
Lead Security Engineer
San Francisco, CA at a glance
- Rent
- #2 of 51$2,680/mo+46% vs US avg
- Weather
- #17 of 51295 mild days0 hot · 0 cold
- Income tax
- #1 of 5113.3% top rateCalifornia
What you need
- Write production-quality code and build automation tooling
- Secure cloud infrastructure and IAM/PAM systems
- Investigate access anomalies and suspicious activity
- Prioritize security work by real risk
- Ship weekly in small team, decide with incomplete info
What you'll do
- Run SOC 2, PCI, and bank security compliance operations
- Test security across cloud, app, payment, AI boundaries
- Manage vulnerability scanning and remediation tracking
- Build incident runbooks, detections, and response handoffs
- Automate security evidence collection and obligation tracking
About Us
Salient builds AI agents for regulated financial services. Our agents automate loan servicing, compliance, collections, recovery, insurance claims, and disputes for banks, captives, and specialty lenders.
We are:
Backed by a16z and Y Combinator, with $75M raised in Series A funding
Cash flow positive and profitable, with mid eight figure ARR achieved in under two years
Already serving more than 20% of the auto lending industry
Processing millions of real customer calls and transactions every day
Fully deployed in production with major financial institutions
Actively expanding into new financial services segments
Building together in person in San Francisco
We are deeply integrated with our customers, own the full technology stack, and move quickly to bring modern AI into regulated industries where precision, reliability, and performance matter.
About the Role
We're hiring a hands-on Lead Security Engineer to build a repeatable security operating system for Salient. This is a Staff-level individual contributor role reporting to senior leadership. You will be our single dedicated security hire, with reserved support from infrastructure, IT, and People Operations.
You will own compliance operations, boundary testing, access and vulnerability management, detection and response, and the automation that makes all of it repeatable and provable. We'll sequence this work by risk together. We don't expect anyone to arrive as an expert in every area below.
What You'll Own
• The operating procedure for SOC 2, PCI, enterprise security questionnaires, and bank-specific security requirements, keeping implementation, approval, submission, and acceptance separate.
• Security testing across cloud/IAM, application, payment, and AI boundaries, including synthetic tests covering recordings, transcripts, logs, tools, storage, and providers.
• Investigation of access anomalies.
• Stronger IAM/PAM controls and monitoring.
• Network and vulnerability scanning, with every finding tracked through service-owner remediation and retest, or an authorized exception.
• Incident runbooks, useful detections, and proven handoffs between security, service teams, and backup personnel.
• Automation for security controls and evidence: tested evidence connectors, asset reconciliation, obligation tracking, and claim-review workflows.
What We're Looking For
• You own outcomes end to end and ship weekly with a small team, deciding with incomplete information.
• You're a software engineer first: you write production-quality code and build tested tooling and automation.
• You have hands-on experience securing cloud infrastructure and identity and access (IAM/PAM), including investigating suspicious access.
• You prioritize by real risk, are clear about what isn't covered, and can explain tradeoffs to leadership.
Nice to Have
• Experience operating SOC 2, PCI, or bank security controls and producing audit evidence.
• Experience leading SOC 2 or PCI audits with external auditors.
• Experience with detection engineering, incident response, or vulnerability management.
• Interest or experience in threat-modeling AI systems, LLM tool use, or data flows through model providers.
• Clear writing for runbooks, questionnaires, and customer security reviews, and a track record of partnering with engineering teams.
• Experience with financial services, payment data, or other regulated consumer data.
At Salient, we’re building at the edge of AI - fast, focused, and with real ownership. Sprints and major launches move quickly, and we look for people who are energized by that pace. Our team typically works around 60 hours per week, beginning at 8:00 AM, with four days spent collaborating in person at our San Francisco office.
We also offer a benefits package designed to support our full-time employees: medical, dental, and vision coverage, a generous 401(k), and catered lunches.
By applying, you acknowledge that your personal information will be processed in accordance with our Privacy Policy.
Optimize your resume for this job
Get a match score and the keywords you're missing
About Salient
Salient Predictions is an AI-driven firm that merges machine learning, climate science, and oceanography to generate weather forecasts. Their approach delivers twice the accuracy compared to typical forecasts and handles billions of data predictors to generate insights via APIs, interactive maps, and decision tools.
Similar Security roles


