• Own application security across our product surface: threat modeling, secure code review, SAST/DAST, dependency and supply-chain hygiene
• Harden our cloud and infrastructure: AWS/GCP configuration, Kubernetes, secrets management, network boundaries, CI/CD pipeline security
• Build the security foundation for our agent platform: sandboxing, permission boundaries, prompt-injection defenses, data exfiltration controls, and safe tool execution
• Partner with engineering and research to bake security into product design from day zero, not bolted on later
• Run incident response and lead investigations when things go wrong; build the playbooks so the next one is faster
• Drive vendor reviews, customer security questionnaires, and the compliance work needed as we move upmarket (SOC 2, ISO, etc.)
• Establish the security culture: lightweight processes, useful tooling, clear ownership; scrappy, not bureaucratic