Staff Security Engineer, Cloud and Product Security

Lob
$197,500 - $220,000Remote

About The Position

Lob is transforming the way businesses use direct mail by bringing the power of technology to a traditionally manual channel. Our modern logistics and fulfillment engine helps businesses build and scale high-quality, personalized direct mail programs without the operational burden. As we grow to meet the evolving needs of our customers and expand our product offerings, we’re building a team to shape the future of direct mail. This is the senior technical security role at Lob and the first hire in a newly split security function. You will own the engineering side of security: cloud infrastructure, detection and response, application security, and incident response. A dedicated GRC counterpart owns audit, compliance, and customer trust, so you are not the questionnaire desk. You will partner with them, not absorb them. You will report directly to the CTO, manage our application security contractor, and work day to day with our Platform, Logistics, and IT teams. This is a builder role with real autonomy and a mandate to raise the security floor of a system that processes hundreds of requests per second and moves millions of physical mailpieces.

Requirements

  • 8 or more years in security engineering, with meaningful depth in cloud security
  • Hands on expertise with AWS security services, IAM design, and infrastructure as code
  • Demonstrated detection engineering experience: you have written detections, tuned them, and cut false positive rates
  • Real incident response experience as a responder or lead, not just as a plan author
  • Fluency in application security sufficient to review findings, judge severity, and argue exploitability with engineers
  • Track record of shipping security improvements through other teams by earning trust rather than filing tickets
  • Comfort as the senior technical security voice in an organization without a large security team

Nice To Haves

  • Experience supporting SOC 2 Type 2, HIPAA, or Microsoft SSPA from the engineering side
  • Container and orchestration security, particularly Nomad or Kubernetes
  • Cloudflare, including Zero Trust and WAF
  • Experience in a company handling regulated or consumer-identifiable data at scale
  • Prior experience mentoring or managing engineers or contractors

Responsibilities

  • Cloud infrastructure security: Security posture of our AWS environment, including our CNAPP program and cloud misconfiguration risk. Security review of infrastructure changes across Terraform, Nomad, and our Cloudflare edge. WAF strategy and tuning at the domain level. Working with Platform engineers so security is designed in rather than reviewed at the end.
  • Detection and response: Build and own our detection engineering practice on our SIEM, moving us from noisy alert channels to curated, high signal detections. Define alert triage ownership, runbooks, and severity criteria. Own security incident response: escalation paths, tabletop exercises, post incident reviews. Partner with IT on endpoint detection and endpoint vulnerability coverage.
  • Application and product security: Own the vulnerability management program across SCA, SAST, DAST, and container scanning. Manage and mentor our application security contractor, and route remediation work into engineering teams effectively. Threat modeling and security architecture review for new products and major changes. Improve secure SDLC practice in a high velocity, AI-assisted engineering org.
  • Penetration testing and assurance: Technical ownership of our annual independent penetration test: scoping, findings triage, remediation routing, retest coordination. Produce the technical evidence our GRC counterpart needs for SOC 2, HIPAA, and Microsoft SSPA, without owning the audit itself.
  • Security engineering and automation: Build tooling and automation rather than process and spreadsheets. Apply AI to security operations where it creates real leverage.

Benefits

  • RSUs
  • Competitive benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service