Security Engineer
About the Role
Town holds the keys to a person's entire working life. To do real work on someone's behalf, it reads their email, moves through their calendar, acts in their docs, Slack, and CRM. This means that security is absolutely paramount. We're looking for a dedicated Security Engineer to own that surface end to end. You'll set the security bar for a company whose whole premise is trusted, autonomous access to sensitive data. That means securing the product and the agent that acts inside it, hardening the infrastructure and data pipeline behind it, and building the practices - threat modeling, secure SDLC, incident response, etc. - that let us move fast without betraying that trust.
Responsibilities
- Own application and product security across the Town assistant and the agent action surface — the systems that read and act on user data across email, calendar, docs, Slack, and CRM.
- Threat-model autonomous agent behavior: prompt injection, tool misuse, the "lethal trifecta" of untrusted input + sensitive data + external action, and the guardrails that contain it.
- Secure the data pipeline behind Town's persistent model of each user — encryption, tenant isolation, access controls, and secrets management.
- Harden our cloud infrastructure and third-party OAuth integrations (Google, Slack, CRM) against real-world attacks.
- Build the secure development lifecycle: design reviews, code review for security, dependency and supply-chain hygiene, and the tooling to scale it.
- Stand up and run incident response — detection, triage, and clean postmortems.
- Partner across engineering to make the secure path the easy path.
Qualifications
- Extensive experience in security engineering, with real depth in application and/or infrastructure security.
- Ability to read and write production code — you fix problems, not just file them.
- Experience securing a multi-tenant SaaS product handling sensitive user data at scale.
- Proficiency in cloud security (AWS and/or GCP), authn/authz, secrets, and encryption in practice.
- Instinctive threat-modeling skills and the ability to explain risk to engineers and founders without hand-waving.
- Desire to own security from the ground up and move at startup speed.
- Energy and enthusiasm for working in person, 5 days a week at our office in downtown SF.
Location
In-person in San Francisco's Financial District, five days a week.
Compensation
$250K - $300K
Location: San Francisco; Employment Type: Full-time; Location Type: On-site; Department: EPD