Lead Security Engineer at Liberate
San Francisco, CA
$180,000–$240,000from the description
Jul 21, 2026
San Francisco, CA
Jul 22, 2026
What this job asks for AI summary
A first dedicated product security hire responsible for owning security architecture, compliance programs, and vulnerability management across a multi-tenant SaaS platform. Day-to-day work spans threat modeling, secure SDLC practices, SOC 2 program ownership, and incident readiness — with a strong emphasis on embedding controls into engineering workflows rather than relying on manual processes. Suits an experienced security engineer comfortable building programs from scratch in a fast-moving environment.
Senior level · 8+ years · Boston-Cambridge-Newton, MA-NH · Full-time
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 100 people in the Boston-Cambridge-Newton, MA-NH area plausibly meet what this posting asks for (information security analysts). range 20–150
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $139,553 (middle half $110,917–$180,330). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The role is posted for two metros with different pay bands: Boston ($180K–$240K) and San Francisco ($190K–$250K). The Boston range is reported here; the SF range is $190,000–$250,000/year.
This is a hybrid role (2x/week in office) in Boston or the Bay Area — not fully remote.
The role sits at the intersection of security engineering and compliance program ownership, making it a close call between 15-1212 (Information Security Analysts) and 15-1299 (Computer Occupations, All Other). The strong emphasis on hands-on product security engineering, secure SDLC, and architecture reviews tips it toward 15-1212.
Vanta is mentioned explicitly but framed as a leverage tool ('Use tools like Vanta as leverage, not as the job'), so it is listed as preferred rather than a hard gate.
Penetration testing appears in the vulnerability management responsibilities section as an activity the candidate will oversee, not as a stated skill requirement — listed as preferred.
'Security architecture' the years demanded is set to 4 based on the explicit '4+ years owning security architecture or security programs for a production SaaS product' requirement.
No degree requirement is stated anywhere in the posting.
Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): security architecture, secrets management, key management.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.