Talent.com
Information Security Engineer
Information Security EngineerWorkstream • San Francisco, California, United States
Information Security Engineer

Information Security Engineer

Workstream • San Francisco, California, United States
[job_card.variable_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Workstream is a mission-driven company building the all-in-one HR, payroll, and hiring platform for managing the hourly workforce. There are 2.7 billion hourly workers, making up 80% of the global workforce, but this market has been heavily underserved by technology and deserves better. Workstream has been purpose-built for the hourly workforce from day one so that these businesses and their employees can thrive.

Our customers include leading brands from multiple sectors, including Burger King, Carl's Jr. / Hardee's, IHOP, KFC, and Culvers. We are a high growth series B company and quickly expanding our product portfolio to deliver on our vision. We are backed by legendary VCs and industry experts like Founders Fund, BOND, and Coatue.

Grow With Us

We are seeking a

Security Engineer

who is, at heart, a builder. In this role, you won't just be running scans or writing policies; you will be writing code, fixing vulnerabilities, and architecting secure infrastructure alongside our engineering teams.

You will act as the primary "Blue Team" lead, defending Workstream against threats while collaborating with external Red Team communities to stay sharp. Your scope is holistic : you will cover

Application Security, Infrastructure Security, and Corporate Security , ensuring that security is baked into our DNA, not bolted on at the end.

This is a full-time, office-based role requiring presence 5 days a week to foster close collaboration with cross-functional teams –

Monday, Tuesday, and Friday at the Menlo office, and Wednesday and Thursday at the San Francisco office.

Day in the Life

Application Security (AppSec)

Embed yourself in the software development lifecycle (SDLC). Perform code reviews and architectural analysis for new features in

Node.js

and

Ruby on Rails .

Work side-by-side with software engineers to locate, triage, and fix security vulnerabilities (e.g., XSS, SQLi, IDOR) directly in the codebase.

Build and maintain automated security tooling (SAST / DAST) in our CI / CD pipelines.

Secure AI / ML integrations and APIs, including protection against prompt injection, model poisoning, and data exfiltration through AI interfaces

Review and secure implementations of large language models (LLMs) and other AI services used in the platform

Design and implement secure networking, IAM policies, and container security (Kubernetes / Docker).

Monitor system logs and alerts to detect and respond to anomalies in real-time.

Act as the internal Blue Team lead. Collaborate with external Red Teams and bug bounty researchers to understand the latest attack vectors.

Translate Red Team findings into concrete engineering tasks and defensive measures.

Lead incident response simulations (Tabletops) and actual response efforts during security events.

Corporate Security

Oversee internal company security posture, including endpoint protection, identity management ( Okta / SSO ), and zero-trust networking access.

Conduct security training for employees to foster a culture of security awareness.

Design security architecture supporting multi-state and multi-jurisdiction data residency requirements.

Collaborate with legal and other teams on data breach notification procedures and requirements across multiple jurisdictions.

Maintain security documentation for SOC 2 Type II audits and other compliance frameworks.

Who You Are

Technical Qualifications

Engineering Background :

You have a strong background in software engineering. You are comfortable reading and writing production-level code, specifically in

Node.js

and

Ruby on Rails .

Holistic Security Experience :

3+ years of experience covering the "Security Trinity" :

Software Security, Infrastructure Security, and Corporate / IT Security . Experience in SaaS, fintech, or HR technology environments strongly preferred.

Vulnerability Remediation :

Proven track record of not just finding bugs, but working with engineers to solve them. You understand how to implement fixes without breaking functionality.

Cloud Native :

Deep experience securing modern cloud environments (AWS preferred) and containerized applications.

HR / Payroll Security Understanding : Familiarity with security challenges specific to HR and payroll systems, including protection of sensitive employee data (PII, SSN, wage information), multi-tenant architecture security, and regulatory compliance requirements for employment data.

AI / ML Security : Understanding of AI security principles including model security, training data protection, prompt injection vulnerabilities, AI-powered threat detection, and emerging AI-specific attack vectors. Familiarity with AI governance frameworks and responsible AI practices.

