Pylon

Software Engineer, Security

Pylon2 weeks ago
Location

San Francisco

Type

Full Time

Salary

USD 180,000 – 250,000

Level

Mid

Role

Security Engineer

Posted

Jul 9, 2026

Full TimeMid

The role

Summary

Join Pylon as a Security Engineer to build the security foundations for the leading B2B post-sales platform trusted by 1,500+ companies including Linear and Modal Labs. You'll own application security across the full stack, build scalable security tooling, manage the vulnerability lifecycle, and ship production-grade security solutions while working hands-on with a talented engineering team in San Francisco. This role requires 3+ years of production software development with security expertise or strong backend/infrastructure experience transitioning into security focus.

What you'll do

Application and Product Security Ownership: Own comprehensive application and product security across Pylon's platform, including conducting threat modeling exercises, facilitating secure design reviews, performing critical code reviews in high-risk areas such as authentication and access control, and ensuring security is built into both current and future releases.
Scalable Security Tooling Development: Design and implement security tools and frameworks that enable the organization to scale security practices beyond individual contributors. This includes building supply chain security solutions, implementing vulnerability management systems, developing secure-by-default libraries, and creating developer-friendly security guardrails.
Vulnerability Lifecycle Management: Drive the complete vulnerability management process including triage, validation, prioritization, and remediation. Additionally, help mature Pylon's bug bounty program and security disclosure workflows to ensure responsible vulnerability handling.
AI-Assisted Security Workflows: Build innovative AI-powered security solutions such as agents that autonomously scan code, propose fixes, and surface real-world risks. Develop governance controls and safety mechanisms that enable the broader engineering team to leverage coding agents securely and effectively.
Developer-Focused Security Collaboration: Work hands-on with software engineers across the organization to ship security fixes and foster a security-by-default engineering culture. Help differentiate between theoretical risks and practical threats, ensuring security efforts are strategically focused on issues that genuinely matter.
Full-Cycle Project Ownership: Own security projects from initial customer or internal request through design, implementation, and production shipment. Provide end-to-end ownership including monitoring, maintenance, and iteration post-launch.
Security Incident Response: Participate in incident response activities including triage of security events, investigation of potential incidents, and coordination of remediation efforts with relevant teams.
Infrastructure and Reliability Contributions: Contribute to broader infrastructure and platform engineering initiatives as Pylon scales. Address scaling, reliability, and developer velocity challenges alongside the infrastructure team.

What we look for

Technical

Application Security FundamentalsDeep expertise in authentication, session management, API security, secrets handling, and common vulnerability classes (OWASP Top 10, injection attacks, XSS, CSRF, etc.). Ability to design systems that eliminate or mitigate these vulnerabilities by default.
Production Software DevelopmentStrong background building and shipping production systems with security considerations embedded from the start. Experience debugging complex system failures and implementing solutions at scale.
Vulnerability Assessment and TriagePractical experience with vulnerability identification, classification, and remediation. Ability to assess risk severity, prioritize issues, and distinguish between theoretical risks and actual exploitable vulnerabilities.
Code Review and Secure DesignProficiency in reviewing code for security issues, identifying design flaws that could lead to vulnerabilities, and collaborating with engineers on secure implementation patterns.
Backend or Infrastructure EngineeringStrong foundation in backend systems or infrastructure engineering, either from dedicated security experience or as a strong infra/backend engineer transitioning into security focus.
AI-Assisted Development ToolsProficiency leveraging modern AI tools and coding assistants (such as Claude, GitHub Copilot) for software development, and understanding of how to build with and govern agentic systems.

Education

Computer Science or Related FieldBachelor's degree in Computer Science, Software Engineering, Information Security, or equivalent practical experience demonstrating software engineering and security expertise.

Experience

Production Security ExperienceMinimum 3+ years of production software development with security as a central concern, or equivalent experience as a strong backend/infrastructure engineer transitioning into dedicated security work.
Vulnerability and Bug Bounty ProgramsHands-on experience with any combination of vulnerability triage, bug bounty program management, responsible disclosure workflows, or incident response. Experience balancing speed with pragmatism in remediation.
Startup Environment NavigationPrevious experience working at startups or scaling organizations, with demonstrated ability to navigate ambiguous environments, wear multiple hats, and adapt to evolving priorities.
Agentic Product Development (Preferred)Bonus experience building and shipping production systems with agentic AI components, understanding the unique security and operational challenges they present.

