Enter a job title or keyword

Senior Security Engineer

Luxer One


Job Location:

Sacramento, CA - USA

Monthly Salary: USD 145000 - 180000
Experience Required: 5-8years
Posted: 2 October 2026 (3 hours ago)
Application Deadline: 30 December 2026
Vacancies: 1 Vacancy

Job Summary

SENIOR SECURITY ENGINEER

Own the security program from cloud infrastructure to AI agents at a hardware-meets-software IoT company moving fast.

About Luxer One

Luxer One builds and deploys smart locker and access systems across multifamily commercial retail and enterprise markets in North America. An Assa Abloy company our platform spans cloud infrastructure mobile applications IoT firmware and a live AI operating system Cortex with more than twenty deployed autonomous AI agents running real operations across the company. We process millions of transactions annually and are trusted by enterprise customers who take security seriously.

We are not a software company that ships firmware on the side. We are not a hardware company trying to do software. We are both fully which makes the security surface broader and more interesting than most.

Why This Role Exists

We have built a lot. Cloud infrastructure running on AWS and GCP. Mobile apps. Embedded firmware on connected locker hardware deployed at thousands of sites. A growing AI operating system with autonomous agents that take real actions against real data. Enterprise customers with real compliance requirements CCPA CPRA ISO 27001 and a pipeline expanding into Canada and Europe.

What we need is one senior security engineer who owns the whole picture: designs the programs runs the tools executes incident response and is the security authority for our AI systems. Not a team. Not a security analyst to hand off to. You.

If you have been the first or founding security hire somewhere before or you are ready to be this is a high-ownership high-impact seat at a company that is genuinely ahead of most on AI adoption and needs someone who can help keep it that way.

Who You Are

You are a security practitioner who builds programs and runs them. The distinction between "architect" and "operator" is not interesting to you you do both because both need to get done. You are hands-on with tooling direct in incident response and thoughtful in design reviews. You treat engineering teams as partners not compliance risks to manage.

You are also someone who has thought seriously about AI security not because it is a trend but because you understand that LLM-based systems and autonomous agents introduce attack surfaces that traditional security tooling does not cover and you want to be the person who figures that out in a production environment.

You are probably at a startup or growth-stage company right now or you have been recently. You have had to make the program work with limited resources build what did not exist and be the person engineering leadership calls when something goes wrong. That is the profile.

You are:

  • A builder who ships you produce controls libraries compliance evidence playbooks and threat models not just recommendations

  • An operator who runs it SIEM tuning alert triage IR execution vulnerability management with real patching accountability

  • A product security partner threat modeling alongside engineers penetration test coordination secure SDLC enforcement in CI/CD pipelines

  • An AI security practitioner you understand prompt injection tool abuse agent identity and runtime monitoring for autonomous systems; you can design the guardrails and detect when they fail

  • Low ego high ownership you take the 3am call you close the finding you write the post-mortem

And you bring:

  • A track record at startup or growth-stage companies you have operated where security is lean and the surface area is large
  • Experience as the founding or first dedicated security hire somewhere or effectively functioning as one
  • Hands-on depth across IT security and product/application security in the same role
  • Real AI or LLM security experience: securing model access auditing agent actions building monitoring for autonomous behavior or applying AI governance frameworks to production systems
  • End-to-end compliance ownership: you have run a compliance program to certification not just contributed to one


Requirements
What Were Looking For
  • Eight or more years of security experience with clear ownership across both IT and product security in the same role
  • Demonstrated experience as a founding or first security hire or the functional equivalent at a startup or growth-stage company
  • Hands-on security operations depth: SIEM IR execution vulnerability management real incident ownership
  • Product security experience: threat modeling pen test coordination secure SDLC enforcement alongside engineering teams
  • AI or LLM security experience securing model access auditing agent actions building guardrails for autonomous systems or applying AI governance frameworks to production deployments
  • End-to-end compliance program ownership: ISO 27001 SOC 2 or equivalent not just participation full ownership
  • Familiarity with AI governance frameworks: NIST AI RMF ISO 42001 or emerging regulatory requirements
  • Cloud security depth AWS or GCP CSPM IAM cloud incident response
  • Strong written and verbal communication policy post-mortems executive briefings customer-facing security conversations
Strongly Preferred
  • Experience securing IoT connected hardware or firmware-based products
  • Hands-on agentic AI security experience MCP tool-use APIs multi-agent systems autonomous agent monitoring
  • Privacy engineering depth CCPA/CPRA operational compliance DSAR handling consent management
  • Relevant certifications: CISSP GIAC (GCIH GPEN GCIA) CIPP/US or CIPP/E ISO 27001 Lead Implementer AIGP or ISO 42001 Lead Implementer
  • Experience with Wiz Datadog Security CrowdStrike or similar modern security tooling


Benefits
Location & Work Model
  • Sacramento CA. On-site or hybrid
Benefits
Luxer Has Got You Covered!
  • You will have a 401k with up to 4.5% matching untracked vacation and a hybrid work schedule.
  • We promote education through tuition reimbursement.
  • You will also have medical dental vision and life insurance programs as well as employee assistance programs.
  • Youll have opportunities to advance.
  • Were fans of helping our employees learn different aspects of the business be challenged with new tasks be mentored and grow.
  • We promoted 42% of our employees last year!
Luxer One is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin age disability veteran status or any other legally protected status.

