Engine Logo

Engine

VP, Security

Posted 3 Days Ago
Be an Early Applicant
Easy Apply
Remote
Hiring Remotely in United States
298K-400K Annually
Expert/Leader
Easy Apply
Remote
Hiring Remotely in United States
298K-400K Annually
Expert/Leader
The VP of Security will lead Engine’s security strategy, engineering, operations, AI security, corporate IT, and enterprise trust. Key priorities include building an AI security function, securing agent identities and AI gateways, leading AppSec, SecOps, and CloudSec, strengthening identity and access controls, managing corporate IT, supporting SOC 2 and PCI controls, and representing security to executives, the board, and enterprise customers.
The summary above was generated by AI
About Engine
Engine is the all-in-one travel and spend management platform trusted by 38K+ businesses and groups representing 1.8M+ travelers. We're the retailer and the rails of business travel, one of the fastest-growing companies in travel tech, built on a decade of proprietary technology, supply, and pricing no one else can replicate. Other travel and AI companies run on our infrastructure to book real trips, hold rates, and move payments, without building any of it themselves. We built it, AI-forward at every layer, from how travelers book to how the rails run.
That work has earned recognition as one of Fast Company's Best Workplaces for Innovators (2025), TravelTech's Reservation Platform of the Year (2026), and one of Built In's Best Places to Work (2020–2026).
We're looking for bold, ambitious people to help redefine how businesses manage and experience travel. Working here, you can expect exponential growth, an ambitious pace, full ownership, and high-caliber colleagues who push you to do the best work of your career. Every hire raises the bar. 

Come outpace the ordinary and build the future of travel with us.

The Role

We're hiring a VP of Security to own security at Engine end to end: strategy, engineering, operations, and the trust posture that carries us through future funding and beyond. This is not a maintain-the-program role. The program is healthy: clean SOC 2 and PCI audits, established AppSec, SecOps, and CloudSec functions, modern tooling across the stack. The mandate is to build what comes next.

What comes next is AI. Agents inheriting human credentials in cloud environments with real access sprawl. Prompt injection and data exfiltration attempts against customer-facing AI surfaces. Shadow AI usage across every function of the business. Non-engineers shipping AI-built software that never touches a review path. Adversaries using the same models we do, at machine speed. We need a leader who sees this wave clearly, has strong conviction about what to build, and can stand up net-new AI security capability while keeping the fundamentals sharp.

This role reports directly to the SVP of Engineering and AI and operates as a peer to senior engineering leadership. You'll represent security to the executive team, the board, and enterprise customers.

What You'll Own
  • AI Security (the priority). Stand up our AI security function from approved headcount. Build the internal AI gateway: single controlled egress for all internal AI usage, with authN, per-tool authZ, central prompt and output logging, inline DLP, and model allowlisting that discovers and absorbs shadow AI. Define agent identity in AWS so agents get scoped roles and short-lived credentials, never inherited human permissions. Harden consumer-facing AI surfaces: authenticated MCP with gateway-enforced per-tool authorization, a bad-prompt detection pipeline feeding the SIEM, output filtering on sensitive fields, and a red team scenario suite that runs as CI regression on every AI surface.
  • Security Engineering. Lead AppSec and SecArch, SecOps, and CloudSec, roughly ten people at full staffing across the current team and approved reqs, plus the corporate IT function. Drive the roadmap already in motion: secure-by-design intake, secrets refactoring, org-wide RBAC mapped to Okta groups, detection engineering on our next-gen SIEM, automated response playbooks, and identity log onboarding across Okta, Salesforce, and AWS.
  • GTM and Operations Security. Harden how the business operates: Salesforce least privilege, contractor and BPO access through VDI on managed hardware, insider threat monitoring, and production data hygiene.
  • Enterprise Trust and Series D Readiness. Own the security narrative for fundraising diligence and enterprise sales. Run point on customer security reviews and build the trust artifacts that shorten enterprise deals. Own the technical controls behind SOC 2 and PCI in close partnership with our legal team, which owns compliance, privacy, and audit programs.
  • Corporate IT. Own identity, endpoint fleet, and SaaS administration. Our Okta unification work makes identity the connective tissue between security and IT, and this role owns both sides of it: joiner-mover-leaver automation, entitlement hygiene, and a managed environment that holds up as agents become first-class users of our systems.
What Success Looks Like in Year One
  • AI security team hired and shipping: internal AI gateway live, agent identity model enforced ahead of broad agent rollout, prompt abuse pipeline running in production
  • security diligence and a customer-facing trust posture that accelerates enterprise deals rather than slowing them
  • RBAC, secrets remediation, and JML automation moving access from person-accumulated to role-driven
  • SOC 2 and PCI technical controls sustained without heroics, with a crisp operating boundary established with legal's compliance and privacy function
  • A security org that engineering wants to work with: gates that block only when the issue is real and the fix is clear
Who You Are
  • 12+ years in security with 5+ leading security organizations, ideally through hypergrowth and a major fundraise or IPO-track diligence process
  • Deep technical credibility: you can whiteboard an agent identity model, argue the details of an AI gateway architecture, and review a detection engineering backlog without a translator
  • Genuine, current conviction about AI security. You've thought hard about prompt injection, agentic access, model-mediated data exfiltration, and LLM red teaming, and you have opinions about what actually works
  • Builder of net-new functions, not just an operator of mature ones. You've taken a domain from zero headcount to a working team with real controls
  • Fluent in cloud-native security: AWS identity, CSPM, EDR and SIEM operations, modern AppSec tooling in CI
  • Comfortable owning corporate IT: identity platforms, endpoint fleets, and SaaS governance as extensions of the security mission, not a side duty
  • Executive presence: you can brief a board, close an enterprise customer's security review, and tell leadership no with a better alternative attached
  • Bias toward enablement. You believe security's job is to make the safe path the fast path, and you remove low-value controls as readily as you add high-value ones
Nice to Have
  • Experience securing customer-facing AI or LLM products at scale
  • Background in payments, travel, or another PCI-regulated, high-transaction-volume environment
  • Experience partnering with legal on privacy programs and regulatory frameworks (GDPR, CCPA, emerging AI regulation)
Why This Role

