Security Engineer
Claylabs · New York
About this role
## About Clay AI Clay is building the engine that helps companies grow—predicting the next best action and enabling personalized go-to-market campaigns (emails, ads, landing pages, and workflows). Clay already supports thousands of customers, including Anthropic, OpenAI, Google, and Visa. ## Security Engineering @ Clay Clay is building a modern security organization from the ground up and is hiring **Senior or Staff Security Engineers**. This is a **hands-on** role where you’ll spend significant time writing **production code-security tooling**, building **detection systems**, creating **remediation pipelines**, and developing **frameworks** that make secure defaults the easiest path. You’ll also help define how Clay leverages **modern automation and frontier AI models** (e.g., Mythos) to scale security operations—such as autonomously discovering vulnerabilities, reviewing AI-generated code, and building detections that understand context and intent. --- ## What You’ll Do - Build security primitives, tooling, and automation that scale with the product and engineering org - Define and implement strategy for modern security workflows: **AI-assisted vulnerability discovery**, **automated code review**, **threat detection**, and **remediation** - Collaborate with Infrastructure and Product Engineering to make secure defaults the easiest path - Own projects end to end: **design, implementation, rollout, and measurement** ### Cloud Security - Secure the cloud environment (IAM, network policies, container security, secrets management, misconfiguration prevention) - Define and enforce least-privilege access patterns across services and humans - Improve cloud visibility and control using infrastructure-as-code and cloud security tooling (e.g., Terraform, AWS Config, AWS Security Hub) - Develop preventative controls and safe deployment patterns to reduce incident probability and blast radius ### Application Security - Lead secure design and secure coding practices; prevent common vulnerability classes - Perform architecture reviews and code-level security reviews; work hands-on with engineers to ship fixes - Own the vulnerability discovery and validation lifecycle (static/dynamic analysis, dependency checks, pen tests, bug bounties) - Integrate modern automated detection systems (including Claude Mythos-class models) to find vulnerabilities at scale - Build and deploy security agents and automated workflows that scan codebases, propose fixes, and sometimes autonomously deploy security patches - Build frameworks and reusable components for authentication, authorization, and secure-by-default patterns - Define practical policies and controls for code generation tools and coding agent changes so they’re used safely and consistently --- ## What You’ll Bring - Strong software engineering fundamentals and a track record of shipping production systems - Deep expertise in **either cloud security or application security**, with the ability to flex into the adjacent domain - Ability to build (not just advise): translate risk into concrete engineering work and ship solutions - Comfort with ambiguity: thrive when building from first principles and defining what good looks like - Forward-thinking about tooling: interest in leveraging modern automation and AI to scale security operations while maintaining engineering rigor --- ## Out of Scope This is **not** an IT helpdesk or general operations role. Clay partners with other teams and vendors for ro
Listing freshness
CronJobs last confirmed this listing 13h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.