SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead Security Engineer

Canary Technologies - San Francisco, CA, United States - Hybrid - posted 2026-09-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Canary Technologies is the leading agentic AI platform for hotel and guest management, powering digital infrastructure for 20,000+ hotels across 125+ countries. Major hospitality brands including Marriott International, Four Seasons, and Wyndham Hotels & Resorts rely on Canary to increase revenue, improve operations, and elevate guest experiences. The company has raised nearly $200M and was recognized as a 2024-2025 Deloitte Technology Fast 500 company and Inc. 5000 fastest-growing company. You will lead and grow Canary's Security team, including hiring, performance management, priorities, and career development. You'll own the company's security and compliance program across SOC 2, PCI DSS, GDPR/CCPA, and other applicable frameworks. As the primary security point of contact for the organization, you'll manage vendor and third-party risk, write and maintain security policies and standards company-wide, and run security awareness and training programs. You'll set technical direction for security tooling while staying hands-on in architecture and threat-model reviews. Canary values rigor and velocity equally: high standards, fast pace, and real ownership. The company offers unlimited PTO, standard holidays plus monthly company-wide days off, birthday holidays, office exchange travel stipends, professional development budgets, and a self-improvement club with monthly budgets for personal goals. REQUIREMENTS: - 8+ years in security engineering, including 2+ years leading a team as a manager or tech lead - Proven experience owning compliance programs end to end (SOC 2 Type II, PCI DSS, ISO 27001, or similar) - Exceptional written and verbal communication skills - Hands-on technical foundation in cloud security (AWS), identity and access management, application security, and vulnerability management - Experience with vendor risk management and reviewing security terms in customer and vendor contracts - Track record of building pragmatic, risk-based security programs at a growth-stage SaaS company - Nice to have: hospitality, fintech, or payments industry experience; CISSP, CISM, or CISA certification

Similar roles