Most VP of Security roles are about maturing what exists. This one is about defining how an AI-native company defends itself while the threat model is still being written. You'll inherit a clean foundation, approved headcount, executive air cover, and a company that treats AI as its operating model rather than a feature. Join us on this mission to reshape how businesses experience travel, and help build the security foundation every AI at Engine runs on.

We accept applications for this role on an ongoing basis. We review applications as they are received and encourage interested candidates to apply early.

Compensation
Our compensation packages are based on several factors, including your experience, expertise, and location. In addition to a competitive base salary, all roles receive equity. Depending on the role, total compensation may also include an annual bonus. Your recruiter will share your complete compensation package as you move through the process.

Base Pay Range
$298,000$400,000 USD

The Engine Edge: Perks & Compensation
We believe in rewarding great work with great benefits:

  • Compensation: Competitive base pay tied to role and experience, with equity for all employees. Some roles are also eligible for bonuses or commissions.
  • Benefits: Check out our full list at engine.com/culture 
  • Environments for Success: Different roles have different needs in terms of the environments that drive success which is why we have a hybrid-hub model. Whether you are in one of our amazing offices or fully remote, we'll make sure you have what you need to succeed.

Perks and benefits may vary based on employment type, location, and more

HQ

Engine Denver, Colorado, USA Office

Cherry Creek is a mostly residential district with a vibrant shopping scene — department stores, high-end fashion boutiques and eclectic eateries.

Similar Jobs at Engine

Yesterday
Easy Apply
Remote
United States
Easy Apply
75K-120K Annually
Senior level
75K-120K Annually
Senior level
Artificial Intelligence • Fintech • Software • Travel
Design and implement backend services, modernize legacy systems into microservices, ensure strong testing and production observability, and collaborate with Product and Engineering teams. The role requires independent project ownership, strong system design, AI-assisted development using tools such as Claude or Cursor, effective communication with nontechnical stakeholders, and adaptability in an ambiguous, fast-changing environment.
Top Skills: ClaudeCursorDatadogJavaKotlinMicroservicesRelational DatabasesSplunkSQLTerraform
Yesterday
Easy Apply
Remote
United States
Easy Apply
135K-187K Annually
Senior level
135K-187K Annually
Senior level
Consumer Web • Software • Travel
Lead technical direction for a central infrastructure team supporting all product engineering. Design and maintain AWS infrastructure, Terraform modules, CI/CD workflows, observability, security, networking, cost-visibility tooling, and operational platforms. Coordinate multiple initiatives, improve reliability and incident response, establish paved roads adopted by feature teams, guide infrastructure strategy, and coach engineers across the organization.
Top Skills: AWSCloudflareDatadogDnsFinopsGithub ActionsIamJfrogOidcTerraformWafWarp
2 Days Ago
Easy Apply
Remote
United States
Easy Apply
94K-130K Annually
Senior level
94K-130K Annually
Senior level
Consumer Web • Software • Travel
Own acquisition and lifecycle growth for Engine’s sports and wedding travel verticals. Develop and scale experiments across digital, events, referrals, affiliates, and community; use data and AI to optimize performance; collaborate with Product, Sales, Design, and Lifecycle teams; and influence roadmap decisions to improve customer acquisition, retention, and the wedding booking experience.
Top Skills: AmplitudeBrazeClaudeCustomer.IoGoogle AdsKlaviyoMeta AdsOutreachSalesforceSnowflakeSQLTiktok Ads

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account