About the Role
We are seeking a Senior Security Engineer to serve as the technical backbone of our security and compliance program for SaaS products and client delivery. This role involves implementing controls, tooling, automation, and processes to ensure product and client data security. You will collaborate directly with engineering teams and embed into delivery workflows.
Responsibilities
- Build and maintain security controls across cloud infrastructure and SaaS products, including identity and access, encryption, logging, monitoring, secrets management, and multi-tenancy patterns.
- Own the technical implementation of SOC 2 Type II, ISO 27001, and ISO 42001 compliance, including building evidence pipelines, automating control testing, and maintaining audit artifacts.
- Instrument and operate security monitoring and alerting across cloud environments (GCP, AWS, and/or Azure), with hands-on responsibility for threat detection, log aggregation, and response.
- Partner with engineering teams to embed security into CI/CD pipelines, including vulnerability scanning, SAST/DAST tooling, dependency management, container security, and secure code review.
- Implement privacy controls in product and client environments, aligning with HIPAA, GDPR, and CCPA/CPRA requirements.
- Execute the client engagement security model, including provisioning/deprovisioning access, configuring environment segregation, and meeting client-specific delivery security requirements.
- Conduct hands-on vendor security assessments, reviewing third-party architectures, configurations, and data handling practices.
- Maintain and test incident response playbooks, and lead technical response and forensic analysis during security events.
- Build and maintain AI-specific security controls, including reviewing model inputs/outputs, securing agent workflows, and managing prompt injection and data leakage risks in AI-enabled products.
- Contribute to the security questionnaire and RFP response library as the technical author for customer assurance requests.
Requirements
- 5+ years of hands-on security engineering experience, ideally spanning SaaS product environments and/or professional services/agency delivery.
- Deep practical knowledge of cloud security in at least one major platform (GCP, AWS, or Azure) including IAM, networking, secrets management, logging, and security tooling.
- Hands-on experience with SOC 2 Type II and ISO 27001 control implementation.
- Experience building security automation across CI/CD pipelines.
- Working knowledge of privacy regulations (HIPAA, GDPR, CCPA/CPRA) and experience implementing technical controls.
- Proficiency with security monitoring and SIEM tooling.
- Strong communication skills, with the ability to explain complex findings clearly to various stakeholders.
- Comfort working across a distributed, fast-moving organization with multiple concurrent workstreams.
- Experience working with AI-enabled development tools and integrating security thinking into AI-assisted workflows.
- Hands-on experience reviewing and hardening AI agent workflows.
- Comfortable leveraging AI-enabled development tools and workflows to accelerate engineering, automation, debugging, and operational tasks.
- Experience orchestrating multi-step AI or agent-driven workflows.
- Strong judgment reviewing and hardening AI-assisted output for security, scalability, maintainability, and architectural fit.
- Experience building or maintaining prompts, evaluation frameworks, documentation, or operational context systems that improve engineering velocity and reliability.
- Familiarity with automated evaluation and feedback loops for AI-enabled systems and workflows.
Skills
- Cloud Security (GCP, AWS, Azure)
- IAM
- Networking
- Secrets Management
- Logging
- Security Tooling
- SOC 2 Type II
- ISO 27001
- CI/CD Security Automation
- Vulnerability Scanning
- SAST/DAST
- Privacy Regulations (HIPAA, GDPR, CCPA/CPRA)
- Security Monitoring
- SIEM Tooling
- Incident Response
- Forensic Analysis
- AI Security Controls
- Prompt Injection Mitigation
- Data Leakage Prevention
- AI Agent Workflow Hardening
- AI-Enabled Development Tools
- AI Workflow Orchestration
- AI Output Review
- Prompt Engineering
- AI Evaluation Frameworks
- Automated Evaluation
- Infrastructure-as-Code Security Tooling (e.g., Checkov, tfsec, OPA/Rego)
- ISO 42001
- AI Governance Frameworks
- Multi-tenant SaaS Security
Experience Level
- Senior
Salary/Compensations
- $110,000 – $150,000
About the Company
- Code and Theory is a digital-first creative agency founded in 2001, operating at the intersection of creativity and technology.
- We solve consumer and business problems and establish new capabilities for clients.
- We serve a global client roster of Fortune 100 companies and startups.
- Our teams are distributed across North America, South America, Europe, and Asia.
- The Code and Theory global network includes agencies like Kettle, Instrument, Left Field Labs, Create Group, Current, and TrueLogic.
- We work across diverse categories including tech, CPG, financial services, travel & hospitality, government, education, media, and publishing.
- We collaborate with clients such as Adidas, Amazon, Con Edison, Diageo, EY, J.P. Morgan Chase, Lenovo, Marriott, Mars, Microsoft, Thomson Reuters, and TikTok.
- The Code and Theory network comprises nearly 2,000 people, with a 50/50 split between engineers and creative talent.
- We are seeking smart, driven, and forward-thinking individuals to join our team.
