> job detail
A
👑Data Leadership
Principal / Staff Security Engineer
AiDASH, Inc. · Palo Alto, California, United States
// classified as
Data Leadership (Heads of data, directors, managers.)
posted
1d ago
location
Palo Alto, California, United States
languages
c, shell
tools
—
> stack
cshell
> description
<div class="content-intro"><p><strong>About AiDASH</strong><br><br>AiDASH is an enterprise AI company and the leading provider of vegetation risk intelligence for electric utilities. Powered by proprietary VegetationAI™ technology, AiDASH delivers a unified remote grid inspection and monitoring platform that uses a SatelliteFirst approach to identify and address vegetation and other threats to the grid. With a prevention-first strategy to mitigate wildfire risk and minimize storm impacts, AiDASH helps more than 140 utilities reduce costs, improve reliability, and lower liability across their networks. AiDASH exists to safeguard critical utility infrastructure and secure the future of humanAIty™. Learn more at <a href="https://www.aidash.com." target="_blank">www.aidash.com.</a></p>
<p>We are a Series C growth company backed by leading investors, including Shell Ventures, National Grid Partners, G2 Venture Partners, Duke Energy, Edison International, Lightrock, Marubeni, among others. We have been recognized by Forbes two years in a row as one of “America’s Best Startup Employers.” We are also proud to be one of the few software companies in Time Magazine’s “America’s Top GreenTech Companies 2024”. <a href="https://www2.deloitte.com/us/en/pages/technology-media-and-telecommunications/topics/north-america-technology-fast-500.html?utm_source=bngaiwebsite&utm_medium=referral&utm_campaign=evolve-banner" target="_blank"><u>Deloitte Technology Fast 500</u></a>™ recently ranked us at No. 12 among San Francisco Bay Area companies, and No. 59 overall in their selection of the top 500 for 2024. </p>
<p>Join us in Securing Tomorrow!</p></div><p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">The Role</span></span></strong><span data-ccp-props="{"335559738":200,"335559739":100}"> </span></p>
<p><span data-contrast="auto">AiDASH protects the critical infrastructure that delivers power to tens of millions of people. We are SOC 2 Type II certified today, and we're working toward ISO 27001 and ISO 42001 certifications in 2027. As we embed GenAI more deeply into our SaaS products (RAG pipelines, agentic / MCP services) and roll out AI-assisted development internally, the threat landscape is shifting fast. Autonomous adversaries, Mythos-class threat actors, prompt injection, model exfiltration, and vibe-coded internal apps spun up by non-engineers are now part of the daily attack surface.</span><span data-ccp-props="{"335559739":120}"> </span></p>
<p><span data-contrast="auto">We're hiring a Principal or Staff Security Engineer to be our deepest technical voice on security — covering DevSecOps, AI/LLM security, cloud and endpoint defense, IT-Security, and the governance work that will land us ISO 27001 and 42001 certifications in 2027. You'll architect the strategy, pick the right tools where gaps exist, run the audits, and grow the function. You will report to senior leadership and partner with platform, ML, DevOps, and IT leadership across the company.</span><span data-ccp-props="{"335559739":120}"> </span></p>
<p><span data-contrast="auto">If you've been waiting for a chance to lead the security program at a Series C AI company that ships production AI to critical infrastructure operators, this is that role.</span><span data-ccp-props="{"335559739":120}"> </span></p>
<p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">The Team</span></span></strong><span data-ccp-props="{"335559738":200,"335559739":100}"> </span></p>
<p><span data-contrast="auto">You'll partner with our existing security and compliance team based in India — a security engineer plus two compliance specialists, currently within the DevOps organization — and serve as the most senior security IC at AiDASH and the company's authority on AI/LLM security. This role represents the next phase of our security investment: bringing senior-IC depth, AI-native security leadership, and modern detection engineering to a program that has so far been operated alongside DevOps.</span><span data-ccp-props="{"335559739":120}"> </span></p>
<p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">How you'll make an impact:</span></span></strong></p>
<ul>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 3">DevSecOps</span><span data-ccp-parastyle="heading 3"> & AppSec</span></span></strong><span data-ccp-props="{"335559738":160,"335559739":80}"> </span>
<ul>
<li><span data-contrast="auto">Operate and mature our AppSec toolchain across CI/CD — SAST, DAST, SCA, secrets scanning, and IaC policy-as-code. Deepen coverage and evaluate additional tooling where gaps are real</span></li>
<li><span data-contrast="auto">Run threat modeling and secure-design reviews; champion shift-left so security is part of every PR, not a gate at the end</span></li>
<li><span data-contrast="auto">Operate the AIBOM / SBOM toolchain; enforce risk-tiered dependency controls and extend SLSA practices to model artifacts</span></li>
</ul>
</li>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 3">AI & LLM Security</span></span></strong>
<ul>
<li><span data-contrast="auto">Harden production GenAI deployments on AWS (managed model APIs, agentic / MCP services) — IAM, VPC routing, prompt-layer guardrails, output filtering, rate/cost controls</span></li>
