Principal Security Engineer
Indexed description
Head of Security
San Francisco (On-site, 5 days/week) · Full-time
About the role
Code Red Partners is exclusively partnering with a San Francisco investment firm on its first dedicated security hire.
In just a few years they've scaled from launch to managing billions, powered by a very small and exceptionally technical team. Their edge is a research environment built for speed: highly autonomous, permissive by design, and increasingly built and deployed by AI agents rather than by hand.
This is a builder's role first and a leadership role second. You will architect and implement the security of their infrastructure yourself. Title and level are flexible for the right person, from senior individual contributor through CISO; what isn't flexible is that this is a hands-on seat.
What you'll own
- Secure cloud infrastructure on AWS from the ground up: account architecture, IAM and least-privilege at scale, network boundaries, and secrets management
- A CI/CD and deployment pipeline that researchers actually want to use, where the secure path is the fast path
- Infrastructure-as-code guardrails (Terraform or Pulumi) and policy-as-code, so researchers self-serve inside safe boundaries
- The security model for agent-driven development: sandboxing and isolation of code that AI agents generate and deploy, with least-privilege execution and egress control
- Protection of the firm's most sensitive intellectual property against exposure and exfiltration
- Vendor and tooling selection, with a genuine budget to bring in what you need
What we're looking for
- You have personally built and owned secure cloud infrastructure, not just reviewed or assessed it. You've authored the IaC others build on and configured IAM at real scale
- Deep AWS, and fluency with modern platform tooling (Terraform/Pulumi, containers, CI/CD)
- Experience isolating untrusted or agent-generated code (containers, gVisor, Firecracker, egress controls, or similar), or a clear, considered view of how you'd approach it
- You've been the sole or founding security owner somewhere, with a budget and no team to hide behind
- You work well with researchers and engineers who won't change how they work, and you make security the path of least resistance rather than a gate
- High learning velocity. Securing agent-driven development is a new problem everywhere; we're hiring for how you think, not for a matching résumé
Details
- On-site in San Francisco, five days a week. Relocation supported
- Compensation is set at fund level and is highly competitive 7-figures TC annually for the right person
- This is a foundational hire with significant autonomy, budget, and direct exposure to firm leadership
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search