SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
HUD is building infrastructure for RL training data and evals for frontier AI agents, with a marketplace connecting frontier labs and Fortune 500 companies to these capabilities. The company has raised $16M from top VCs and was part of YC W25.
As HUD's first full-time Security Engineer, you will own and build the company's security program from the ground up. You'll work closely with the engineering team to secure the product, cloud infrastructure, data workflows, and internal systems. Given that HUD secures up to billions in data assets, this role is critical to ensuring the infrastructure is never compromised.
Key responsibilities include:
- Leading detection and incident response from signal to alert through postmortem
- Owning HUD's security roadmap across product security, cloud and infrastructure security, corporate security, incident response, and compliance
- Securing APIs, platform, and data systems through threat modeling, design and code reviews, authentication and authorization controls, and secrets management
- Building monitoring, detection, and incident-response capabilities; leading investigations and postmortems; turning incidents and emerging threats into durable improvements
- Owning SOC 2 compliance and customer trust, including control design, security questionnaires, policy management, vendor reviews, and audits
- Partnering with legal, commercial, engineering, and operations to translate customer contracts and data-license requirements into enforceable controls for data access, provenance, permitted use, retention, deletion, isolation, and auditability
The team is ~25 people, mostly full-time in-person, including 4 International Olympiad medalists, serial AI startup founders, and researchers with publications at ICLR and NeurIPS. The company has 8 figures in funding and high revenue growth, scaling profitably to meet strong demand.
REQUIREMENTS:
Core qualifications:
- Strong security engineering fundamentals and hands-on experience across multiple areas (infrastructure security, detection and response, identity, etc.)
- Experience leading security incidents end-to-end, from detection and containment through root-cause analysis and follow-up engineering work
- Experience implementing or operating SOC 2 or comparable security framework, including translating requirements into real technical and operational controls
- High agency and sound judgment—ability to identify and prioritize risks that matter, make pragmatic decisions under uncertainty, and personally drive implementation
- Strong communication skills for working with founders, engineers, operations, legal, auditors, customers, and external partners
Strong additional qualifications:
- Experience as an early security hire or building a security program from scratch at a fast-growing startup
- Experience securing AI/ML infrastructure, agent execution environments, data platforms, developer tools, or systems that run untrusted code or process sensitive data
- Experience protecting licensed, proprietary, or customer-provided data and operationalizing contractual requirements around access, use, retention, and deletion
- Experience finding CVEs, creating security tooling on GitHub, or with bug bounty programs
- Relevant certifications: OSCP, AWS Security Specialist, OSWE, CKS, or GIAC hands-on certifications
- Conference talks, blog posts about incidents, or other public security work
The company prioritizes technical aptitude and learning potential over years of experience and encourages motivated candidates to apply even if they don't meet all criteria.