About the Role
As the first dedicated security hire, you will own the security architecture, harden the platform, and build out the compliance posture for an AI-native requirements platform. You will lead the security efforts for AI and agentic workflows, ensuring the protection of sensitive systems requirements for customers in defense, aerospace, and other industries.
Responsibilities
- Own security architecture across the platform, including threat modeling, secure design reviews, and establishing build standards.
- Harden the full stack, covering application security, cloud infrastructure (identity, network, secrets), tenant isolation, and data protection.
- Drive SOC 2 compliance and prepare for certifications required by defense and aerospace customers, such as export control and ITAR.
- Secure AI and agentic systems by addressing prompt injection, data leakage through models, agent actions, and implementing guardrails.
- Build necessary security tooling for detection, monitoring, vulnerability management, and CI/CD.
- Establish and manage incident response processes, from detection to postmortems.
- Collaborate with sales and product teams to navigate security reviews and build customer confidence.
Requirements
- 8+ years of experience building production software.
- Experience running secure services at scale in the cloud.
- Deep experience in application and cloud security (AWS, GCP, or Azure), including identity and access, secrets management, network security, and data protection.
- Proven experience owning security in a regulated or high-trust environment.
- Experience implementing SOC 2.
- Experience with export control, ITAR, or FedRAMP is a significant advantage.
- Proficiency in threat modeling, secure architecture, and incident response.
- Experience securing AI or LLM systems.
- Comfortable taking the lead on security at a startup and defining the security strategy.
Skills
- TypeScript
- Node.js
- Python
- AI
- LLM APIs
- Orchestration libraries
- Postgres
- Cloud services
- Threat modeling
- Secure architecture
- Incident response
- Application security
- Cloud security
- Identity and access management
- Secrets management
- Network security
- Data protection
- SOC 2
- Export control
- ITAR
- FedRAMP
Location
- Remote
Work Type
- Full-time
Experience Level
- Staff
- 8+ years
Benefits
- Competitive salary
- Meaningful equity
- Health coverage
- Dental coverage
- Vision coverage
- Flexible time off
- Support for experimentation
- Support for learning
- Support for staying current with the AI ecosystem
About the Company
- Flow Engineering is an AI-native requirements platform for modern engineering organizations.
- The platform enables hardware teams to collaborate with AI agents to design, validate, and evolve complex systems with speed and rigor.