Compensation

The pay range for this role is $00 per year depending on experience skills and location. This range reflects what we believe in good faith wed pay for this position at the time of posting and final offers may vary based on qualifications and business needs.


Required Skills:

About Luxer One Luxer One builds and deploys smart locker and access systems across multifamily commercial retail and enterprise markets in North America. An Assa Abloy company our platform spans cloud infrastructure mobile applications IoT firmware and a live AI operating system Cortex with more than twenty deployed autonomous AI agents running real operations across the company. We process millions of transactions annually and are trusted by enterprise customers who take security seriously. We are not a software company that ships firmware on the side. We are not a hardware company trying to do software. We are both fully which makes the security surface broader and more interesting than most. Why This Role Exists We have built a lot. Cloud infrastructure running on AWS and GCP. Mobile apps. Embedded firmware on connected locker hardware deployed at thousands of sites. A growing AI operating system with autonomous agents that take real actions against real data. Enterprise customers with real compliance requirements CCPA CPRA ISO 27001 and a pipeline expanding into Canada and Europe. What we need is one senior security engineer who owns the whole picture: designs the programs runs the tools executes incident response and is the security authority for our AI systems. Not a team. Not a security analyst to hand off to. You. If you have been the first or founding security hire somewhere before or you are ready to be this is a high-ownership high-impact seat at a company that is genuinely ahead of most on AI adoption and needs someone who can help keep it that way. Who You Are You are a security practitioner who builds programs and runs them. The distinction between architect and operator is not interesting to you you do both because both need to get done. You are hands-on with tooling direct in incident response and thoughtful in design reviews. You treat engineering teams as partners not compliance risks to manage. You are also someone who has thought seriously about AI security not because it is a trend but because you understand that LLM-based systems and autonomous agents introduce attack surfaces that traditional security tooling does not cover and you want to be the person who figures that out in a production environment. You are probably at a startup or growth-stage company right now or you have been recently. You have had to make the program work with limited resources build what did not exist and be the person engineering leadership calls when something goes wrong. That is the profile. You are: A builder who ships you produce controls libraries compliance evidence playbooks and threat models not just recommendations An operator who runs it SIEM tuning alert triage IR execution vulnerability management with real patching accountability A product security partner threat modeling alongside engineers penetration test coordination secure SDLC enforcement in CI/CD pipelines An AI security practitioner you understand prompt injection tool abuse agent identity and runtime monitoring for autonomous systems; you can design the guardrails and detect when they fail Low ego high ownership you take the 3am call you close the finding you write the post-mortem And you bring: A track record at startup or growth-stage companies you have operated where security is lean and the surface area is large Experience as the founding or first dedicated security hire somewhere or effectively functioning as one Hands-on depth across IT security and product/application security in the same role Real AI or LLM security experience: securing model access auditing agent actions building monitoring for autonomous behavior or applying AI governance frameworks to production systems End-to-end compliance ownership: you have run a compliance program to certification not just contributed to one What Youll Do Security Program Design and Operations Own security policy standards and controls across IT and Product and keep them current as the company evolves Operate the security monitoring and detection function: SIEM management alert triage threat hunting Lead incident response end to end detection containment remediation root cause post-mortem Run vulnerability management across IT assets and product surfaces with enforced patching SLAs Select implement and manage the security tooling stack SIEM EDR CSPM secrets management IAM DLP Execute security awareness training and phishing simulation programs Product Security Partner with engineering teams on threat modeling secure design reviews and release readiness Coordinate penetration testing and bug bounty programs scoping vendor management findings triage remediation tracking Enforce secure SDLC practices: code scanning dependency auditing secrets detection in CI/CD pipelines Own the security posture for IoT and firmware products device fleet monitoring OTA security hardware security co


Required Education:

What Were Looking ForEight or more years of security experience with clear ownership across both IT and product security in the same roleDemonstrated experience as a founding or first security hire or the functional equivalent at a startup or growth-stage companyHands-on security operations depth: SIEM IR execution vulnerability management real incident ownershipProduct security experience: threat modeling pen test coordination secure SDLC enforcement alongside engineering teamsAI