<li><span data-contrast="auto">Codify OWASP LLM Top 10 and MITRE ATLAS controls into the SDLC; introduce LLM eval-as-gate in CI</span></li>
<li><span data-contrast="auto">Govern internal AI-assisted developer tooling — DLP for what egresses to external model providers, sensitive-data discovery in prompts, and acceptable-use telemetry</span></li>
<li><span data-contrast="auto">Stand up controls for vibe-coded apps and shadow AI: discover, classify, gate with sane defaults, and bring under the SDLC</span></li>
</ul>
</li>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 3">ISO 27001 / 42001 & Security Governance</span></span></strong><span data-ccp-props="{"335559738":160,"335559739":80}"> </span>
<ul>
<li><span data-contrast="auto">Lead the company's path to ISO 27001 and ISO 42001 (AI Management System) certifications in 2027 — scope the management systems, run gap assessments, build the control sets, and steer the audit cycles</span></li>
<li><span data-contrast="auto">Maintain our SOC 2 Type II posture; manage the evidence pipeline, control mappings, and external auditor relationships</span></li>
<li><span data-contrast="auto">Maintain alignment with the NIST AI RMF and translate emerging AI regulation (EU AI Act, US state AI laws, utility-sector mandates) into concrete engineering requirements</span></li>
</ul>
</li>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 3">Cloud, Endpoint & IT-Security</span></span></strong><span data-ccp-props="{"335559738":160,"335559739":80}"> </span>
<ul>
<li><span data-contrast="auto">Operate our endpoint, cloud, identity, and SIEM platforms end-to-end. Own detection engineering, tuning, and integration with the rest of the stack</span></li>
<li><span data-contrast="auto">Harden AWS posture across accounts (Organizations, SCPs, Control Tower); mature Kubernetes security (admission controllers, runtime visibility, pragmatic hardening)</span></li>
<li><span data-contrast="auto">Stand up zero-trust privileged access — short-lived, audited sessions for production infra, databases, and Kubernetes</span></li>
<li><span data-contrast="auto">Lead IT-Security: device posture, identity (SSO, MFA, SCIM), network segmentation, SaaS posture, and offboarding hygiene</span></li>
</ul>
</li>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 3">Detection, Response & Resilience</span></span></strong><span data-ccp-props="{"335559738":160,"335559739":80}"> </span>
<ul>
<li><span data-contrast="auto">Build and tune detections in our SIEM; own the on-call rotation, runbooks, and IR retainer relationships</span></li>
<li><span data-contrast="auto">Run tabletop exercises across Eng, Legal, and Exec; lead post-incident reviews with blameless write-ups</span></li>
<li><span data-contrast="auto">Translate AI threat research — prompt injection, data poisoning, model inversion, agent hijacking — into detections and controls that ship with every release</span></li>
</ul>
</li>
</ul>
<p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">What we're looking for:</span></span></strong></p>
<p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 3">Minimum qualifications</span></span></strong></p>
<ul>
<li><span data-contrast="auto">10+ years in security engineering, with 3+ years owning a DevSecOps or platform-security program in a cloud-native environment (AWS strongly preferred)</span></li>
<li><span data-contrast="auto">AppSec depth: shipped and operated SAST/DAST/SCA (e.g., Codacy, Semgrep, CodeQL, Snyk, Veracode, or equivalents) at production scale</span></li>
<li><span data-contrast="auto">AI security: hands-on hardening of a production LLM deployment (AWS Bedrock, Azure OpenAI, Vertex AI, or equivalent) — IAM, VPC routing, guardrails, eval gating. RAG-demo experience alone does not meet the bar</span></li>
<li><span data-contrast="auto">EDR/XDR + cloud security platform operator: production experience administering CrowdStrike Falcon (Insight/XDR, Cloud Security CNAPP/CSPM, Identity Protection, or Next-Gen SIEM), SentinelOne, Microsoft Defender XDR, or equivalent, including custom detection authoring</span></li>
<li><span data-contrast="auto">Zero-trust access: experience standing up or operating a privileged-access broker (e.g., Teleport, StrongDM, BeyondTrust, CyberArk, HashiCorp Boundary)</span></li>
<li><span data-contrast="auto">SBOM/AIBOM tooling: operated Interlynk, Anchore, Dependency-Track, or equivalent at production scale</span></li>
<li><span data-contrast="auto">Vulnerability management: production experience with Trivy, Aqua, Wiz, Orca, Lacework, or equivalent across containers, IaC, and SCA</span></li>
<li><span data-contrast="auto">IaC & policy-as-code: Terraform plus production policy-as-code (OPA/Rego, Checkov, Kyverno, tfsec, or equivalent) in a live pipeline</span></li>
<li><span data-contrast="auto">Container & Kubernetes security: production experience with admission controllers (Kyverno, Gatekeeper), runtime visibility (Falco or equivalent), and pragmatic Kubernetes hardening (gVisor, Kata where it earns its keep)</span></li>
<li><span data-contrast="auto">DLP experience: real-world sensitive-data discovery across SaaS or developer tooling, including AI-assisted environments</span></li>
<li><span data-contrast="auto">Compliance fluency: has personally driven SOC 2 Type II or ISO 27001 controls to audit, and can read a control map without flinching.</span><span data-ccp-props="{"335559739":80}"> </span></li>
