SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
ConductorOne is hiring a Senior Security Engineer to join an early-stage security team with broad responsibility spanning security engineering, application security, cloud security, and compliance. This is a hands-on generalist role where you'll build AI-native automation and agents to orchestrate security into the development lifecycle, rather than performing manual security reviews.
You'll define and drive security standards, build purpose-built agents and skills that automate repetitive security work (triage, enrichment, review), and shift security left by embedding risk-based review into design specs and architecture decisions. The role emphasizes solving problems systemically—helping engineering teams implement fixes rather than just handing them findings lists.
Key responsibilities include: leading threat modeling and risk assessment for high-risk features; assessing security risks from agentic development and AI-powered product features; partnering with engineering on API security standards and code reviews; building security tooling and observability; identifying and leading multi-team remediation of systemic risks; and contributing to compliance initiatives (SOC 2, ISO 27001/42001).
You'll work primarily with Go and AWS, with a tech stack emphasizing automation over manual processes. The company values practical results and good judgment in applying automation, not just familiarity with latest tools. You're expected to show real hands-on experience building agents and automation that replaced manual security work—candidates should be prepared to share projects, demos, or walkthroughs demonstrating this capability.
The role requires proven experience securing enterprise SaaS applications (authentication, authorization, input validation), securing deployment and change-management mechanisms, hands-on code review experience (ideally Go, Python, or Rust), and comfort with AWS and cloud infrastructure. Background in Software Engineering, Platform Engineering, Systems Engineering, Network Engineering, Cloud Security, or Application Security is expected. Nice-to-haves include Kubernetes, service mesh, PKI/network technologies, experience building internal security tooling, or prior work at high-growth SaaS or identity/access management companies.
Quarterly in-person participation required at San Francisco or Portland office.