Application Security Lead

Hightouch Hightouch · Data AI · Remote · Engineering

This role is for an Application Security Lead at Hightouch, a company that provides an AI platform for marketing and growth teams. The lead will be the first dedicated security hire and will be responsible for defining and owning the company's application security posture end-to-end. The role involves hands-on work in the codebase, focusing on challenges related to multi-tenant isolation, sub-tenant access control, security architecture, securing internet-facing APIs, and multi-region/multi-cloud environments. The ideal candidate has prior experience as an early security hire in a SaaS or data infrastructure company, with expertise in securing multi-tenant platforms, cloud security, and data infrastructure.

What you'd actually do

  1. Own Hightouch's application security posture end-to-end
  2. Solving hard problems at the intersection of security and distributed systems
  3. Build and refine our frameworks for compute isolation and perform threat modeling and hardening of new products
  4. Improve our rate limiting, abuse detection, and granularity of access control
  5. Run security programs in practice: bug bounty, pentest engagements, working with external researchers, and partnering across engineering to drive adoption.

Skills

Required

  • Application security
  • Security architecture
  • Threat modeling
  • Distributed systems expertise
  • SaaS security
  • Multi-tenant platform security
  • Cloud security
  • Data infrastructure security
  • Privacy-adjacent security (PII handling, data residency, GDPR/CCPA technical controls)

Nice to have

  • Experience as a first or second security hire
  • Experience securing systems that span more than one cloud
  • Experience operating against customer-owned accounts
  • Experience securing data infrastructure from early design or during major redesigns

What the JD emphasized

  • first dedicated security hire
  • define the function from the ground up
  • own Hightouch's application security posture end-to-end
  • hands-on, high-autonomy role
  • You'll spend most of your time in the codebase, not in meetings
  • You'll own your roadmap
  • identify the highest-leverage problems, and go fix them
  • early security hire at a SaaS company before
  • moved the needle on how they approach security
  • significant distributed systems expertise
  • influence from a place of trust
  • Being an early security hire (first 1-3) at a SaaS or data infrastructure company
  • Design and build of data infrastructure as an early engineer, not just a user
  • helped secure it from early design or during major redesigns
  • We don't care about certifications. We care about what you've built.