Application Security Lead

HightouchRemote (Fully Remote)
InternshipFully RemoteLead$100,000 - $100,000 / YearLimited info disclosed
37 views0 applications

Description

<div class=&quot;content-intro&quot;><h2>About Hightouch</h2> <p>Hightouch is an Agentic Marketing Platform powered by the industry-leading Composable CDP. With complete brand context, customer data, and performance history in one place, every marketer finally has the power to build and ship end-to-end campaigns themselves. Teams move faster, stay on brand, and get AI marketing that actually works.</p> <p>Founded in 2019 and headquartered in San Francisco, Hightouch enables marketing teams to analyze performance, brainstorm ideas, and generate creative at a speed and quality that wasn&#39;t previously possible.</p> <p>Named a Leader in the 2026 Gartner® Magic Quadrant™ for Customer Data Platforms, Hightouch is trusted by leading enterprises like Domino&#39;s, Spotify, Aritzia, Cars.com, Ramp, and PetSmart.</p> <p>At Hightouch, our mission is to help our customers leverage data and AI to grow their businesses. The team is ambitious, impact-driven, efficient — and we believe humility, kindness, and compassion are essential to our success. If you&#39;re energized by velocity, obsessed with raising the bar, and want to build alongside people who care deeply about each other and our customers, we&#39;d love to meet you.</p></div><h2><strong>About</strong> <strong>the</strong> <strong>Role</strong></h2> <p>This is our first dedicated security hire, and it&#39;s a rare chance to define the function from the ground up. You&#39;ll own Hightouch&#39;s application security posture end-to-end. We have strong engineering fundamentals and a solid foundation; now you&#39;ll shape what security looks like here as we scale from 70 to 140+ engineers.</p> <p>This is a hands-on, high-autonomy role. You&#39;ll spend most of your time in the codebase, not in meetings. You’ll be solving hard problems at the intersection of security and distributed systems:</p> <ul> <li><strong>Multi-tenant</strong> <strong>isolation</strong> on a system running ~1M data syncs per day and ingesting 100K+ events/sec</li> <li><strong>Sub-tenant access control</strong> - for multi-team and multi-brand use cases, requiring differentiated access to configuration and data</li> <li><strong>Security</strong> <strong>architecture</strong> - Build and refine our frameworks for compute isolation and perform threat modeling and hardening of new products</li> <li><strong>Internet-facing APIs</strong> - Our high-throughput, internet-facing architecture services customer data at scale. You’ll improve our rate limiting, abuse detection, and granularity of access control</li> <li><strong>Multi-Region and Multi-Cloud -</strong>&nbsp;Supporting our multi-region and multi-cloud backend, including extending it to launch Hightouch on in new regions to support data residency requirements of our global customer base</li> </ul> <p>You&#39;ll own your roadmap. We&#39;re not looking for someone to run a checklist — we&#39;re looking for someone who can look at our architecture, identify the highest-leverage problems, and go fix them.</p> <p>We are looking for talented, intellectually curious, and motivated individuals who are interested in tackling the problems above. This is a senior role, but we focus on impact and potential for growth more than years of experience. The salary range for this position is $180,000 - $400,000 USD per year, which is location independent in accordance with our remote-first policy. We also offer meaningful equity compensation in the form of ISO options, and offer early exercise and a 10 year post-termination exercise window.</p> <h2><strong>About</strong> <strong>You</strong></h2> <p>You’ve been an early security hire at a SaaS company before and moved the needle on how they approach security. You can read application code, threat model a distributed system, and ship production fixes. You have significant distributed systems expertise so that you can understand and influence what is being built by the product teams and influence from a place of trust.</p> <p>Experience that&#39;s relevant:</p> <ul> <li>Being an early security hire (first 1-3) at a SaaS or data infrastructure company</li> <li>Securing multi-tenant platforms: tenant isolation, authorization models, etc</li> <li>Cloud security on systems that span more than one cloud and operate against customer-owned accounts</li> <li>Design and build of data infrastructure as an early engineer, not just a user. You helped secure it from early design or during major redesigns. You understand how it scales and how it’s secured</li> <li>Privacy-adjacent security (PII handling, data residency, GDPR/CCPA technical controls)</li> </ul> <p>We don&#39;t care about certifications. We care about what you&#39;ve built.</p> <h2><strong>Interview</strong> <strong>Process</strong></h2> <ol> <li> <p><strong>Recruiter</strong> <strong>Screen</strong> <strong>[30m]</strong> - Introductory mutual fit assessment</p> </li> <li> <p><strong>Security Architecture Interview</strong> <strong>[60m]</strong> - Threat model discussion of a real-ish system, followed by a systems design exercise</p> </li> <li> <p><strong>Core interview [90m]</strong> - deep dive on distributed systems knowledge</p> </li> <li> <p><strong>Hiring</strong> <strong>Manager</strong> <strong>Interview</strong> <strong>[60m]</strong> - What you&#39;ve built in the past, how you work</p> </li> <li> <p><strong>Security Program Interview [60m]</strong> with Head of Engineering — How you&#39;ve run security programs in practice: bug bounty, pentest engagements, working with external researchers, and partnering across engineering to drive adoption.</p> </li> </ol><div class=&quot;content-conclusion&quot;><p><strong>E-Verify Statement</strong></p> <p><em>Hightouch participates in E-Verify. After you join the team, we&#39;ll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only — we never use E-Verify to pre-screen applicants.</em></p> <p><em><br></em><a href=&quot;https://www.rhoworld.com/wp-content/uploads/E-Verify_Participation_Poster-1.pdf&quot;><em>E-Verify Notice</em><em><br></em></a><a href=&quot;https://www.rhoworld.com/wp-content/uploads/E-Verify_Participation_Poster_ES-1.pdf&quot;><em>E-Verify Notice (Spanish)</em><em><br></em></a><a href=&quot;https://www.rhoworld.com/wp-content/uploads/ier_poster_final.pdf&quot;><em>Right to Work Notice</em><em><br></em></a><a href=&quot;https://www.rhoworld.com/wp-content/uploads/spanish_ier_poster_final.pdf&quot;><em>Right to Work Notice (Spanish)</em></a></p></div>