Skills

Required skills

Secure Coding PracticesDemonstrated expertise in writing secure code, implementing cryptographic functions, and understanding common vulnerabilities in multiple programming languages.
Authentication and AuthorizationExpert-level knowledge of OAuth, OpenID Connect, JWT, session management, role-based access control (RBAC), and attribute-based access control (ABAC) implementation and security.
API SecurityComprehensive understanding of REST and GraphQL API security, rate limiting, input validation, output encoding, and common API vulnerabilities.
Secrets ManagementExperience implementing and managing secrets management solutions, key rotation, credential handling, and preventing secrets leakage in production systems.
System Architecture SecurityAbility to evaluate and design secure system architectures, considering data flow, trust boundaries, and defense-in-depth principles.
Debugging and Problem-SolvingStrong analytical and troubleshooting skills to identify root causes of security issues and implement effective, scalable solutions.
Communication and CollaborationAbility to explain complex security concepts to non-security engineers, provide constructive feedback, and work collaboratively across teams with different technical backgrounds.

Nice to have

React Frontend SecurityExperience understanding common React vulnerabilities, XSS prevention in modern web applications, and secure component development patterns.
Go Backend DevelopmentFamiliarity with Go language and its security considerations, including memory safety characteristics and concurrency patterns that impact security.
Cloud Infrastructure Security (AWS)Practical experience securing AWS infrastructure, including IAM policies, S3 bucket security, network security, secrets management in AWS, and cloud security best practices.
Agentic AI Systems SecurityExperience building or securing AI-powered agents and LLM-based systems, including prompt injection prevention, output validation, and governance of autonomous AI workflows.
Supply Chain and Dependency SecurityExperience with Software Composition Analysis (SCA), dependency vulnerability scanning, container security, and securing the software supply chain.
Incident ResponsePractical experience responding to security incidents, including investigation, remediation coordination, and post-incident review processes.

Compensation & benefits

Salary

USD 180,000 – 250,000 (annual)

Stock options

Available

Benefits

Unlimited PTO

Flexible paid time off policy plus 14 company holidays, enabling you to balance work and personal needs throughout the year.

Parental Leave

Comprehensive parental leave program supporting work-life balance and family planning.

Stock Options

Opportunity to participate in Pylon's upside through equity grants. As a Series B company backed by a16z and BCV with strong traction, this represents meaningful wealth-building potential.

Comprehensive Health Insurance

Medical, dental, and vision coverage as part of Pylon's competitive benefits package.

Commuter Benefits

Transit and commuter support for employees in the San Francisco area, reducing commute costs.

Office Benefits and Meals

Lunch, dinner, and snacks provided daily at Pylon's San Francisco office, supporting productivity and team bonding during in-person work.

Fitness Stipend

Monthly fitness allowance supporting your health and wellness goals.

Annual Company Offsite

Company-organized annual offsite events strengthening team cohesion and culture.

Growth and Learning

Opportunity to work with cutting-edge security challenges, AI-assisted development, and scale alongside a high-caliber team backed by top-tier venture capital.


Interview process

  1. 1
    Initial Screening Call Casual conversation with a recruiter to understand your background, security experience, motivations for joining Pylon, and confirm alignment with the role's requirements.
  2. 2
    Technical Security Assessment Discussion with the Security Engineering team covering application security fundamentals, past projects, threat modeling, and your approach to vulnerability triage and remediation. May include a whiteboard discussion of secure system design.
  3. 3
    Hands-On Security Challenge Technical problem-solving exercise focused on security scenarios, code review, or vulnerability assessment. Demonstrates your practical ability to identify and solve real-world security problems.
  4. 4
    System Design Interview Discussion of how you would architect secure systems at scale, design security tooling, or approach building scalable security infrastructure for a growing platform.
  5. 5
    Cross-Functional Team Meeting Conversation with backend/infrastructure engineers, product managers, or other relevant stakeholders to assess collaboration style, communication, and fit within Pylon's engineering culture.
  6. 6
    Leadership Interview Meeting with engineering leadership to discuss career aspirations, decision-making philosophy, approach to ambiguity, and cultural alignment with Pylon's mission and values.
  7. 7
    Offer Discussion Conversation regarding compensation, equity, benefits, start date, and logistics for joining Pylon in San Francisco (in-person requirement).

Apply for this position

You'll be redirected to the company's application page