Jobs Companies Lob Staff Security Engineer, Cloud and Product Security

Über diese Staff Security Engineer, Cloud and Product Security Stelle bei Lob

Lob · Vor Ort · United States

Lob was founded in 2013 by technical co-founders with a vision to connect the world one mailbox at a time. Today, we're transforming the way businesses use direct mail and bringing the power of technology to a traditionally manual channel. 

Our modern logistics and fulfillment engine helps businesses to build and scale high-quality, personalized direct mail programs without the operational burden. As we grow to meet the evolving needs of our customers and expand our product offerings, we’re building a team to shape the future of direct mail.

About the role

This is the senior technical security role at Lob and the first hire in a newly split security function. You will own the engineering side of security: cloud infrastructure, detection and response, application security, and incident response. A dedicated GRC counterpart owns audit, compliance, and customer trust, so you are not the questionnaire desk. You will partner with them, not absorb them.

 

You will report directly to the CTO, manage our application security contractor, and work day to day with our Platform, Logistics, and IT teams. This is a builder role with real autonomy and a mandate to raise the security floor of a system that processes hundreds of requests per second and moves millions of physical mailpieces.

What you will own

Cloud infrastructure security

 

  • Security posture of our AWS environment, including our CNAPP program and cloud misconfiguration risk
  • Security review of infrastructure changes across Terraform, Nomad, and our Cloudflare edge
  • WAF strategy and tuning at the domain level
  • Working with Platform engineers so security is designed in rather than reviewed at the end

 

Detection and response

 

  • Build and own our detection engineering practice on our SIEM, moving us from noisy alert channels to curated, high signal detections
  • Define alert triage ownership, runbooks, and severity criteria
  • Own security incident response: escalation paths, tabletop exercises, post incident reviews
  • Partner with IT on endpoint detection and endpoint vulnerability coverage

 

Application and product security

 

  • Own the vulnerability management program across SCA, SAST, DAST, and container scanning
  • Manage and mentor our application security contractor, and route remediation work into engineering teams effectively
  • Threat modeling and security architecture review for new products and major changes
  • Improve secure SDLC practice in a high velocity, AI-assisted engineering org

 

Penetration testing and assurance

 

  • Technical ownership of our annual independent penetration test: scoping, findings triage, remediation routing, retest coordination
  • Produce the technical evidence our GRC counterpart needs for SOC 2, HIPAA, and Microsoft SSPA, without owning the audit itself

 

Security engineering and automation

 

  • Build tooling and automation rather than process and spreadsheets
  • Apply AI to security operations where it creates real leverage

What we are looking for

Required

 

  • 8 or more years in security engineering, with meaningful depth in cloud security
  • Hands on expertise with AWS security services, IAM design, and infrastructure as code
  • Demonstrated detection engineering experience: you have written detections, tuned them, and cut false positive rates
  • Real incident response experience as a responder or lead, not just as a plan author
  • Fluency in application security sufficient to review findings, judge severity, and argue exploitability with engineers
  • Track record of shipping security improvements through other teams by earning trust rather than filing tickets
  • Comfort as the senior technical security voice in an organization without a large security team

 

Nice to have

 

  • Experience supporting SOC 2 Type 2, HIPAA, or Microsoft SSPA from the engineering side
  • Container and orchestration security, particularly Nomad or Kubernetes
  • Cloudflare, including Zero Trust and WAF
  • Experience in a company handling regulated or consumer-identifiable data at scale
  • Prior experience mentoring or managing engineers or contractors

What this role is not

We want to be direct about scope, because we have deliberately designed this role to be technical.

 

  • You will not be the primary owner of security questionnaires, RFPs, or Trust Center requests
  • You will not own the auditor relationship or the compliance calendar
  • You will not be the sole owner of vendor security reviews or policy authoring

 

Those live with our GRC lead. You will contribute technical input and evidence. You will not run the program.

First 90 days

  • 30 days: own alert triage and incident escalation, know our AWS and edge posture, take over the penetration test findings workflow
  • 60 days: a working detection engineering backlog, endpoint and cloud vulnerability coverage verified end to end, application security contractor's work routed cleanly into engineering teams
  • 90 days: a prioritized security engineering roadmap you own and defend, with the top three infrastructure risks either closed or explicitly accepted

Why this role is interesting

Physical mail is an unusual attack surface. Our security work spans a cloud platform, a print and logistics network, recipient identifiable data, and enterprise customers in regulated industries. You get executive access, a clean mandate, and a function you are helping design rather than inherit.

Compensation Information

The total compensation package for this role is comprised of an annual base salary and RSUs. 

