Hightouch Logo

Hightouch

Product Security Engineer

Posted Yesterday
Remote
Hiring Remotely in USA
180K-400K Annually
Entry level
Remote
Hiring Remotely in USA
180K-400K Annually
Entry level
Own Hightouch’s application security posture as the first dedicated security hire. Secure multi-tenant systems, sub-tenant access controls, distributed architecture, internet-facing APIs, and multi-region, multi-cloud infrastructure. Lead threat modeling, compute isolation, rate limiting, abuse detection, authorization, privacy controls, and security program initiatives. The role is highly hands-on, emphasizing code-level fixes, architecture influence, roadmap ownership, and collaboration with engineering teams.
The summary above was generated by AI
About Hightouch

Hightouch is an Agentic Marketing Platform powered by the industry-leading Composable CDP. With complete brand context, customer data, and performance history in one place, every marketer finally has the power to build and ship end-to-end campaigns themselves. Teams move faster, stay on brand, and get AI marketing that actually works.

Founded in 2019 and headquartered in San Francisco, Hightouch enables marketing teams to analyze performance, brainstorm ideas, and generate creative at a speed and quality that wasn't previously possible.

Named a Leader in the 2026 Gartner® Magic Quadrant™ for Customer Data Platforms, Hightouch is trusted by leading enterprises like Domino's, Spotify, Aritzia, Cars.com, Ramp, and PetSmart.

At Hightouch, our mission is to help our customers leverage data and AI to grow their businesses. The team is ambitious, impact-driven, efficient — and we believe humility, kindness, and compassion are essential to our success. If you're energized by velocity, obsessed with raising the bar, and want to build alongside people who care deeply about each other and our customers, we'd love to meet you.

About the Role

This is our first dedicated security hire, and it's a rare chance to define the function from the ground up. You'll own Hightouch's application security posture end-to-end. We have strong engineering fundamentals and a solid foundation; now you'll shape what security looks like here as we scale from 70 to 140+ engineers.

This is a hands-on, high-autonomy role. You'll spend most of your time in the codebase, not in meetings. You’ll be solving hard problems at the intersection of security and distributed systems:

  • Multi-tenant isolation on a system running ~1M data syncs per day and ingesting 100K+ events/sec

  • Sub-tenant access control - for multi-team and multi-brand use cases, requiring differentiated access to configuration and data

  • Security architecture - Build and refine our frameworks for compute isolation and perform threat modeling and hardening of new products

  • Internet-facing APIs - Our high-throughput, internet-facing architecture services customer data at scale. You’ll improve our rate limiting, abuse detection, and granularity of access control

  • Multi-Region and Multi-Cloud - Supporting our multi-region and multi-cloud backend, including extending it to launch Hightouch on in new regions to support data residency requirements of our global customer base

You'll own your roadmap. We're not looking for someone to run a checklist — we're looking for someone who can look at our architecture, identify the highest-leverage problems, and go fix them.

The base salary range for this position is $180,000 - $400,000 USD per year, which is location independent in accordance with our remote-first policy. We also offer meaningful equity compensation.

About You

You’ve been an early security hire at a SaaS company before and moved the needle on how they approach security. You can read application code, threat model a distributed system, and ship production fixes. You have significant distributed systems expertise so that you can understand and influence what is being built by the product teams and influence from a place of trust.

Experience that's relevant:

  • Being an early security hire (first 1-3) at a SaaS or data infrastructure company

  • Securing multi-tenant platforms: tenant isolation, authorization models, etc

  • Cloud security on systems that span more than one cloud and operate against customer-owned accounts

  • Design and build of data infrastructure as an early engineer, not just a user. You helped secure it from early design or during major redesigns. You understand how it scales and how it’s secured

  • Privacy-adjacent security (PII handling, data residency, GDPR/CCPA technical controls)

We don't care about certifications. We care about what you've built.

Interview Process
  1. Recruiter Screen [30m] - Introductory mutual fit assessment

  2. Security Architecture Interview [60m] - Threat model discussion of a real-ish system, followed by a systems design exercise

  3. Core interview [90m] - deep dive on distributed systems knowledge

  4. Hiring Manager Interview [60m] - What you've built in the past, how you work

  5. Security Program Interview [60m] with Head of Engineering — How you've run security programs in practice: bug bounty, pentest engagements, working with external researchers, and partnering across engineering to drive adoption.

Similar Jobs

54 Minutes Ago
Remote
USA
223K-279K Annually
Junior
223K-279K Annually
Junior
Consumer Web • Healthtech • Professional Services • Social Impact • Software
Build and lead product and application security efforts, partnering with Product and Engineering on secure design, development, code reviews, vulnerability discovery, and security guardrails. Develop AI-native security tooling and support incident response, vulnerability management, penetration testing, and security operations. Help establish secure development practices and scalable security systems across Headway’s platform.
Top Skills: AWSDatadogEcsFargateFastapiGitKafkaLaceworkPagerdutyPostgresPython 3ReactRedisS3SemgrepSnykSparkSqlalchemyTypescript
3 Hours Ago
Easy Apply
Remote or Hybrid
42 Locations
Easy Apply
192K-240K Annually
Senior level
192K-240K Annually
Senior level
Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Own the security architecture and implementation of Datadog’s Bits Code cloud coding agent from design through production. Build threat models for agentic risks such as prompt injection, secure untrusted workload execution through sandboxing, develop security libraries, guide engineering processes, and support production operations. Collaborate across engineering, product, infrastructure, and security teams while making pragmatic trade-offs and participating in on-call responsibilities.
Top Skills: Ai AgentsApplication SecurityCloud SystemsFull-Stack SystemsPrompt InjectionSandboxingSecurity ArchitectureThreat Modeling
9 Hours Ago
Remote
United States
115K-145K Annually
Senior level
115K-145K Annually
Senior level
Financial Services
Serve as an embedded security partner to business, product, data, and technology teams. Assess architectures, conduct threat reviews, develop secure-by-design patterns, guide SaaS and vendor selection, and translate security requirements into practical controls. Support identity, infrastructure, AI workflows, data strategy, M&A integrations, and automated guardrails while enabling teams through training and collaboration.
Top Skills: APIsArtificial IntelligenceAuthenticationAuthorizationCloud ComputingData Loss PreventionDevOpsEncryptionIdentity And Access ManagementObservabilitySaaSSre

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account