Ciphire

Senior Security Engineer

HUD

On-siteSan Francisco · Singapore · Remote (Asia) · Remote (North America)Full-time$105k–260k/yr

Posted Sep 9, 2026 · Listed on HUD's Ashby board, re-checked daily

Apply on HUD's site ↗

SOC 2OSCPGIACAWS

About HUD

HUD's mission is to build reliable, fair and open infrastructure for AI data. We want data to be valuable for the people who create it and trustworthy for the labs that train on it. Our team is a quickly growing group of researchers, engineers and operators building the economy that shapes what AI will become. Backed by $16M from top VCs and YC (W25), our marketplace and platform are used by startups, Fortune 500 companies and frontier labs.

About the role

We’re looking for a Security Engineer to own and build HUD’s security program as our first full-time security hire. You will work closely with the rest engineering to secure our product, cloud infrastructure, data workflows, and internal systems. You’ll also lead incident response, SOC 2, and customer trust.

We are securing up to billions in data assets and are looking for someone who can lead security such that our infrastructure is never compromised.

Responsibilities

  • Lead detection and incident response from signal to alert to postmortem

  • Own HUD’s security roadmap across product security, cloud and infrastructure security, corporate security, incident response, and compliance

  • Secure HUD’s APIs, platform, and data systems through threat modeling, design and code reviews, authentication and authorization controls, secrets management, etc.

  • Build monitoring, detection, and incident-response capabilities; lead investigations and postmortems; and turn incidents and emerging threats into durable improvements

  • Own SOC 2 and customer trust, including control design, security questionnaires, policy management, vendor reviews, and audits

  • Partner with legal, commercial, engineering, and operations to translate customer contracts and data-license requirements into enforceable controls for data access, provenance, permitted use, retention, deletion, isolation, and auditability

Experience

You may be a good fit if you have:

  • Strong security engineering fundamentals and hands-on experience across multiple areas such as infrastructure security, detection and response, identity, etc.

  • Experience leading security incidents end-to-end, from detection and containment through root-cause analysis and follow-up engineering work

  • Experience implementing or operating SOC 2 or a comparable security framework, including translating requirements into real technical and operational controls

  • High agency and sound judgment—you can identify and prioritize the risks that matter, make pragmatic decisions under uncertainty, and personally drive implementation

  • Strong communication skills for working with founders, engineers, operations, legal, auditors, customers, and external partners

Strong candidates may also:

  • Experience as an early security hire or building a security program from scratch at a fast-growing startup

  • Experience securing AI/ML infrastructure, agent execution environments, data platforms, developer tools, or other systems that run untrusted code or process sensitive data

  • Experience protecting licensed, proprietary, or customer-provided data and operationalizing contractual requirements around access, use, retention, and deletion

  • Experience finding CVEs, creating security tooling on GitHub, or with bug bounty programs

  • CVEs, or have created security tooling on GitHub, have conference talks, bug bounty history, or blog posts about incidents/something security related they've done that would also be good

  • OSCP, AWS Security Specialist, OSWE, CKS, or GIAC hands on certifications

We prioritize technical aptitude and learning potential over years of experience. Motivated candidates are encouraged to apply even if they don't meet all criteria.

Team & company details

  • Team Size: ~25 people currently, mostly full-time in-person, but some remote.

  • Our team: Our team includes 4 International Olympiad medalists (IOI, ILO, IPhO), serial AI startup founders, and researchers with publications at ICLR, NeurIPS, etc.

  • Company stage: We have 8 figures in funding and are scaling profitably and quickly to meet very strong demand.

Logistics

  • Employment: Full-time.

  • Location: We have offices in San Francisco or Singapore but are open to remote candidates who can work hours that 70-80% overlap with either San Francisco or Singapore time zones.

  • Visa Sponsorship: We provide support for relocation and visas for strong full-time candidates to the US or Singapore.

  • Timeline: Applications are rolling. The process is 2 technical interviews and a 2-3 day work trial.

What we offer

  • Competitive compensation

  • 100% covered top-of-the-line medical, dental, and vision from Blue Shield of CA (US employees)

  • Lunch and dinner when you’re in the office (in-office employees)

  • Company-wide holiday break (Christmas Eve to New Year’s Day) on top of PTO and paid holidays

  • Other perks including an Equinox membership, 401k, and commuter benefits (US employees)

  • Unlimited* access to tokens for ChatGPT, Claude Code, Cursor, etc. *By unlimited, we mean no one on our token usage leaderboard has ever hit a limit. So we have no idea what the limit is.

Compensation

Actual offers are adjusted for experience and location, but our base salary bands are

  • San Francisco (and other major US cities): $175,000 - $260,000

  • Singapore: $130,000 - $195,000

  • Rest of world: $105,000 - $195,000

Due to high volume, we may not actively respond to every application, but feel free to contact us at recruiting@hud.so or elsewhere if we missed your application!

Apply on HUD's site ↗

Source: HUD on Ashby. Ciphire is not the employer and doesn't take applications.

Related Security Engineering jobs

All Security Engineering jobs →