SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead Security Engineer

Salient - San Francisco, CA, USA - Hybrid - posted 2026-09-26

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salient builds AI agents for regulated financial services, automating loan servicing, compliance, collections, recovery, insurance claims, and disputes for banks and specialty lenders. The company is backed by a16z and Y Combinator, has raised $75M in Series A funding, is cash flow positive with mid-eight figure ARR, and serves over 20% of the auto lending industry. You will be hired as a hands-on Lead Security Engineer—a Staff-level individual contributor role reporting to senior leadership. This is Salient's first dedicated security hire, with reserved support from infrastructure, IT, and People Operations. You will own the complete security operating system, including compliance operations, boundary testing, access and vulnerability management, detection and response, and automation to make all of it repeatable and provable. Work will be sequenced by risk in collaboration with leadership. Key responsibilities: • Establish operating procedures for SOC 2, PCI, enterprise security questionnaires, and bank-specific security requirements, keeping implementation, approval, submission, and acceptance separate. • Conduct security testing across cloud/IAM, application, payment, and AI boundaries, including synthetic tests covering recordings, transcripts, logs, tools, storage, and providers. • Investigate access anomalies and implement stronger IAM/PAM controls and monitoring. • Execute network and vulnerability scanning, tracking every finding through service-owner remediation, retest, or authorized exception. • Develop incident runbooks, useful detections, and proven handoffs between security, service teams, and backup personnel. • Build automation for security controls and evidence: tested evidence connectors, asset reconciliation, obligation tracking, and claim-review workflows. The role requires shipping weekly with a small team and deciding with incomplete information. You will be a software engineer first, writing production-quality code and building tested tooling and automation. The team typically works around 60 hours per week, beginning at 8:00 AM, with four days spent collaborating in person at the San Francisco office. Requirements: • Own outcomes end to end; ship weekly with a small team while deciding with incomplete information. • Software engineer first: write production-quality code and build tested tooling and automation. • Hands-on experience securing cloud infrastructure and identity and access (IAM/PAM), including investigating suspicious access. • Prioritize by real risk, be clear about what isn't covered, and explain tradeoffs to leadership. Nice to have: • Experience operating SOC 2, PCI, or bank security controls and producing audit evidence. • Experience leading SOC 2 or PCI audits with external auditors. • Experience with detection engineering, incident response, or vulnerability management. • Interest or experience in threat-modeling AI systems, LLM tool use, or data flows through model providers. • Clear writing for runbooks, questionnaires, and customer security reviews; track record of partnering with engineering teams. • Experience with financial services, payment data, or other regulated consumer data.

Similar roles