<li><span data-contrast="auto">Bay Area based; able to work hybrid (3 days/week in office)</span></li>
</ul>
<p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 3">Preferred qualifications</span></span></strong><span data-ccp-props="{"335559738":160,"335559739":80}"> </span></p>
<ul>
<li><span data-contrast="auto">Hands-on MCP work — design, hardening, or auth — even early-stage</span></li>
<li><span data-contrast="auto">ISO 42001 implementation experience; ISO/IEC 42001 Lead Implementer or Lead Auditor certification, or comparable AI-governance leadership</span></li>
<li><span data-contrast="auto">Familiarity with NIST AI RMF and the EU AI Act's high-risk system requirements</span></li>
<li><span data-contrast="auto">Prompt-layer DLP and AI runtime guardrails (e.g., Nightfall, Lakera Guard, Cyberhaven, Harmonic Security, Protect AI, NVIDIA NeMo Guardrails)</span></li>
<li><span data-contrast="auto">LLM eval-as-gate in CI (e.g., Promptfoo, Garak, DeepEval, Giskard) and AI red-teaming experience</span></li>
<li><span data-contrast="auto">Modern PAM / zero-trust rollouts (Teleport, StrongDM) and SaaS posture management (e.g., AppOmni, Obsidian)</span></li>
<li><span data-contrast="auto">Experience securing SaaS products sold into regulated sectors (utilities, energy, financial services, healthcare)</span></li>
<li><span data-contrast="auto">Public signals: conference talks (fwd:cloudsec, DEF CON AI Village, BSides) or open-source contributions in CI/CD, MCP, or LLM-deployment security</span></li>
<li><span data-contrast="auto">Leadership of incident response for a material security event</span></li>
<li><span data-contrast="auto">Comfort working with remote, distributed engineering teams across US/India time zones</span></li>
</ul>
<p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">What you'll love:</span></span></strong></p>
<ul>
<li><span data-contrast="none">Comprehensive Medical, Dental, and Vision Coverage: 100% coverage for employees and 80% for their spouses and children</span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="none">Health Reimbursement Account (HRA): 100% funded by AiDASH to cover medical deductibles</span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="none">401(k) Plan: Begin contributing after three months of employment to prepare for your future. Currently, no company match is offered</span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="none">Parental Leave: Supportive parental leave with 16 weeks for primary caregivers and 4 weeks for secondary caregivers</span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="none">Generous Vacation Policy: Accrue 20 vacation days per year, plus enjoy an additional flex holiday to celebrate whatever feels most important to you!</span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="auto">Winter Break: From December 25th through January 1st, we give everyone time off to recharge and enjoy time with family and friends!</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-contrast="none">We are proud to be an equal-opportunity employer. We are committed to embracing diversity and inclusion in our hiring practices, and we promote a work environment where everyone, from any race, color, religion, sex, sexual orientation, gender identity, or national origin, can do their best work.</span><span data-ccp-props="{}"> </span></p>
<p><span class="TextRun SCXW203899095 BCX0" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW203899095 BCX0">We</span><span class="NormalTextRun SCXW203899095 BCX0"> offer a competitive base pay range for this full-time position, which is between $210</span><span class="NormalTextRun SCXW203899095 BCX0">,000</span><span class="NormalTextRun SCXW203899095 BCX0"> </span><span class="NormalTextRun SCXW203899095 BCX0">and $</span><span class="NormalTextRun SCXW203899095 BCX0">270</span><span class="NormalTextRun SCXW203899095 BCX0">,000</span><span class="NormalTextRun SCXW203899095 BCX0"> per </span><span class="NormalTextRun SCXW203899095 BCX0">year. </span><span class="NormalTextRun SCXW203899095 BCX0">This range reflects t</span><span class="NormalTextRun SCXW203899095 BCX0">he </span><span class="NormalTextRun SCXW203899095 BCX0">anticipa</span><span class="NormalTextRun SCXW203899095 BCX0">ted</span><span class="NormalTextRun SCXW203899095 BCX0"> base salary for new hires. In addition, this role is also eligible for an annual performance bonus and equity. We strive to ensure our compensation packages a</span><span class="NormalTextRun SCXW203899095 BCX0">re </span><span class="NormalTextRun SCXW203899095 BCX0">equita</span><span class="NormalTextRun SCXW203899095 BCX0">ble</span><span class="NormalTextRun SCXW203899095 BCX0"> and aligned with industry standards. Your recruiter can share more about compensation during the hiring process.</span></span><span class="EOP SCXW203899095 BCX0" data-ccp-props="{}"> </span></p><div class="content-conclusion"><div>We are committed to providing an inclusive and accessible interview experience for all candidates. Please let us know if you require any accommodation during the interview process, and we will make every effort to meet your needs.<br><br>Read our Privacy Policy here: <a id="menur8uvg" class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" href="https://www.aidash.com/policy/privacy-policy/" target="_blank">https://www.aidash.com/policy/privacy-policy/</a>
<p> </p>
</div></div>