SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Endor Labs is an application security platform company that helps teams identify, prioritize, and fix critical software risks by building call graphs of entire software estates. The company serves enterprises across industries and is backed by leading VCs including Dell Technology Capital, Lightspeed, and Sierra Ventures.
This is an early-stage, high-ownership role as one of the first dedicated members of the Security team. You will own application security end-to-end, securing the Endor Labs platform from code to artifact to runtime, including the AI agents driving their SDLC.
Key responsibilities include:
- Owning software supply chain security, defending against risks from open-source packages, third-party binaries, container base images, build tools, and dependencies
- Owning first-party software security including code and container scanning, automated security testing in CI, penetration testing, and software integrity/provenance
- Hardening AI agents by enforcing least-privilege access across MCP, credentials, filesystem, and network resources while maintaining visibility into agent inventory and activity
- Running the responsible disclosure program, including triaging external reports and scaling the review process
- Conducting security design reviews and defining secure architectures in partnership with engineering teams
- Shaping Endor Labs' application security program as one of its earliest dedicated security team members
- Serving as customer zero of the product, using it firsthand and helping shape the roadmap
You will partner closely with the Head of Security & IT, engineering, and product teams in a fast-moving, ambiguous environment where you define priorities without an established playbook.