Annual base salary: $197,500 - $220,000 base

<#LI-REMOTE #LI-GD1

“Lob’s salary ranges are based on market data, relative to our size, industry and stage of growth. Salary is one part of total compensation, which also includes equity, perks and competitive benefits. Salary decisions are based on many factors including geographic location, qualifications for the role, skillset, proficiency and experience level. Lob reasonably expects to pay candidates who are offered roles within the provided salary ranges.”

We offer remote working opportunities in AZ, CA, CO, DC, FL, GA, IA, IL, MA, MD, MI, MN, MT, NE, NC, NH, NJ, NV, NY, OH, OR, PA, RI, TN, TX, UT, and WA, unless specified otherwise in the job description above. 

If you are looking for a progressive, fun-spirited, and mentally stimulating environment, come join us at Lob!

Our Commitment to Diversity

Lob is an equal opportunity employer and values diversity of backgrounds and perspectives to cultivate an environment of understanding to have greater impact on our business and customers. We encourage under-represented groups to apply and do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or criminal history in accordance with local, state, and/or federal laws, including the San Francisco’s Fair Chance Ordinance.

Recent awards

#88 on BuiltIn's Best Remote Midsize Companies to Work For in 2025
BuiltIn Best Remote Midsize Companies to Work For in 2024
BuiltIn Best Midsize Companies to Work For 2022

Bereit, sich bei Lob zu bewerben?
Bei Lob bewerben

Wie sich dieses Gehalt für Security Engineer vergleicht

Diese Stelle zahlt $208,750/yrim Einklang mit der üblichen Spanne für Security Engineer Stellen.

$145,000 dem Median $198,388 $264,800

Übliche Spanne $163,972–$240,000/yr, aus 237 vergleichbaren Security Engineer Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Security Engineer ansehen →

Über Lob

Lob is building a suite of APIs for the enterprise. Our most popular API is our print and mail API that enables companies to send physical mail as effortlessly as sending emails. We are growing our customer base and product offerings quickly and are looking for talented software engineers to join our team and shape the future of Lob. As a member of Lob’s engineering team, you will have the unique opportunity to shape the product roadmap, contribute to defining engineering best practices, and create great products on a modern infrastructure.

Why work at Lob?

Built with developers in mind, Lob provides tools that allow businesses to build scalable and powerful applications. The most popular API is a print and mail API that enables companies to send postcards, letters, checks, photos, and more as effortlessly as sending emails. Lob is based in San Francisco, CA and is venture backed with over 3500 customers including Intuit, Twice, and Ubiquiti Networks.

We are a small but dynamic and passionate team based in the continental United States. We are looking to grow our team with talented and driven people who share our vision that APIs will eat up the world. We give our employees a lot of responsibility and the ability to help dictate our product roadmap. You will have fun at work while engaging in challenging projects with the best and brightest.

Perks:

  • Health benefits for you and your dependent(s)
  • Open vacation policy
  • Commuter benefits
  • Wellness program

Alle Jobs bei Lob ansehen →

Ähnliche Jobs

Verisign
Senior InfoSec Tools Engineer
Verisign
⚡ Früh bewerben Reston,Virginia,United States Hybrid $135,800–$183,800
● Neu 👁 Gesehen ✓ Beworben vor 2 Std.
Roblox
Senior Enterprise Security Engineer
Roblox
⚡ Früh bewerben San Mateo, CA, United States Vor Ort $243,290–$295,250
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
Roblox
Principal Enterprise Security Engineer
Roblox
⚡ Früh bewerben San Mateo, CA, United States Vor Ort $293,800–$343,340
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
Roblox
Principal Security Software Engineer, Enterprise IAM
Roblox
⚡ Früh bewerben San Mateo, CA, United States Vor Ort $385,050–$443,200
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
Credence
Security Engineer / Network Engineer (DoD | AWS GovCloud)
Credence
⚡ Früh bewerben McLean, Virginia, United State... Vor Ort $120,000–$150,000
● Neu 👁 Gesehen ✓ Beworben vor 8 Std.
GoDaddy
Senior Security Engineer
GoDaddy
⚡ Früh bewerben United States Vor Ort $154,000–$231,000
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
Postman
Principal Offensive Security Engineer
Postman
⚡ Früh bewerben San Francisco, California, Uni... Vor Ort $275,000–$300,000
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
CHAOS Industries
Cloud Cybersecurity Engineer
CHAOS Industries
⚡ Früh bewerben El Segundo, California, United... Vor Ort $130,000–$180,000
● Neu 👁 Gesehen ✓ Beworben vor 14 Std.
CHAOS Industries
Cybersecurity Engineer, Product Security
CHAOS Industries
⚡ Früh bewerben Washington, District of Columb... Vor Ort $110,000–$190,000
● Neu 👁 Gesehen ✓ Beworben vor 14 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Lob

Alle Jobs bei Lob ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos