About ALSO
We are ALSO, a pioneering electric mobility company dedicated to creating innovative, delightful, and highly efficient small EVs. Our mission is to inspire a global shift, replacing countless local car, truck, and SUV miles with more affordable, enjoyable, and significantly more efficient alternatives. We're a passionate team of builders, dreamers, and innovators focused on solving tomorrow's global mobility challenges today.
Staff Security Engineer, Cloud
This isn't a typical security advisory role; it's a hands-on building position. You will architect, implement, and operate the entire cloud security posture for our connected, software-defined EV platform. Nearly everything of value at ALSO flows through the cloud: real-time telemetry from vehicles in the field, remote diagnostics and updates, fleet intelligence, and the customer-facing product APIs. You'll be instrumental in protecting it all.
You'll set the security architecture and then personally build it in Go, working collaboratively with our backend engineering team. One moment you might be crafting a detailed threat model, the next reviewing a critical Kubernetes admission policy, and then immediately shipping the service that enforces it. When the company asks, "is this secure?", you'll be the expert with the autonomy to provide and implement the definitive solution, not just flag the risk.
What You'll Do
Own Cloud Security End-to-End: Drive the strategy, architecture, implementation, and operations across AWS, Kubernetes, and our microservices platform. This includes proactive threat modeling for new systems during architecture reviews, even before a single line of code is written.
Scale Identity and Access: Design and implement robust identity and access management for workloads and across the organization, ensuring least privilege by default. Manage secrets, certificate/key lifecycles, and establish mutual TLS between services, and critically, between cloud and vehicle systems.
Harden Containers and Orchestration: Secure our containerized environment with expertise in image provenance, admission control, runtime and network policy, service mesh configuration, and pristine isolation across microservices.
Fortify the Software Supply Chain: Implement comprehensive security for our software supply chain, including SBOM generation, automated dependency and image scanning, signed artifacts, and CI/CD pipelines that intelligently fail closed on critical issues.
Build Custom Security Controls in Go: Develop authorization services, policy enforcement mechanisms, and provisioning/rotation tooling in Go. Act as the embedded DevSecOps function, creating guardrails and policy-as-code to empower other engineers to move quickly and securely without routing every decision through security.
Lead Detection & Response: Establish security logging and telemetry, develop meaningful alerting, create robust runbooks, take ownership of security incidents (including on-call duties), and lead blameless postmortems that drive genuine, lasting fixes.
Secure the Vehicle-to-Cloud Boundary: Protect the critical interface between our vehicles and the cloud, managing device identity and provisioning, fleet-wide certificate rotation, secure OTA update paths, and large-scale anomaly and tamper detection.
Integrated Assurance & Backend Contribution: Contribute to core backend development alongside the team, and own security assurance activities such as penetration tests, vulnerability management, evidence collection, and ensure security standards pragmatically strengthen the product.
What You'll Bring
Extensive Engineering Background: 10+ years in backend and infrastructure engineering, with a substantial, hands-on portion dedicated to owning security in production environments.
AWS Mastery: Expert-level, hands-on experience with AWS services including IAM, VPC and network design, KMS, Secrets Manager, GuardDuty, Security Hub, CloudTrail, Config, and organization-level guardrails (SCPs), alongside core compute and data services (EKS, ECS, ECR, Lambda, DynamoDB, S3).
Deep Kubernetes & Container Security: Proven expertise in RBAC, admission controllers, pod security standards, network policy, secrets handling, runtime detection, and image hardening. You have real experience operating clusters, not just theoretical knowledge.
Fluent Go Development: You actively design, review, and ship production-grade Go code today.
Microservices & Distributed Systems Security: In-depth understanding and practical experience with service-to-service authentication and authorization, API gateway patterns, rate limiting, tenant isolation, and event-driven pipeline security.
Applied Cryptography & Identity Protocols: Practical experience with OAuth2, OIDC, JWT, SAML, mutual TLS, and PKI, including certificate lifecycle management at scale.
Infrastructure & Policy as Code: Proficient in using infrastructure and policy as code, with security gating seamlessly integrated into CI/CD pipelines.
Threat Modeling & Incident Response Leadership: Routine practice in threat modeling and secure architecture reviews, with specific examples of how you've influenced designs. Demonstrated experience personally leading security incidents from detection through postmortem.
0-to-1 Ownership: A track record of standing up a security function or program where none previously existed, driving impact without a large supporting team.
The salary for this position ranges from $205,000 - $240,000 per year, depending on experience, qualifications, and location.
Perks & Benefits
Robust health coverage: excellent health, dental, and vision insurance covered up to 100% by ALSO with FSA & HSA options.
One Medical membership and dedicated insurance advocates.
Rich fertility and family building benefits with Progyny.
Flexible time off.
401(k) match.
Why ALSO?
We are fiercely passionate about helping the world find a better, more sustainable way to get there—wherever "there" may be. Located in the heart of Silicon Valley, we've assembled a world-class team from leading brands in technology, automotive, cycling, outdoor recreation, and retail.
Join us to work hands-on, imagine boldly, design innovatively, and build an entirely new solution to some of the most pressing global transportation challenges. Your expertise will not just protect our platform, but enable a greener, more efficient future.