Lead Security Engineer, Internal and IT
- Location
- New York City, NY
- Work type
- Full Time
- Posted
- 2026-07-27
Job description
Responsibilities
Security (primary focus)
Own Artemis’s internal security posture end to end, including endpoint security, identity and access management, network security, email security, and cloud security for our corporate environment
Design and run our identity strategy across SSO, MFA, conditional access, and privileged access management
Build and operate our vulnerability management program, including patching, endpoint hardening, and continuous monitoring
Lead incident response for internal security events, from detection and containment through investigation and post-incident review
Drive our compliance and certification work (SOC 2 Type II, ISO 27001, and others as we grow), including scoping, evidence collection, and working with external auditors
Build and run the security awareness program, including ongoing training, phishing simulations, and role-specific education
Set and maintain security policies, standards, and internal documentation that scale with the company
Own vendor risk and third-party security reviews for tools and partners we bring in
Partner with product security and engineering leadership to keep internal and product security aligned
You’ll be working hands-on with the best security tool in the world, Artemis!
IT (secondary but critical)
Own the IT architecture
Selecting which IT provider we will use and making any changes, if necessary
Manage the tools and configurations that keep the team productive and secure across Google Workspace, Slack, our identity provider, MDM, and related systems
Contribute to the design and security of our office network, AV, and physical access controls
Qualifications
5+ years of hands-on experience in security engineering, IT security, or corporate security, with real ownership of internal security programs at a top-tier software/tech company
Deep expertise in one or more of the following: identity and access management, endpoint security, cloud security (AWS/GCP/Azure), or SaaS security
Hands-on experience with SOC 2 and/or ISO 27001 audits, including scoping, evidence collection, and working with auditors
Strong understanding of modern attacker tradecraft — you know how real breaches happen, not just what the frameworks say
Direct experience leading incident response for internal security events, from detection through post-mortem
Familiarity with modern security tooling across EDR, SIEM, IAM, MDM, DLP, email security, and vulnerability management
Strong systems thinking — you can balance security rigor with the reality of a fast-moving startup
Clear communicator who can translate security tradeoffs to leadership and non-technical teams
Comfort operating with autonomy in an early-stage environment and building programs from scratch, without a manager or team backing you up
Nice to Have
Prior experience as the first or founding internal security hire at a startup
Background as a practitioner in cybersecurity — SOC, threat detection, red team, or product security experience
Relevant certifications (CISSP, OSCP, GCIA, GCIH, CISA, or equivalent)
Experience with security operations tooling that Artemis itself sells (SIEM, XDR, detection & response platforms)
Familiarity with regulated frameworks beyond SOC 2 and ISO (FedRAMP, HIPAA, PCI, GDPR)