← WORK 목록으로
GLOBALWWR서버/인프라REMOTE

Hightouch: Application Security Lead

Hightouch의 첫 전담 애플리케이션 보안 리드를 채용하는 정규직 포지션입니다. 하루 약 100만 건의 데이터 동기화와 초당 10만+ 이벤트를 처리하는 멀티테넌트 분산 시스템에서 테넌트 격리, 세부 접근 제어, 위협 모델링, 인터넷 노출 API 하드닝, 멀티리전·멀티클라우드 보안 아키텍처를 직접 코드베이스에서 구축·개선합니다. SaaS 초기 보안 담당 경험과 강력한 분산 시스템 역량을 갖춘 시니어 보안 엔지니어에게 적합합니다.

2026.09.14VIEW 67WWR에서 수집
Budget협의
Difficulty전문가
Duration정규직(상시)
Work style원격 가능
Required stack

필요 기술

Full-Stack ProgrammingDistributed SystemsApplication SecurityMulti-CloudMulti-TenancyAPI Security
Project brief

프로젝트 내용

Headquarters: Remote (North America)

About Hightouch

Hightouch is an Agentic Marketing Platform powered by the industry-leading Composable CDP. With complete brand context, customer data, and performance history in one place, every marketer finally has the power to build and ship end-to-end campaigns themselves. Teams move faster, stay on brand, and get AI marketing that actually works.

Founded in 2019 and headquartered in San Francisco, Hightouch enables marketing teams to analyze performance, brainstorm ideas, and generate creative at a speed and quality that wasn't previously possible.

Named a Leader in the 2026 Gartner® Magic Quadrant™ for Customer Data Platforms, Hightouch is trusted by leading enterprises like Domino's, Spotify, Aritzia, Cars.com, Ramp, and PetSmart.

At Hightouch, our mission is to help our customers leverage data and AI to grow their businesses. The team is ambitious, impact-driven, efficient — and we believe humility, kindness, and compassion are essential to our success. If you're energized by velocity, obsessed with raising the bar, and want to build alongside people who care deeply about each other and our customers, we'd love to meet you.

About the Role

This is our first dedicated security hire, and it's a rare chance to define the function from the ground up. You'll own Hightouch's application security posture end-to-end. We have strong engineering fundamentals and a solid foundation; now you'll shape what security looks like here as we scale from 70 to 140+ engineers.

This is a hands-on, high-autonomy role. You'll spend most of your time in the codebase, not in meetings. You’ll be solving hard problems at the intersection of security and distributed systems:

- Multi-tenant isolation on a system running ~1M data syncs per day and ingesting 100K+ events/sec

- Sub-tenant access control - for multi-team and multi-brand use cases, requiring differentiated access to configuration and data

- Security architecture - Build and refine our frameworks for compute isolation and perform threat modeling and hardening of new products

- Internet-facing APIs - Our high-throughput, internet-facing architecture services customer data at scale. You’ll improve our rate limiting, abuse detection, and granularity of access control

- Multi-Region and Multi-Cloud - Supporting our multi-region and multi-cloud backend, including extending it to launch Hightouch on in new regions to support data residency requirements of our global customer base

You'll own your roadmap. We're not looking for someone to run a checklist — we're looking for someone who can look at our architecture, identify the highest-leverage problems, and go fix them.

We are looking for talented, intellectually curious, and motivated individuals who are interested in tackling the problems above. This is a senior role, but we focus on impact and potential for growth more than years of experience. The salary range for this position is $180,000 - $400,000 USD per year, which is location independent in accordance with our remote-first policy. We also offer meaningful equity compensation in the form of ISO options, and offer early exercise and a 10 year post-termination exercise window.

About You

You’ve been an early security hire at a SaaS company before and moved the needle on how they approach security. You can read application code, threat model a distributed system, and ship production fixes. You have significant distributed systems expertise so that you can understand and influence what is being built by the product teams and influence from a place of trust.

Experience that's relevant:

- Being an early security hire (first 1-3) at a SaaS or data infrastructure company

- Securing multi-tenant platforms: tenant isolation, authorization models, etc

- Cloud security on systems that span more than one cloud and operate against customer-owned accounts

- Design and build of data infrastructure as an early engineer, not just a user. You helped secure it from early design or during major redesigns. You understand how it scales and how it’s secured

- Privacy-adjacent security (PII handling, data residency, GDPR/CCPA technical controls)

We don't care about certifications. We care about what you've built.

Interview Process

-
Recruiter Screen [30m] - Introductory mutual fit assessment

-
Security Architecture Interview [60m] - Threat model discussion of a real-ish system, followed by a systems design exercise

-
Core interview [90m] - deep dive on distributed systems knowledge

-
Hiring Manager Interview [60m] - What you've built in the past, how you work

-
Security Program Interview [60m] with Head of Engineering — How you've run security programs in practice: bug bounty, pentest engagements, working with external researchers, and partnering across engineering to drive adoption.

E-Verify Statement

Hightouch participates in E-Verify. After you join the team, we'll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only — we never use E-Verify to pre-screen applicants.

E-Verify Notice
E-Verify Notice (Spanish)
Right to Work Notice
Right to Work Notice (Spanish)

To apply: https://weworkremotely.com/remote-jobs/hightouch-application-security-lead
지원 기회 분석

지원 전에 볼 것

핵심 요구사항

  • SaaS 기업 초기 보안 담당(early security hire) 경험 및 성과
  • 애플리케이션 코드 리딩 및 프로덕션 보안 픽스 배포 능력
  • 분산 시스템 위협 모델링 및 컴퓨트 격리 프레임워크 설계
  • 멀티테넌트 격리 및 서브테넌트 접근 제어 설계
  • 인터넷 노출 고처리량 API의 rate limiting·abuse 탐지 개선
  • 멀티리전/멀티클라우드 백엔드 및 데이터 레지던시 대응

예상 산출물

  • 애플리케이션 보안 로드맵 및 보안 기능 전반
  • 컴퓨트 격리·하드닝 프레임워크
  • 멀티테넌트/서브테넌트 접근 제어 체계
  • API rate limiting·abuse 탐지 강화
  • 신규 리전 확장을 위한 보안 아키텍처

매력 포인트

  • 고단가($180K~$400K)
  • 완전 원격·자율성 높음
  • 0→1 보안 조직 구축 기회
Client signal

클라이언트 정보

플랫폼에서 상세 정보를 확인하세요.
START THE LOOP · CHOOSE

시장과 사람의 답을 봤다면,
다음 결과물의 구조를 고릅니다.

한 번의 결과에 기대지 않고 다시 만들 수 있도록, 문제 발견부터 제작·배포·수익화까지 이어지는 전체 흐름을 익혀보세요.

TTJ CLASS에서 다음 구조 고르기 →
처리 중...