Red Team Aware, Blue Team Focused :

You actively follow Red Team communities (CTFs, DefCon, Bug Bounties) to understand the attacker mindset, but your passion lies in building the defense (Blue Team) to stop them.

Empathy for Engineers :

You understand that "perfect security" shouldn't destroy developer velocity. You focus on guardrails, not gates.

Communication :

Ability to explain complex security risks to non-technical stakeholders and provide clear technical guidance to developers.

Bonus Points

Active participation in Bug Bounty programs or CTF competitions.

Experience with compliance frameworks (SOC 2, ISO 27001, HIPAA).

Certifications such as OSCP (Offensive Security Certified Professional) or CISSP.

Experience securing Open APIs.

Experience with multi-tenant SaaS security architecture.

Background in fintech, HR technology, or payroll systems security.

Familiarity with state-specific data residency and privacy requirements.

Knowledge of AI security frameworks.

Understanding of AI bias, fairness, and discrimination issues in employment contexts.

What We Offer

A mission-driven and value-based company dedicated to empower deskless workers and local businesses.

An early employee opportunity at a Series B hyper-growth startup; work with the founding team and industry veterans to accelerate your career.

Competitive salary and equity.

Comprehensive health coverage : medical, dental, and vision. We pay 95% of your premiums for our employees and 85% for dependents.

In office amenities and stocked kitchen.

401K Plan.

Learning / development stipend.

Flexible PTO.

Salary Range

In compliance with the California Pay Transparency Law, the base salary range for this role is between $150,000 - $180,000 in San Francisco. This range is not inclusive of our discretionary bonus or equity package. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.

Workstream provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

We are committed to the full inclusion of all qualified individuals.

#J-18808-Ljbffr

[job_alerts.create_a_job]

Information Security Engineer • San Francisco, California, United States

[internal_linking.similar_jobs]
Information Security Engineer

Information Security Engineer

Atomic Machines • Emeryville, CA, United States
[job_card.full_time]
Atomic Machines is ushering in a new era of micromanufacturing with its Matter Compiler™ technology platform.This platform enables new classes of micromachines to be designed and built by providing...[show_more]
[last_updated.last_updated_30] • [promoted]
AI Security Infrastructure Engineer

AI Security Infrastructure Engineer

Cerebras • San Francisco, CA, United States
[job_card.full_time]
A cutting-edge tech company in San Francisco is seeking a skilled engineer to architect the foundation of AI agents aimed at detecting and stopping adversarial AI threats.You will design and build ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Security Engineer, Content Engineering

Senior Security Engineer, Content Engineering

Practical DevSecOps • San Francisco, CA, United States
[job_card.full_time] +1
Senior Security Engineer, Content Engineering at Practical DevSecOps.Permanent(Full Time / Full-Time).We are looking for a Senior Security Engineer to help us with our content engineering team.We are...[show_more]
[last_updated.last_updated_30] • [promoted]
Infrastructure Engineer (Security)

Infrastructure Engineer (Security)

Vapi • San Francisco, CA, United States
[job_card.full_time]
Infrastructure Engineer – Security at Vapi.This is a hands-on engineering role focused on owning security within our infrastructure and codebase. You’ll design, implement, and automate secure system...[show_more]
[last_updated.last_updated_30] • [promoted]
Security Engineer

Security Engineer

Kaedim • San Francisco, CA, United States
[job_card.full_time]
As a Security Engineer, you will play a critical role in safeguarding our organization’s digital assets and infrastructure. You will be responsible for identifying vulnerabilities, implementing secu...[show_more]
[last_updated.last_updated_30] • [promoted]
Security Engineer : AI Infra Security, On-Site SF + Equity

Security Engineer : AI Infra Security, On-Site SF + Equity

Recruiting From Scratch • San Francisco, CA, United States
[job_card.full_time]
A fast-growing AI infrastructure company in San Francisco is seeking a Security Engineer.You'll own the security function, design security controls, and respond to emerging threats.The ideal candid...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Information Security Engineer

