praxy/jobs
← Back to search

Staff Security Engineer, Cloud and Product Security

Lob

indexed from greenhouse · seen 2d ago · board verified 2026-07-12

https://boards-api.greenhouse.io/v1/boards/lob/jobs

Board last validated live · 2026-07-12

Salary
$197.5–220K/yr
Location
United States, US
Employment
Contract
First seen
2d ago
Finance RiskFinance Business ControlRisk Security Compliance

About this role

<div class="content-intro"><p>Lob was founded in 2013 by technical co-founders with a vision to connect the world one mailbox at a time. Today, we're transforming the way businesses use direct mail and bringing the power of technology to a traditionally manual channel. </p> <p>Our modern logistics and fulfillment engine helps businesses to build and scale high-quality, personalized direct mail programs without the operational burden. As we grow to meet the evolving needs of our customers and expand our product offerings, we’re building a team to shape the future of direct mail.</p></div><h2>About the role</h2> <p>This is the senior technical security role at Lob and the first hire in a newly split security function. You will own the engineering side of security: cloud infrastructure, detection and response, application security, and incident response. A dedicated GRC counterpart owns audit, compliance, and customer trust, so you are not the questionnaire desk. You will partner with them, not absorb them.</p> <p> </p> <p>You will report directly to the CTO, manage our application security contractor, and work day to day with our Platform, Logistics, and IT teams. This is a builder role with real autonomy and a mandate to raise the security floor of a system that processes hundreds of requests per second and moves millions of physical mailpieces.</p> <h2>What you will own</h2> <p><strong>Cloud infrastructure security</strong></p> <p> </p> <ul> <li>Security posture of our AWS environment, including our CNAPP program and cloud misconfiguration risk</li> <li>Security review of infrastructure changes across Terraform, Nomad, and our Cloudflare edge</li> <li>WAF strategy and tuning at the domain level</li> <li>Working with Platform engineers so security is designed in rather than reviewed at the end</li> </ul> <p> </p> <p><strong>Detection and response</strong></p> <p> </p> <ul> <li>Build and own our detection engineering practice on our SIEM, moving us from noisy alert channels to curated, high signal detections</li> <li>Define alert triage ownership, runbooks, and severity criteria</li> <li>Own security incident response: escalation paths, tabletop exercises, post incident reviews</li> <li>Partner with IT on endpoint detection and endpoint vulnerability coverage</li> </ul> <p> </p> <p><strong>Application and product security</strong></p> <p> </p> <ul> <li>Own the vulnerability management program across SCA, SAST, DAST, and container scanning</li> <li>Manage and mentor our application security contractor, and route remediation work into engineering teams effectively</li> <li>Threat modeling and security architecture review for new products and major changes</li> <li>Improve secure SDLC practice in a high velocity, AI-assisted engineering org</li> </ul> <p> </p> <p><strong>Penetration testing and assurance</strong></p> <p> </p> <ul> <li>Technical ownership of our annual independent penetration test: scoping, findings triage, remediation routing, retest coordination</li> <li>Produce the technical evidence our GRC counterpart needs for SOC 2, HIPAA, and Microsoft SSPA, without owning the audit itself</li> </ul> <p> </p> <p><strong>Security engineering and automation</strong></p> <p> </p> <ul> <li>Build tooling and automation rather than process and spreadsheets</li> <li>Apply AI to security operations where it creates real leverage</li> </ul> <h2>What we are looking for</h2> <p><strong>Required</strong></p> <p> </p> <ul> <li>8 or more years in security engineering, with meaningful depth in cloud security</li> <li>Hands on expertise with AWS security services, IAM design, and infrastructure as code</li> <li>Demonstrated detection engineering experience: you have written detections, tuned them, and cut false positive rates</li> <li>Real incident response experience as a responder or lead, not just as a plan author</li> <li>Fluency in application security sufficient to review findings, judge severity, and argue exploitability with engineers</li> <li>Track record of shipping security improvements through other teams by earning trust rather than filing tickets</li> <li>Comfort as the senior technical security voice in an organization without a large security team</li> </ul> <p> </p> <p><strong>Nice to have</strong></p> <p> </p> <ul> <li>Experience supporting SOC 2 Type 2, HIPAA, or Microsoft SSPA from the engineering side</li> <li>Container and orchestration security, particularly Nomad or Kubernetes</li> <li>Cloudflare, including Zero Trust and WAF</li> <li>Experience in a company handling regulated or consumer-identifiable data at scale</li> <li>Prior experience mentoring or managing engineers or contractors</li> </ul> <h2>What this role is not</h2> <p>We want to be direct about scope, because we have deliberately designed this role to be technical.</p> <p> </p> <ul> <li>You will not be the primary owner of security questionnaires, RFPs, or Trust Center requests</li> <li>You will not own the auditor relationship or the compliance calendar</li> <li>You will not be the sole owner of vendor security reviews or policy authoring</li> </ul> <p> </p> <p>Those live with our GRC lead. You will contribute technical input and evidence. You will not run the program.</p> <h2>First 90 days</h2> <ul> <li><strong>30 days:</strong> own alert triage and incident escalation, know our AWS and edge posture, take over the penetration test findings workflow</li> <li><strong>60 days:</strong> a working detection engineering backlog, endpoint and cloud vulnerability coverage verified end to end, application security contractor's work routed cleanly into engineering teams</li> <li><strong>90 days:</strong> a prioritized security engineering roadmap you own and defend, with the top three infrastructure risks either closed or explicitly accepted</li> </ul> <h2>Why this role is interesting</h2> <p>Physical mail is an unusual attack surface. Our security work spans a cloud platform, a print and logistics network, recipient identifiable data, and enterprise customers in regulated industries. You get executive access, a clean mandate, and a function you are helping design rather than inherit.<br><br></p> <p><strong>Compensation Information</strong></p> <p>The total compensation package for this role is comprised of an annual base salary and RSUs. <br><br>Annual base salary: $197,500 - $220,000 base<br><br></p> <p><span style="color: white;"><#LI-REMOTE #LI-GD1</span></p><div class="content-conclusion"><p><span style="font-weight: 300;">“Lob’s salary ranges are based on market data, relative to our size, industry and stage of gro

Closes fast — jobs here are removed within hours of going off the company's board.

Apply on Lob