Senior Security Engineer- San Francisco HQ
Orb · San Francisco, CA
$195,000–$265,000
Jul 9, 2026
San Francisco, CA
Jul 21, 2026
What this job asks for AI summary
The first dedicated security hire at a billing infrastructure company, this role covers end-to-end technical security across an AWS environment and a Python/TypeScript codebase. Day-to-day work includes threat modeling, IAM and access management, embedding security controls into CI/CD pipelines, and tackling the emerging challenge of scoping AI coding agents safely against production systems. It suits an experienced engineer who prefers building structural, lasting defenses over adding process.
Senior level · 5+ years · Remote · Full-time
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 4,450 people nationally plausibly meet what this posting asks for (information security analysts). range 2,650–6,700
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (6)
This is Orb's first dedicated security hire, so the role carries broad, autonomous scope — application security, infrastructure security, IAM, CI/CD integration, and AI agent safety — which supports a Senior classification despite the title carrying no explicit level.
AWS is listed as 'preferred' in the requirements text but is the only cloud platform named and is the company's stated cloud environment; treated as a hard gate.
Threat modeling, code review, and CI/CD security integration are described as core day-to-day responsibilities in the role description and are treated as required.
Vulnerability management and detection & response appear as depth areas listed with 'several of' framing, making them preferred rather than individually required.
Python, PostgreSQL, Kafka, TypeScript, and React appear only in the 'Orb's Tech Stack' section, which explicitly states candidates do not need experience with these specific tools; all are marked preferred for context only.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.