SlipstreamJobsFresh Startup & VC-Backed Jobs

Security & Trust Engineer (SF-based)

Alex - San Francisco, CA, United States - In-office - posted 2026-08-26

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Alex is an AI-powered recruiting platform that conducts interviews, screens, and schedules candidates across voice, video, and text. The company has processed over 1M interviews, integrates with 33+ ATS platforms, and serves enterprise customers (VPs of Talent Acquisition, CHROs, CFOs at large employers). You will be Alex's first dedicated Security & Trust Engineer, owning information security, compliance, and AI governance as the company scales its enterprise footprint. AI in hiring is heavily scrutinized by enterprise security teams and regulators, so you'll need to build both robust controls and the credibility to stand in front of CISOs and earn their confidence. Key responsibilities: - Own the complete customer security review process: manage infosec questionnaires, SIGs, CAIQs, vendor risk assessments, DPAs, and security addenda. Unblock deals stalled on security concerns and turn around reviews rapidly without pulling engineering resources. - Build automation and tooling: create answer libraries, evidence repositories, and AI-powered systems to reduce questionnaire turnaround from weeks to days, scaling volume while reducing manual effort. - Become the expert on AI risk and regulation: develop and maintain Alex's point of view on the EU AI Act, NYC LL144, GDPR, state AI and biometric laws, bias auditing, and emerging rules on automated employment decision tools. Keep leadership, Sales, and Product ahead of regulatory changes. - Lead external security engagement: conduct security and AI governance calls with enterprise prospects and customers. Build the trust center, security whitepapers, and AI governance documentation that positions Alex as enterprise-grade and a leading expert. - Run compliance and audit programs: own SOC 2 certification, drive the roadmap for ISO 27001 and ISO 42001, manage auditors and penetration tests, and maintain compliance tooling. - Implement technical controls: partner with Engineering to ensure systems, processes, and technical controls (access management, vendor/subprocessor review, vulnerability triage, incident response, cloud/CI/CD security) genuinely support customer commitments. Build and manage the risk register. - Shift left on security: engage early with Product and Engineering on new features and model changes to address security, privacy, and AI governance questions at design time. You'll report to the CTO, work closely with Engineering, Sales, and Operations, and be based in the San Francisco office full-time (5 days/week). Why this role is compelling: You're the first security hire, so you define the program and narrative from scratch rather than inheriting legacy systems. AI in hiring is the regulatory frontier—you'll build a playbook that doesn't yet exist. Security review is a live bottleneck in enterprise GTM, so your work is immediately visible and revenue-impacting. You'll have direct exposure to the CTO, CEO, Sales leadership, and enterprise customers' security teams. Requirements: - Technical background with strong organizational skills and genuine interest in AI risk and security. - No requirement to be a compliance expert today, but you must be motivated to own this space and capable of going deep fast. - Ability to communicate complex security and regulatory concepts to both technical teams and enterprise CISOs.

Similar roles