Security Engineer
San Francisco, CAFull-timePosted 2mo agoStill listed 2w ago
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near San Francisco, CA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Requirements
Credentials this posting asks for.
Job overview
HeyGen is hiring a Security Engineer. HeyGen is seeking a Security Engineer to own the security posture of their fast-growing AI company. This role involves partnering with engineering teams to ship secure features, harden cloud infrastructure, and build compliance and trust programs. The ideal candidate thinks in threat models and ships code, contributing to a high-impact, high-autonomy position.
Key focus areas include Partner with engineering teams as an embedded security expert, Write code, review architectures, and build secure application features and infrastructure components, and Design and implement automated fraud detection systems to mitigate platform abuse.
Successful candidates bring Strong Software Engineering Background With Python And AWS Experience and Familiarity With GRC Frameworks And Compliance Programs. Important skills include Python, AWS, Vulnerability Management, Network Security, IAM, and Secrets Management. Preferred (not required): Drata, Infisical, and Bugcrowd.
Skills & qualifications
Skills
Qualifications
Full job description
About HeyGen At HeyGen, our mission is to make visual storytelling accessible to all. Over the last decade, visual content has become the preferred method of information creation, consumption, and retention. But the ability to create such content, in particular videos, continues to be costly and challenging to scale. Our ambition is to build technology that equips more people with the power to reach, captivate, and inspire audiences. Learn more at www.heygen.com . Visit our Mission and Culture doc here .
Position Summary
As a Security Engineer at HeyGen, you will own the security posture of one of the fastest-growing AI companies in the world. You will partner directly with engineering teams to ship secure features, harden our cloud infrastructure, and build the compliance and trust programs that unlock enterprise deals. This is a high-impact, high-autonomy role for an engineer who thinks in threat models and ships code.
Key Responsibilities
-
Product & Infrastructure Security: Partner with engineering teams as an embedded security expert — writing code, reviewing architectures, and building secure application features and infrastructure components from the ground up.
-
Fraud Detection & Remediation: Design and implement automated fraud detection systems to mitigate platform abuse, credential stuffing, and payment fraud. Partner with product and engineering to build real-time monitoring and rapid-response remediation workflows.
-
Cloud & Vulnerability Management: Own the strategy and execution for hardening our AWS/Python infrastructure. Build and run a robust vulnerability management program, including network security, cloud configuration, and remediation workflows.
-
AI Security: Serve as HeyGen's point person for AI and agentic system security. As we scale our agentic coding and AI agent products, you will ensure these rollouts are designed and deployed with strong security controls.
-
GRC & Compliance: Oversee our SOC 2 compliance operations (currently managed via Drata) and annual audit cycles. Evaluate and roadmap future certifications, including ISO 27001, as the business scales.
-
Trust & Safety Oversight: Provide high-level oversight for platform abuse and content moderation (in partnership with growth and avatar teams), and serve as the escalation point for IT security incidents. Qualifications
-
Strong software engineering background with hands-on Python and AWS experience; you write code, not just policies.
-
Demonstrated experience securing cloud infrastructure and applications — vulnerability management, network security, IAM, and secrets management.
-
Familiarity with GRC frameworks and compliance programs (SOC 2, ISO 27001, or equivalent).
-
Excellent communication skills: able to translate threat models for engineers, compliance requirements for auditors, and security architecture for enterprise CISOs.
-
Comfortable with ambiguity and rapid scale; you prioritize ruthlessly and know when to build vs. buy.
-
Experience with modern security tooling is a plus (Drata, Infisical, Bugcrowd, or equivalents). Why HeyGen:
-
Massive Scale, Unique Problems: We are protecting user identity at one of the fastest growth rates in SaaS history. The security engineering challenges here are genuinely novel.
-
Speed with Guardrails: Our security philosophy is not about saying "no." It is about building guardrails that let the engineering team ship fast without introducing unacceptable risk.
-
Mature Tooling from Day One: We already run Drata for GRC, Infisical for secrets management, and a private bug bounty program via Bugcrowd. You are not starting from zero.
-
Autonomy and Ownership: You will have the visibility and resources to shape HeyGen's entire security roadmap. Small team, big mandate.
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Security EngineerRaindrop · San Francisco, CAPosted 3w agoPosted 3w ago
Security EngineerGreptile · San Francisco, CA · $170–300K/yrPosted 1w agoPosted 1w ago
Senior Security EngineerCohere · Remote · CA · CAD 260–310K/yrPosted 5 days agoPosted 5 days agoBrowser Security EngineerKernel · San Francisco, CAPosted 3w agoPosted 3w ago
Enterprise Security Engineer, Senior & Lead (Enterprise Security - Security AI)Salesforce · San Francisco, CA · $149–260K/yrPosted 1w agoPosted 1w ago
You've read the whole posting — now see how you match it.