OpenSpace Logo

OpenSpace

Sr. Security Engineer

Posted 2 Days Ago
Remote
Hiring Remotely in United States
180K-230K Annually
Senior level
Remote
Hiring Remotely in United States
180K-230K Annually
Senior level
Conduct proactive security reviews of features, architectures, integrations, and AI/ML systems. Lead threat modeling, design reviews, secure SDLC practices, vulnerability remediation, AI security governance, incident response exercises, and security automation. Support SOC 2 and ISO 27001 programs, collaborate with consultants on penetration testing and vendor assessments, and influence engineering teams on security without owning their roadmaps.
The summary above was generated by AI

At OpenSpace, we’re redefining how the world’s most complex projects are built. Our AI-powered Visual Intelligence Platform uses computer vision and spatial AI to give construction teams a real-time view of what’s happening on-site, helping them build faster, safer, and with greater confidence.

But what truly sets us apart is our people. We hire curious, driven teammates who love solving hard problems, taking ownership, and making a real-world impact. Great people build great culture—and apparently it shows. Forbes has named OpenSpace one of America’s Best Startup Employers five years in a row. Come see what all the fuss is about ✨


Brief summary of role:

Security is in OpenSpace's DNA. A significant portion of our core engineering team — including several of our most senior engineers — came together at a security SaaS company before OpenSpace, and that shows up in how we design systems, review code, and think about customer data. We run a mature program today: an external security partner handles pen testing and structured assessments, our DevOps and IT team owns infrastructure security, IAM, and endpoint, and product engineers carry real ownership of the code they ship.

This role is about pushing our team from strong to elite: building the proactive security review muscle that lives day-to-day inside the engineering org, rather than at the cadence of an external engagement.

You'll maintain partnership with our existing security consultants. Our partners will continue to manage structured assessments including Penetration Testing and security assessments.  You will support our team and maintain our in-house practice that catches issues long before they reach one.

This role reports to the Director of DevOps and IT.


What you will be doing:

  • Run proactive security reviews of new features, architectures, and third-party integrations before they ship
  • Assist in optimizing our application and product security practice: threat modeling, design review, secure SDLC integration
  • Ownership in our approach to AI-related security risk, including:
    • Securing our own AI/ML systems and the data flowing through them
    • Governing internal use of AI dev tools (Claude Code and similar) so we move fast without leaking sensitive data
    • Reviewing AI-assisted code contributions and helping us evolve our policies as the tooling matures
  • Partner with engineering teams to triage and remediate vulnerabilities from pen tests, customer findings, and internal discovery
  • Support our SOC 2 and ISO 27001 programs as a key technical contributor (compliance ownership lives elsewhere, but you'll be the engineering voice in the room)
  • Help mature our incident response practice and run security tabletop exercises
  • Build internal tooling and automation that scales security review without bottlenecking shipping
  • Work with our consultant on scoping pen tests, vendor assessments, and customer security reviews

What we are looking for:

  • 5+ years in security engineering, application security, or product security
  • Hands-on experience doing proactive security review (threat modeling, design review, secure code review) on production systems
  • Strong fundamentals in web application security, cloud security (we run primarily on AWS and GCP), and modern auth patterns
  • Comfortable reading and reviewing code across at least one of our stacks (Python, Java/Kotlin, TypeScript)
  • A real point of view on how AI changes the security landscape, both as a new risk surface and as new tooling for defenders
  • Track record of working effectively in a startup or fast-moving environment where you have to prioritize ruthlessly and make tradeoffs
  • Ability to influence engineers without owning their roadmap

Nice to have:

  • Experience as the first or early security hire at a growth-stage company
  • Hands-on contributor experience with SOC 2 and/or ISO 27001
  • Background in security automation, internal tooling, or open source security work
  • Familiarity with construction tech, geospatial systems, or computer vision
 

Our US Benefits include:

  • 🩺 100% employer-paid medical, dental, and vision coverage
  • 🌴 Flexible paid time off
  • 💰 401(k) with company match
  • 👶 Paid parental leave
  • 🏡 Home office stipend
  • 🤝 Employee referral program
  • ✈️ Annual company retreats and team gatherings

Base Salary: $180,000-$230,000

The “Base Salary: range represents the low and high end of the anticipated salary range for this position across all US locations including but not limited to CA, CO, NY, WA, NV, MD, CT and RI. The determination of this anticipated Base Salary involves the consideration of many factors in making compensation decisions including but not limited to: location of candidate, unique skill sets, experience, training, performance, licensure and certifications, as well as other business and organizational needs. 

Please note: We are unable to provide visa sponsorship or employment-based immigration support for this position. Applicants must be authorized to work in the country of employment without current or future sponsorship

#LI-Remote


OpenSpace welcomes employees from varied backgrounds and walks of life, and it’s reflected in our diverse community. OpenSpace is proud to be an equal opportunity employer and is committed to providing equal employment opportunities to all employees and applicants for employment, without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

Similar Jobs

11 Hours Ago
Remote or Hybrid
182K-288K Annually
Senior level
182K-288K Annually
Senior level
Healthtech • Social Impact • Software
Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development.
Top Skills: Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling
15 Hours Ago
Easy Apply
Remote or Hybrid
Lafayette, CO, USA
Easy Apply
110K-150K Annually
Senior level
110K-150K Annually
Senior level
Automotive • Greentech • HR Tech • Sales • Software
Own and improve enterprise security platforms, cloud and infrastructure security, identity governance, endpoint protection, vulnerability management, incident response, network controls, and DevSecOps practices. Lead complex security initiatives, compliance controls, vendor assessments, security architecture reviews, and AI security governance. Build automation with PowerShell and Python, partner with IT Operations and DevOps, reduce manual work, and serve as the senior escalation point for technical security incidents.
Top Skills: Amazon SesAuth0AWSAws Identity CenterAzureChatgpt EnterpriseCi/CdCisco DuoCisco MerakiCisco UmbrellaClaudeConditional AccessContainersCrowdstrikeDastDkimDmarcInfrastructure As CodeKnowbe4KubernetesMcpMicrosoft 365Microsoft Entra IdMicrosoft GraphNist CsfPimPowershellPythonRapid7 InsightappsecRapid7 InsightidrRapid7 InsightvmRapid7 MdrRest ApisSastScimSendgridSnykSoc 2SpfSsoVpn
2 Days Ago
Easy Apply
Remote or Hybrid
Easy Apply
134K-168K Annually
Senior level
134K-168K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Provides operational support for Zscaler security platforms, including policy configuration, tuning, monitoring, alert triage, DLP, CSPM, DSPM, and incident response. Maintains zero trust access controls, investigates user and application experience issues, documents procedures, and automates repetitive workflows. Requires five-plus years in security operations or related technical fields, hands-on ZIA or ZPA administration, cloud and networking knowledge, and U.S. citizenship.
Top Skills: Ai SecurityAWSCloud Security Posture Management (Cspm)Crowdstrike FalconData Loss Prevention (Dlp)Data Security Posture Management (Dspm)DevsecopsGoogle Cloud Platform (Gcp)LinuxmacOSAzureMtrNssPingSIEMSsl/TlsTcpdumpTracerouteWindowsWiresharkZero TrustZscaler Digital Experience (Zdx)Zscaler Internet Access (Zia)Zscaler Private Access (Zpa)

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account