Lead Security Engineer

Composio

3h ago 0 views 0 applications
Full-time On-site
Bangalore Tech Hub - भारत
Competitive
Full-time
Security Engineer

Job Description

About ComposioWe're building the learning infrastructure that transforms AI agents into true digital workers. While today's agents can reason and plan, they fail to do meaningful work because they lack real experience operating in apps. Composio gives agents continuously improving, reusable skills across 1000+ production-grade app connectors including Gmail, Linear, and Hubspot. We handle authentication, tool routing, retries, failure handling, and observability, making every action safe and dependable.With a $25M Series A led by Lightspeed and 3× ARR growth since the beginning of 2026, we're scaling fast and building for durability.About the RoleYou'll be the one person at Composio whose entire job is security — and you'll make it so nobody else has to think about it as a side quest ever again. Security and compliance at Composio are continuous. Not a quarterly sprint. Not a calendar event. Not a fire drill. The vulnerability count is trending down month over month. Compliance posture is always current. And critically — none of this slows anyone down. You'll need to build a security function that improves continuously without becoming a gate that blocks engineering velocity.Today, security at Composio is everyone's responsibility and no one's primary charter. The infra team leads security at the moment, and we are building at a massive pace for this to be a role with dedicated direction. We need someone to own this entirely — to take security from reactive to embedded.Your ImpactA continuous security program from scratch — detection, response, prevention, all of itThreat models that reflect the real risks of an integration platform handling cross-app workflows at scaleApplication security practices embedded into the development lifecycle, not bolted on afterInfrastructure security that scales with a fast-growing cloud platformA compliance posture (SOC2, GDPR, and what comes next) that's always audit-ready, not audit-scramblingThe external security narrative — how Composio's posture is perceived by customers, partners, and the marketComposio connects to 500+ apps and orchestrates workflows across them. The attack surface is wide, the trust boundaries are complex, and our customers include some of the largest organizations in the world. You need to deeply understand threat models for a platform like this and translate them into a security posture that matches how the world evaluates us.You'll also own compliance and governance — not as checkbox exercises, but as continuous systems that stay current without manual intervention.What you bringYou've built security at a startup from zero — not inherited a team and a SIEM and a playbook, but actually stood one upYou've been through the 1-to-10 journey of a security function and know what to prioritizeYou think about security as a system that should run continuously, not a set of periodic auditsYou can own application security, infrastructure security, and complianceYou default to building processes that don't impede — you know that security that blocks shipping is security that gets bypassedYou're comfortable with on-call responsibilities and the pace of an early-stage companyWhat We OfferLunch and dinner provided in the office$200/month learning and development budget$1,000/month AI tool experimentation budget to automate, accelerate, and improve how you workHigh-ownership role with direct exposure to leadership and company-building decisionsCompetitive salary and equityOur CultureWe believe in individual ownership and high trust, empowering people to identify and tackle the most important problems in the business. We are an in-person team that defaults to using agents to do work faster and better than we could on our own. Above all, we share a sense of curiosity and excitement about what agents may ultimately be capable of achieving.