own infrastructure security across the entire AWS environment — VPC/VPN peering, network segmentation, IAM, secrets management — designing guardrails that make the secure default also the fastest one
  • Take ownership of application security across web and desktop clients, embedding threat modeling, dependency/supply-chain controls, and secure code review into how the team designs and ships
  • Build and manage identity and access controls (SSO, RBAC, least-privilege) for both humans and AI agents, ensuring every actor reaches exactly what it needs and nothing more
  • Design audit trails and access controls that make autonomous agent activity fully reconstructable — what it did, on whose behalf, with what data, and why
  • Own IT security in partnership with the IT MSP — devices, endpoints, and access for a 12-person in-office team
  • Stand up and run compliance, auditability, bug bounty, VDP, and pentest programs that prove security posture to clients, partners, and auditors as a byproduct of how the system is built.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service