Security Lead
sunset · New York
About The Role
About SunsetAt its core, Sunset was founded to help founders. We started by supporting startups through shutting down, but we have since expanded into unlocking a new revenue stream for all types of <businesses.In> 2025, we had a unique insight: the data every company generates each day through collaboration, communication, and building is some of the most valuable training data in the world. Public and synthetic data can only get frontier models so far, so the next generation of model progress depends on real, proprietary data grounded in how actual businesses operate. We are a primary source of it, partnering directly with the frontier AI labs building what comes next.Why Join Sunset NowWe have scaled from $0 to a multi-eight-figure run rate in a matter of monthsWe have raised from top-tier investors, including Floodgate, Afore, Ludlow, and Hustle FundWe are small enough that you will carry outsized responsibility and grow as quickly as the company doesYou will partner with and build for some of the fastest and most important companies in the worldYou will help build a massive, category-defining business from the ground floorThe RoleSunset handles internal enterprise data from collaboration tools, documents, files, and business systems, then transforms it into de-identified datasets that remain useful. We also build software that can retrieve information, guide workflows, and take carefully bounded actions. Security is part of whether these products can exist, not a review added after they are <built.You> will lead security across the company. The scope includes our products and cloud systems, the enterprise data we acquire and deliver, employee and contractor access, vendors, AI tool authority, incident readiness, and the human workflows through which consequential Dissolution work gets done. You will find the risks that could genuinely limit Sunset and turn them into technical, operational, and organizational controls that work in practice.This is a hands-on individual-contributor role. You will write code, review architecture, test technical and human systems, lead exercises and incidents, and create secure defaults other teams can operate. You own the company-wide security program, but the people who run each product, system, and operation remain responsible for implementing and following its controls. You are not a one-person IT, legal, compliance, or operations department.Problems You Might OwnKeep sensitive data inside explicit boundariesTrace how customer data, credentials, derived artifacts, and delivery outputs move through SaaS applications, workers, data pipelines, review tools, logs, storage, and third parties. Build controls that make tenant isolation, access, retention, deletion, quarantine, and delivery decisions enforceable and auditable rather than dependent on convention.Give people and AI systems only the authority they needDesign identity, authorization, and credential systems for employees, contractors, customers, services, and AI-assisted workflows. You might build just-in-time access, scoped tool contracts, approval boundaries, safe execution environments, or protections against prompt injection, confused-deputy behavior, and data <exfiltration.Secure> how the company and its people operateDesign security into employee onboarding and offboarding, devices, accounts, contractors, vendors, support access, and sensitive human workflows. On the Dissolution side, that includes identity verification, approval boundaries, segregation of duties, document and credential handling, consequential actions, exception paths, and an audit trail that shows who did what and why.Make the secure path the easiest pathBuild paved roads that catch important problems early without creating a security queue. This could include high-signal code and architecture review, secrets and sensitive-data detection, reusable authorization patterns, dependency and cloud controls, release checks, incident tooling, or automated evidence that serves both engineers and customer trust.What You'll DoEstablish Sunset's company-wide security program, current attack surface, highest-consequence risks, and prioritized roadmapThreat-model product, data, AI, cloud, workforce, vendor, delivery, and human operational workflows, then stay involved through implementation and verificationBuild and improve controls for identity, authorization, tenancy, sensitive data, credentials, logging, secure execution, and customer deliveryDefine and verify workforce-security requirements for accounts, endpoints, onboarding, offboarding, contractors, vendors, training, and access reviewsWork with Dissolution Operations to secure identity checks, approvals, segregation of duties, documents, money or asset-related actions, exceptions, and evidence of human decisionsFind vulnerabilities through code review, architecture review, testing, production evidence, and attacker-minded investigationLead the security side of incidents and exercises, including containment, recovery, learning, and durable remediationCreate secure defaults, tooling, and review triggers that let product, machine learning, data, and platform teams move independentlyMaintain the security control framework and evidence for customer reviews and SOC 2, while keeping each control with an accountable operating ownerWork with leadership on risk acceptance and with legal, compliance, and privacy partners on decisions outside the engineering functionUse AI tools deeply for security analysis and engineering while treating generated findings, code, and conclusions as evidence to verifyWhat Success Looks LikeSunset's most consequential security risks are visible, owned, and being reduced in a deliberate orderAt least one high-risk technical or human-operational boundary is materially safer because of a control you designed, implemented with its owner, and verifiedEngineers adopt reusable security capabilities that reduce dependence on case-by-case reviewEmployees, contractors, and operational teams have clear access, approval, escalation, and evidence requirements for consequential workAccess, vulnerabilities, incidents, sensitive-data handling, vendor risk, and control evidence become easier to understand and act onProduct and AI capabilities expand within explicit authority, isolation, monitoring, and recovery boundariesCustomer trust evidence becomes faster to produce because it reflects real, current controlsYou Might Thrive Here IfYou have at least three years of professional security or software engineering experience, including hands-on work securing production systemsYou are a strong software engineer with security as a core specialty, and you are comfortable building controls rather than only recommending themYou have worked in a startup and can prioritize a few consequential risks across a much larger set of possible improvementsYou have owned security outcomes across several of product engineering, infrastructure, workforce, vendors, compliance, or business operationsYou can reason deeply about application security, identity and authorization, multi-tenant systems, cloud infrastructure, sensitive data, secrets, and incident responseYou think like both a builder and an attacker and can explain the actual abuse path, affected asset, likely impact, and useful mitigationYou create low-friction defaults and clear decision boundaries instead of making Security the approval step for routine workYou can secure human workflows with approvals, separation of duties, training, evidence, and monitoring without pretending every risk has a software-only solutionYou can communicate risk honestly to engineers, executives, customers, and auditors without using certainty you do not haveYou use modern AI engineering tools fluently and understand their authority, data, dependency, prompt-injection, and verification risksThis Role May Not Be for You IfYou want a compliance-only role centered on collecting evidence and administering frameworksYou prefer producing findings or policies to implementing and verifying durable controlsYou treat every possible vulnerability as equally urgent or use Security as an unconditional veto without explaining the tradeoffYou want a narrow specialty with established teams to own every adjacent system and decisionYou do not want AI tools to be part of your daily security and engineering workflowBonusExperience securing data-intensive, privacy-sensitive, or multi-tenant SaaS productsExperience with information extraction, de-identification, data pipelines, secure delivery, or privacy-preserving systemsExperience securing AI agents, tool-using systems, retrieval, model workflows, or MCP-style integrationsExperience building least-privilege, just-in-time access, policy enforcement, secrets detection, data-loss prevention, or audit systemsExperience with SOC 2, customer security reviews, vulnerability management, incident response, penetration testing, or security partnersExperience as an early security hire who created leverage without centralizing all security workExperience securing operational, financial, legal, support, or other consequential human workflows
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
