Hightouch Logo

Hightouch

Product Security Engineer

Posted 4 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
180K-400K Annually
Entry level
Remote
Hiring Remotely in USA
180K-400K Annually
Entry level
Own Hightouch’s application security posture as the first dedicated security hire. Secure multi-tenant systems, sub-tenant access controls, distributed architecture, internet-facing APIs, and multi-region, multi-cloud infrastructure. Lead threat modeling, compute isolation, rate limiting, abuse detection, authorization, privacy controls, and security program initiatives. The role is highly hands-on, emphasizing code-level fixes, architecture influence, roadmap ownership, and collaboration with engineering teams.
The summary above was generated by AI
About the Role

This is our first dedicated security hire, and it's a rare chance to define the function from the ground up. You'll own Hightouch's application security posture end-to-end. We have strong engineering fundamentals and a solid foundation; now you'll shape what security looks like here as we scale from 70 to 140+ engineers.

This is a hands-on, high-autonomy role. You'll spend most of your time in the codebase, not in meetings. You’ll be solving hard problems at the intersection of security and distributed systems:

  • Multi-tenant isolation on a system running ~1M data syncs per day and ingesting 100K+ events/sec

  • Sub-tenant access control - for multi-team and multi-brand use cases, requiring differentiated access to configuration and data

  • Security architecture - Build and refine our frameworks for compute isolation and perform threat modeling and hardening of new products

  • Internet-facing APIs - Our high-throughput, internet-facing architecture services customer data at scale. You’ll improve our rate limiting, abuse detection, and granularity of access control

  • Multi-Region and Multi-Cloud - Supporting our multi-region and multi-cloud backend, including extending it to launch Hightouch on in new regions to support data residency requirements of our global customer base

You'll own your roadmap. We're not looking for someone to run a checklist — we're looking for someone who can look at our architecture, identify the highest-leverage problems, and go fix them.

We are looking for talented, intellectually curious, and motivated individuals who are interested in tackling the problems above. This is a senior role, but we focus on impact and potential for growth more than years of experience. The salary range for this position is $180,000 - $400,000 USD per year, which is location independent in accordance with our remote-first policy. We also offer meaningful equity compensation. 

About You

You’ve been an early security hire at a SaaS company before and moved the needle on how they approach security. You can read application code, threat model a distributed system, and ship production fixes. You have significant distributed systems expertise so that you can understand and influence what is being built by the product teams and influence from a place of trust.

Experience that's relevant:

  • Being an early security hire (first 1-3) at a SaaS or data infrastructure company

  • Securing multi-tenant platforms: tenant isolation, authorization models, etc

  • Cloud security on systems that span more than one cloud and operate against customer-owned accounts

  • Design and build of data infrastructure as an early engineer, not just a user. You helped secure it from early design or during major redesigns. You understand how it scales and how it’s secured

  • Privacy-adjacent security (PII handling, data residency, GDPR/CCPA technical controls)

We don't care about certifications. We care about what you've built.

Interview Process
  1. Recruiter Screen [30m] - Introductory mutual fit assessment

  2. Security Architecture Interview [60m] - Threat model discussion of a real-ish system, followed by a systems design exercise

  3. Core interview [90m] - deep dive on distributed systems knowledge

  4. Hiring Manager Interview [60m] - What you've built in the past, how you work

  5. Security Program Interview [60m] with Head of Engineering — How you've run security programs in practice: bug bounty, pentest engagements, working with external researchers, and partnering across engineering to drive adoption.

Similar Jobs

4 Days Ago
Remote or Hybrid
US
160K-180K Annually
Senior level
160K-180K Annually
Senior level
Cloud • eCommerce • Information Technology • Professional Services • Software
Owns Cleo’s application and product security strategy across SaaS and customer-hosted products. Responsibilities include maturing the SSDLC, threat modeling, security scanning, vulnerability triage, penetration testing, coordinated disclosure, CVE management, product security controls, customer-facing advisories, and NIST CSF evidence. The role also leads security enablement, roadmap prioritization, AI security reviews, and hands-on exploit reproduction and patch validation while guiding engineers and security partners.
Top Skills: APIsAWSBurp SuiteCi/CdContainer ScanningCyclonedxEksGitGithub Advanced SecurityGoIac ScanningJavaJenkinsKubernetesNist Ai RmfNist CsfOwasp AsvsOwasp SammOwasp Top 10 For Llm ApplicationsPolicy-As-CodePythonRbacSAMLSastScaSecrets ScanningSemgrepSlsaSnykSpdxSsoTerraformTypescriptVex
22 Days Ago
In-Office or Remote
141K-176K Annually
Senior level
141K-176K Annually
Senior level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Lead secure design reviews, threat modeling, and security risk assessments for products and features. Partner with engineers, product managers, and designers to develop secure architectures, provide remediation guidance, promote security culture through training and mentoring, oversee vulnerability management, and explain security events. Build security tooling, automate secure development practices, and establish architectural patterns and processes that reduce security risk across DigitalOcean’s engineering organization.
Top Skills: CContainerizationContinuous DeliveryContinuous IntegrationGoJavaScriptOwasp Top TenRustVirtualization
22 Days Ago
Remote
United States
141K-176K Annually
Senior level
141K-176K Annually
Senior level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Assess product and application architectures, develop threat models, identify security risks, and guide engineering teams on remediation. Promote security culture through training, mentoring, vulnerability management, and internal security initiatives. Build security tooling, automation, patterns, and workflows that embed secure-by-design practices across engineering. Partner with product managers, designers, and engineers to secure complex, large-scale cloud systems.
Top Skills: CContainerizationContinuous DeliveryContinuous IntegrationGoJavaScriptOwaspRustVirtualization

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account