SeniorStaff Security Engineer
San Francisco, CA - USA
Job Summary
Company: Init Intelligence
Location: San Francisco CA - in person Monday to Friday
Compensation: $200000 - $300000 base 1-2% equity
Employment Type: Full-time
Visa Sponsorship: Available (H-1B O-1 OPT)
Init is building AI coworkers for IT teams. Its security-focused IT product is an agent that registers as a governed identity in a customers directory requests scoped access for each task escalates to a human for approval runs in a fresh microVM with credentials the model never sees and can operate systems it was never given an API for.
Init was founded in 2026 by Isaiah De La Fuente and Sazzad Islam. The team comes from Stanford MIT and Delve among others.
You will own the security posture of Init and its product end to end: application cloud network and the agent itself. This is a system with very little prior art so the work is genuinely new. You will lead secure design reviews and threat modeling for an agent that holds a governed identity requests scoped access and acts under human approval.
You will build security into the product rather than around it and you will write the security architecture document that technical buyers read before they deploy. For a technical buyer that document often decides the deal more than any certificate does.
- The end-to-end security posture: application cloud network and the agent itself
- Secure design reviews and threat modeling for a governed-identity agent with scoped approval-gated access
- In-product security primitives: full per-customer isolation credentials the agent uses but never sees approval gates on write actions a customer-controlled limit on what the agent can see and do and audit trails complete enough to replay any run
- The written security architecture that gates enterprise deployments and wins over technical buyers
- External validation: penetration testing by a respected firm required compliance frameworks and enterprise security reviews
- Incident readiness and response with breach notification measured in hours
- Continuous cloud and IAM auditing with security scanning secret detection and compliance checks built into CI
- The internal bar for credential handling data egress and endpoint policy
- 4 years of experience with hands-on application and infrastructure security work
- Production-quality code in Python Go Rust or TypeScript
- Practical threat-modeling and vulnerability-identification skills
- Hands-on network and identity security: identity-based controls policy enforcement and workload IAM
- Cloud security depth on at least one major provider including identity federation and infrastructure as code
- The ability to explain a risk trade-off clearly to both an engineer and a CIO in the same week
- Comfort with high autonomy and ambiguity
- Ability to work in person in San Francisco Monday to Friday at startup intensity
- Experience securing agentic or code-execution systems
- Deep expertise in modern isolation: container security kernel-level hardening microVMs
- Offensive security or penetration testing experience
- Has run or owned a bug bounty or vulnerability disclosure program
- Has taken a company through compliance frameworks and enterprise security reviews
- Experience in or alongside enterprise IT and identity: directory services SSO PAM
Meals in office health insurance unlimited PTO.
Culture screen second culture screen technical interview then a one-day on-site.
$44000 - $66000% of First Year Salary22%
- Senior/Staff app infra security
- Codes in Python/Go/Rust/TS
- Threat modeling identity/workload IAM
- Exceptional signal of excellence in some facet: led an important team at a high-growth company top competition results (ICPC IOI) or elite achievement in a sport game or craft
- Top-tier schooling (e.g. Harvard Stanford Berkeley CMU Northeastern Georgia Tech UIUC UW Waterloo Oxford) for a CS/eng degree OR genuinely exceptional experience in lieu of it
- Worked at a great company on a relevant high-caliber team (team matters: AI infra/security at a big tech co not ads)
- Only implemented scoped features built demos without production rigor or depends on other teams for architecture security infra or product decisions