Information Security Engineer

Workstream • San Francisco, CA, United States
[job_card.full_time]
Workstream is a mission-driven company building the all-in-one HR, payroll, and hiring platform for managing the hourly workforce. Workstream has been purpose-built for the hourly workforce from day...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Information Security Engineer

Information Security Engineer

Irvine Technology Corporation • San Francisco, CA, United States
[job_card.full_time]
San Francisco, CA (Hybrid – 3 days on-site).Irvine Technology Corporation (ITC) – a leading provider of technology and staffing solutions. Security Operations & Incident Response.Assist with 24x7 se...[show_more]
[last_updated.last_updated_30] • [promoted]
Information Security Engineer - Black Lotus Labs Threat Researcher (Crimeware)

Information Security Engineer - Black Lotus Labs Threat Researcher (Crimeware)

Lumen Technologies • San Francisco, CA, United States
[job_card.full_time]
Information Security Engineer - Black Lotus Labs Threat Researcher (Crimeware).We are igniting business growth by connecting people, data and applications – quickly, securely, and effortlessly.Toge...[show_more]
[last_updated.last_updated_30] • [promoted]
Information Security Architect

Information Security Architect

Compunnel, Inc. • San Francisco, CA, United States
[job_card.full_time]
We are seeking a Senior / Lead Information Security Architect to design secure cloud architectures, perform system threat modeling, and propose effective security controls for critical workloads.The ...[show_more]
[last_updated.last_updated_30] • [promoted]
Infrastructure Engineer - Security

Infrastructure Engineer - Security

Slash • San Francisco, CA, United States
[job_card.full_time]
Slash is building the future of business banking, one industry at a time.We combine the reliability of traditional banking with industry‑specific features that make businesses more efficient, more ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Enterprise Security Engineer

Enterprise Security Engineer

OpenAI • San Francisco, CA, United States
[job_card.full_time]
Within the OpenAI Security organization, our IT team works to ensure our team of researchers, engineers, and staff have the tools they need to work comfortably, securely, and with minimal interrupt...[show_more]
[last_updated.last_updated_30] • [promoted]
Lead Security Engineer - DevSecOps & Platform Resilience

Lead Security Engineer - DevSecOps & Platform Resilience

Coderabbit • San Francisco, CA, United States
[job_card.full_time]
An innovative tech company in San Francisco is seeking a Lead Security Engineer to architect, harden, and defend its infrastructure. In this role, you'll lead security initiatives and embed security...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
IAM Security Engineer

IAM Security Engineer

Vertex Elite LLC • San Francisco, CA, United States
[job_card.full_time]
Vertex Elite is currently seeking a qualified IAM Security Engineer to join our team.If you or someone you know is interested, please feel free to reach out for more details or share your updated r...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Enterprise Information Security Leader

Enterprise Information Security Leader

Grocery Outlet Inc. • Emeryville, CA, United States
[job_card.full_time]
A grocery retail company is seeking a Sr.Director of Information Security to lead its cybersecurity program.The role involves developing and executing security strategies, overseeing incident respo...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Information Security Engineer

Information Security Engineer

VirtualVocations • San Francisco, California, United States
[job_card.full_time]
A company is looking for an Information Security Engineer (OKTA and Netskope).Key Responsibilities Engineer and operate modern security platforms, optimizing enterprise-level security tooling Co...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Infrastructure Security Engineer

Infrastructure Security Engineer

Harvey • San Francisco, CA, United States
[job_card.full_time]
At Harvey, we’re transforming how legal and professional services operate — not incrementally, but end-to-end.By combining frontier agentic AI, an enterprise-grade platform, and deep domain experti...[show_more]
[last_updated.last_updated_30] • [promoted]
Senior IT Security & Infrastructure Engineer (Temporary)

Senior IT Security & Infrastructure Engineer (Temporary)

Vir Biotechnology, Inc. • San Francisco, CA, United States
[job_card.full_time]
Senior Infrastructure & Security Engineer (Temporary).Senior Infrastructure & Security Engineer (Temporary).Senior Infrastructure & Security Engineer (Temporary). Be among the first 25 applicants.Se...[show_more]
[last_updated.last_updated_30] • [promoted]