Profound Logo

Profound

Security Engineer

Posted 7 Days Ago
Be an Early Applicant
In-Office
New York, NY, USA
200K-250K Annually
Senior level
In-Office
New York, NY, USA
200K-250K Annually
Senior level
Own and build Profound's security posture across cloud, platform, and corporate environments: harden AWS, run SOC 2 Type II compliance, integrate security scanning into CI/CD, manage vulnerabilities, detect and respond to incidents, run access reviews, maintain risk register, and build practical security policies and incident response.
The summary above was generated by AI

Profound is the marketing platform for the age of AI search. The way brands reach people is being rewritten — AI models like ChatGPT, Perplexity, and Google AI Mode are now the answer layer between companies and their customers. We built the platform marketers use to understand, measure, and win in that world: the analytics, intelligence, and agent automation that turn AI search from a threat into a competitive advantage.

We went from 0 to a $1B valuation in 18 months. Revenue grew 100x last year. Our customers include 15% of the Fortune 500 like Walmart, Wayfair and U.S. Bank, and innovators like Ramp, MongoDB, and Figma. We are backed by Sequoia, Kleiner Perkins, LSVP, and Khosla Ventures — and we are moving fast enough that the people joining now are building the playbook everyone who comes after them will run.

As enterprises integrate AI into critical workflows, they need to trust that the platforms they rely on are secure, compliant, and resilient. That's where you come in.

We're hiring a Security Engineer to own Profound's security posture across our platform, infrastructure, and corporate environment. You'll be the first dedicated security hire, which means you'll shape how we approach access control, vulnerability management, compliance, and incident response from the ground up. You'll partner closely with our Engineering and Infrastructure teams to build practical, scalable security systems that protect customer data and enable rapid growth.

This role is ideal for someone who sees security as a business accelerator, not a blocker, and who thrives on building rather than auditing.

What you'll do

In your first 90 days, you'll focus on our most pressing priorities: partnering with our Infrastructure team to harden our AWS environment, driving SOC 2 Type II continuous compliance (defining controls and closing gaps), and integrating security scanning into our CI/CD pipelines.

Over time, you'll take on broader responsibility across our security posture:

  • Enforce least-privilege access controls and conduct regular access reviews across environments

  • Build and run a vulnerability management program spanning infrastructure, applications, and dependencies

  • Triage and respond to security findings from automated tooling, bug bounty programs, and third-party assessments

  • Partner with Infrastructure to implement detection and monitoring capabilities using log aggregation and SIEM tooling

  • Conduct risk assessments, maintain a risk register, and drive prioritization decisions

  • Build security policies and procedures that reflect how we actually operate

  • Lead post-incident reviews and drive systemic improvements

Must have

  • 5+ years in security engineering, with experience in high-growth SaaS or infrastructure-heavy environments

  • Hands-on experience building or maintaining a SOC 2 compliance program

  • Strong knowledge of AWS security services and cloud security architecture (IAM, VPC, CloudTrail, GuardDuty, Security Hub)

  • Deep understanding of identity and authentication protocols (OAuth, SAML, OIDC)

  • Practical scripting skills in Python or Bash for automating security workflows

Strong plus

  • Experience integrating vulnerability management and security scanning (SAST, DAST, SCA, container scanning) into CI/CD workflows

  • Familiarity with network security fundamentals (firewalls, DNS, VPNs, segmentation, traffic analysis)

  • Experience with infrastructure-as-code security (Terraform, CloudFormation)

  • Background in penetration testing, application security assessments, or CTF competitions

  • Familiarity with data infrastructure security for systems like ClickHouse or PostgreSQL

  • Experience with data processing compliance in analytics-heavy environments

  • Relevant certifications (CISSP, CCSP, AWS Security Specialty, or similar)

Who you are

  • Clear communicator who can translate security risks into business terms for engineering, leadership, and customer-facing teams

  • Systems thinker who reasons about root causes, blast radius, and scalable control design

  • Self-directed with strong judgment and comfort operating with significant autonomy

  • Motivated by building the security foundation for a category-defining AI company

Compensation

For this role, the expected base salary range is $200,000 to $250,000 (NYC). Profound's total compensation package includes base salary, equity, and a full range of benefits and perks. Final compensation depends on skills, experience, qualifications, and location, and will be determined during the interview process. Our recruiting team will share more details about the full package as you move through hiring.

#LI-PRO

 

Note: All official communication from Profound will come from a @tryprofound.com email address. If you're contacted by anyone using a different domain, please disregard and report it as spam.

HQ

Profound New York, New York, USA Office

New York, NY, United States

Similar Jobs

2 Days Ago
Remote or Hybrid
USA
120K-180K Annually
Entry level
120K-180K Annually
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Designs and engineers secure network and cloud architectures across AWS, GCP, Azure, and physical data centers. Responsibilities include threat modeling, network segmentation, monitoring, alerting, automation, attack-surface reduction, and secure connection patterns. The role drives strategic security improvements, partners with product and infrastructure teams, communicates architectural decisions, and mentors engineers. Candidates need deep hybrid networking and cloud security expertise, protocol knowledge, scripting ability, independent problem-solving skills, and strong communication.
Top Skills: AIApplied CryptographyAWSAzureCi/CdDnsGCPGoHttp/SHybrid Cloud NetworkingPrivate EndpointsPythonService MeshesShell ScriptingTcp/IpTlsTransit GatewaysVpcsZero Trust Architecture
4 Days Ago
Remote or Hybrid
United States
80K-120K Annually
Mid level
80K-120K Annually
Mid level
Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Secure LLMs, generative AI systems, ML infrastructure, training pipelines, and AI applications. Responsibilities include threat modeling, architecture reviews, security controls, hardening, vulnerability remediation, data privacy, incident response runbooks, vendor reviews, governance, policy development, and AI security training. The role also supports proof-of-concept security solutions and monitors emerging AI threats.
Top Skills: AnsibleBashETLGdprGenerative AiGoInfrastructure As CodeKubernetesLarge Language ModelsPythonPyTorchScikit-LearnSoc 2TensorFlowTerraform
4 Days Ago
In-Office or Remote
United States
150K-190K Annually
Expert/Leader
150K-190K Annually
Expert/Leader
Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
Serves as the senior technical authority for enterprise browser data protection and security. Owns architecture, roadmap, standards, lifecycle, browser-based DLP controls, integrations, automation, and operational support. Leads complex troubleshooting, major incident response, root-cause analysis, runbook development, and continuous improvement. Partners across cybersecurity, identity, endpoint, network, cloud, risk, compliance, and vendor teams while mentoring engineers and influencing enterprise security design.
Top Skills: Active DirectoryAzure DevopsCasbChrome Enterprise PremiumCisco Secure AccessCloud PlatformsCrowdstrikeCyberarkDigital GuardianDnsEntra IdForcepoint DlpGitGitIslandJAMFMecm/SccmMenlo SecurityMicrosoft Defender XdrMicrosoft Edge For BusinessMicrosoft GraphMicrosoft IntuneMicrosoft Purview DlpMicrosoft SentinelNetskope DlpOktaPalo AltoPalo Alto Prisma BrowserPing IdentityPowershellPythonRest ApisSaseSplunkSwgSymantec DlpTaniumTerraformTls/HttpsVpnZscalerZtna

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account