Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
hud (YC W25)

Senior Security Engineer

hud (YC W25)

. Lead detection and incident response from signal to alert to postmortem .

Posted 9/23/2026full-timeSan Francisco • California • United StatesSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in security engineering, incident response, and compliance, with a focus on implementing SOC 2 controls and securing APIs and data systems. Proven ability to lead investigations, communicate effectively across teams, and operationalize security frameworks in a fast-paced environment.

Highest-signal resume keywords
Security Engineering FundamentalsIncident Response LeadershipSOC 2 ImplementationThreat Modeling and Code ReviewsCommunication Skills

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Infrastructure SecurityDetection and ResponseIdentity ManagementSecurity ToolingVulnerability ManagementData ProtectionThreat ModelingRoot-Cause AnalysisSecurity FrameworksIncident Management
Soft Skills
High AgencySound JudgmentPragmatic Decision-MakingCollaborationPrioritization
Tools & Technologies
GitHubAI/ML InfrastructureDeveloper ToolsCloud SecurityData Workflows
Certifications & Qualifications
OSCPAWS Security SpecialistOSWECKSGIAC
Industry Keywords
SOC 2ComplianceIncident ResponseData Access ControlSecurity Roadmap

Tech Stack

Tools & technologies
AWSCloud

About the role

Key responsibilities & impact
  • Lead detection and incident response from signal to alert to postmortem
  • Own HUD’s security roadmap across product security, cloud and infrastructure security, corporate security, incident response, and compliance
  • Secure HUD’s APIs, platform, and data systems through threat modeling, design and code reviews, authentication and authorization controls, and secrets management
  • Build monitoring, detection, and incident-response capabilities
  • Lead investigations and postmortems and turn incidents and emerging threats into durable improvements
  • Own SOC 2 and customer trust, including control design, security questionnaires, policy management, vendor reviews, and audits
  • Partner with legal, commercial, engineering, and operations to translate customer contracts and data-license requirements into enforceable controls for data access, provenance, permitted use, retention, deletion, isolation, and auditability
  • Secure HUD’s product, cloud infrastructure, data workflows, and internal systems as the first full-time security hire

Requirements

What you’ll need
  • Strong security engineering fundamentals and hands-on experience across multiple areas such as infrastructure security, detection and response, identity, etc.
  • Experience leading security incidents end-to-end, from detection and containment through root-cause analysis and follow-up engineering work
  • Experience implementing or operating SOC 2 or a comparable security framework, including translating requirements into real technical and operational controls
  • High agency and sound judgment; ability to identify and prioritize risks, make pragmatic decisions under uncertainty, and drive implementation
  • Strong communication skills for working with founders, engineers, operations, legal, auditors, customers, and external partners
  • Strong candidates may also have experience as an early security hire or building a security program from scratch at a fast-growing startup
  • Experience securing AI/ML infrastructure, agent execution environments, data platforms, developer tools, or systems that run untrusted code or process sensitive data
  • Experience protecting licensed, proprietary, or customer-provided data and operationalizing contractual requirements around access, use, retention, and deletion
  • Experience finding CVEs, creating security tooling on GitHub, or with bug bounty programs
  • OSCP, AWS Security Specialist, OSWE, CKS, or GIAC hands-on certifications may be advantageous
  • Motivated candidates are encouraged to apply even if they do not meet all criteria
  • Ability to work hours with 70–80% overlap with either San Francisco or Singapore time zones

Benefits

Comp & perks
  • 100% covered top-of-the-line medical, dental, and vision from Blue Shield of CA (US employees)
  • Lunch and dinner when you’re in the office (in-office employees)
  • Company-wide holiday break (Christmas Eve to New Year’s Day) on top of PTO and paid holidays
  • Equinox membership
  • 401k
  • Commuter benefits (US employees)
  • Unlimited access to tokens for ChatGPT, Claude Code, Cursor, etc.
  • Support for relocation and visas for strong full-time candidates to the US or Singapore