Staff Security Engineer, Cloud and Product Security
- Company
- Lob
- Location
- Remote
- Work type
- Full Time
- Posted
- 2026-08-07
Job description
About the role
This is the senior technical security role at Lob and the first hire in a newly split security function. You will own the engineering side of security: cloud infrastructure, detection and response, application security, and incident response. A dedicated GRC counterpart owns audit, compliance, and customer trust, so you are not the questionnaire desk. You will partner with them, not absorb them.
You will report directly to the CTO, manage our application security contractor, and work day to day with our Platform, Logistics, and IT teams. This is a builder role with real autonomy and a mandate to raise the security floor of a system that processes hundreds of requests per second and moves millions of physical mailpieces.
What you will own
Cloud infrastructure security
Security posture of our AWS environment, including our CNAPP program and cloud misconfiguration risk
Security review of infrastructure changes across Terraform, Nomad, and our Cloudflare edge
WAF strategy and tuning at the domain level
Working with Platform engineers so security is designed in rather than reviewed at the end
Detection and response
Build and own our detection engineering practice on our SIEM, moving us from noisy alert channels to curated, high signal detections
Define alert triage ownership, runbooks, and severity criteria
Own security incident response: escalation paths, tabletop exercises, post incident reviews
Partner with IT on endpoint detection and endpoint vulnerability coverage
Application and product security
Own the vulnerability management program across SCA, SAST, DAST, and container scanning
Manage and mentor our application security contractor, and route remediation work into engineering teams effectively
Threat modeling and security architecture review for new products and major changes
Improve secure SDLC practice in a high velocity, AI-assisted engineering org
Penetration testing and assurance
Technical ownership of our annual independent penetration test: scoping, findings triage, remediation routing, retest coordination
Produce the technical evidence our GRC counterpart needs for SOC 2, HIPAA, and Microsoft SSPA, without owning the audit itself
Security engineering and automation
Build tooling and automation rather than process and spreadsheets
Apply AI to security operations where it creates real leverage
What we are looking for
Required
8 or more years in security engineering, with meaningful depth in cloud security
Hands on expertise with AWS security services, IAM design, and infrastructure as code
Demonstrated detection engineering experience: you have written detections, tuned them, and cut false positive rates
Real incident response experience as a responder or lead, not just as a plan author
Fluency in application security sufficient to review findings, judge severity, and argue exploitability with engineers
Track record of shipping security improvements through other teams by earning trust rather than filing tickets
Comfort as the senior technical security voice in an organization without a large security team
Nice to have
Experience supporting SOC 2 Type 2, HIPAA, or Microsoft SSPA from the engineering side
Container and orchestration security, particularly Nomad or Kubernetes
Cloudflare, including Zero Trust and WAF
Experience in a company handling regulated or consumer-identifiable data at scale
Prior experience mentoring or managing engineers or contractors
What this role is not
We want to be direct about scope, because we have deliberately designed this role to be technical.
You will not be the primary owner of security questionnaires, RFPs, or Trust Center requests
You will not own the auditor relationship or the compliance calendar
You will not be the sole owner of vendor security reviews or policy authoring
Compensation Information
The total compensation package for this role is comprised of an annual base salary and RSUs.
Annual base salary: $197,500 - $220,000 base
Skills Required
8 or more years in security engineering, with meaningful depth in cloud security
Hands on expertise with AWS security services, IAM design, and infrastructure as code
Demonstrated detection engineering experience: written detections, tuned them, and cut false positive rates
Real incident response experience as a responder or lead, not just as a plan author
Fluency in application security sufficient to review findings, judge severity, and argue exploitability with engineers
Track record of shipping security improvements through other teams by earning trust rather than filing tickets
Comfort as the senior technical security voice in an organization without a large security team
Experience supporting SOC 2 Type 2, HIPAA, or Microsoft SSPA from the engineering side
Container and orchestration security, particularly Nomad or Kubernetes
Cloudflare, including Zero Trust and WAF
Experience in a company handling regulated or consumer-identifiable data at scale
Prior experience mentoring or managing engineers or contractors