SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead Security Engineer

LawnStarter - Remote - Remote - posted 2026-09-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 80,000 - 100,000 / annual

LawnStarter is the nation's leading on-demand marketplace for lawn care and outdoor services, with over $150M in annual bookings. The company is expanding beyond lawn care to become a one-stop shop for all home services, operating across three brands (LawnStarter, Lawn Love, Home Gnome) on a single shared platform, processing real payments and managing customer and pro data at scale. You will lead security end-to-end across the PHP/Laravel and TypeScript/React codebase, AWS infrastructure, payments flows, and compliance posture. You start as a hands-on individual contributor—security-of-one—with an explicit path to leading a small team within 12–18 months once the foundation is solid. This is not a hands-off management role; you lead by doing first, collaborating heavily with delivery teams and Cloud & DevOps while owning most of the heavy lifting yourself. Key responsibilities include: **Application Security**: Threat modeling the critical path, secure-SDLC practices, code and design review, SAST/secret-scanning/dependency-scanning in CI, and a vulnerability-management loop that closes findings. **Cloud & Infrastructure Security**: AWS posture (IAM, network, encryption), secrets management, EKS/Kubernetes hardening, and partnering with Cloud & DevOps on guardrails that prevent misconfigurations in production. **Compliance & Data Protection**: Mapping PCI scope for payments, driving SOC 2 and LGPD readiness, vendor risk assessment, and confidently answering customer and auditor security questionnaires. **Detection & Response**: Strengthening detection coverage on the critical path (Datadog, Sentry, AWS signals), writing incident runbooks, and leading responses when incidents occur. **AI-Agent Code Security**: Building scans, review gates, and conventions that allow agent-authored code to ship fast and safely—a novel challenge most security engineers haven't faced. **Foundation for Team Growth**: Establishing standards, playbooks, and hiring criteria that enable security to scale beyond one person. Year 1 success means: threat models and risk registers exist with top risks closed; SAST, secret scanning, and dependency scanning run in CI with a tuned review loop; PCI scope is mapped and SOC 2/LGPD readiness has a credible plan; detection coverage spans the critical path with incident runbooks written and rehearsed; a multi-year security roadmap exists with a concrete plan for first hires; and no P1 incidents from known, deprioritized gaps. The role spans the full stack—AppSec one day, AWS IAM the next, PCI scoping the day after. Breadth is the job, not a stretch. You'll prioritize ruthlessly, automate hard, and pick the few things that actually reduce risk over the long list that merely looks thorough. **Requirements** You must have: - Real, hands-on expertise in at least three of: application security, cloud security, compliance/GRC, and incident response—not surface familiarity, but the kind of depth where you've built and owned controls in each domain. - Ability to pick up the fourth domain quickly. - Daily use of AI tools in security work (triaging findings, threat modeling, reviewing code, drafting detections). You should have opinions about where AI sharpens security and where it creates new risk. This is unlikely to be a good fit if you're skeptical of AI tools or prefer to do everything by hand. - Hands-on engineering skills: you write scripts, build pipelines, configure AWS guardrails, and ship detections yourself. This is unlikely to be a good fit if your security experience is primarily policy, audits, and presentations without building controls. - Pragmatic risk prioritization: you ship the control that reduces the most risk for the least friction and are comfortable saying "not now" to real-but-low risks. This is unlikely to be a good fit if you treat every finding as equally urgent or chase perfect posture over shippable solutions. - Strong collaboration skills: you work shoulder-to-shoulder with delivery teams and Cloud & DevOps, bringing them along rather than throwing findings over the wall. This is unlikely to be a good fit if your instinct is to gatekeep, block, and police rather than enable. - Marketplace and payments mindset: you care that real customers, pros, and real money flow through the platform and reason about risk in those terms. - Leadership-in-training mindset: you're energized by shaping a practice and leveling it up, setting standards that make engineers around you better, and building toward leading a team—even before a manager title. This is unlikely to be a good fit if you only want to be heads-down with no interest in growing a function or the people on it.

Similar roles