Orb · San Francisco, CAremote

Salary
$195,000–$265,000
Posted
Jul 9, 2026
Location
San Francisco, CA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

The first dedicated security hire at a billing infrastructure company, this role covers end-to-end technical security across an AWS environment and a Python/TypeScript codebase. Day-to-day work includes threat modeling, IAM and access management, embedding security controls into CI/CD pipelines, and tackling the emerging challenge of scoping AI coding agents safely against production systems. It suits an experienced engineer who prefers building structural, lasting defenses over adding process.

Senior level · 5+ years · Remote · Full-time

Must have (5)
AWSIAMapplication securityCI/CDthreat modeling
Nice to have (7)
vulnerability managementdetection and responsePythonPostgreSQLKafkaTypeScriptReact

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 4,450 people nationally plausibly meet what this posting asks for (information security analysts). range 2,650–6,700

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
IAM45%CI/CD45%application security40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

This is Orb's first dedicated security hire, so the role carries broad, autonomous scope — application security, infrastructure security, IAM, CI/CD integration, and AI agent safety — which supports a Senior classification despite the title carrying no explicit level.

AWS is listed as 'preferred' in the requirements text but is the only cloud platform named and is the company's stated cloud environment; treated as a hard gate.

Threat modeling, code review, and CI/CD security integration are described as core day-to-day responsibilities in the role description and are treated as required.

Vulnerability management and detection & response appear as depth areas listed with 'several of' framing, making them preferred rather than individually required.

Python, PostgreSQL, Kafka, TypeScript, and React appear only in the 'Orb's Tech Stack' section, which explicitly states candidates do not need experience with these specific tools; all are marked preferred for context only.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