Security Engineer

Outmarket AI

1d ago • 1 views • 0 applications
Full-time Remote
Remote US
Competitive
Full-time
Security Engineer

Job Description

Security Engineer - AI-Powered Insurance Platform

About Outmarket: Securing the Future of Commercial Insurance with AI
Outmarket is pioneering the transformation of the commercial insurance industry, a sector ripe for innovation. We've built an advanced AI platform, trusted by over 250 brokerages, to automate the complex, manual workflows that traditionally dominate their business. From quote comparisons and coverage gap analysis to policy review and proposal generation, our platform leverages customer data to deliver source-cited, reliable outputs that significantly enhance efficiency and accuracy.
Our impact is tangible: teams save 12 to 15 hours per person weekly, reduce errors by approximately 65 percent, and win more business. Security and trust are foundational to Outmarket; our infrastructure is SOC 2 Type II certified, single-tenant, and strictly designed never to train AI models with customer data. As an AI-first company, we champion rapid innovation and close partnership with our users, embedding security from concept to delivery.

Your Mission: Own Security for a High-Impact AI Platform
We are searching for a passionate Security Engineer to take complete ownership of product and application security for our critical multi-tenant platform, which processes highly sensitive insurance data. This is a unique opportunity to embed security at every stage of our development lifecycle, shaping our secure SDLC, strengthening AppSec, fortifying cloud posture, and securing our supply chain. You will be at the forefront, leading incident response and ensuring compliance readiness.

Own the end-to-end security of a platform trusted with sensitive insurance and customer data.
Build security into the product's core architecture, ensuring robust protection from the ground up, not as an afterthought.
Command broad scope across application, cloud, and supply-chain security, making a profound, holistic impact.

What You'll Do

Drive secure SDLC initiatives and implement security-focused code reviews across the entire engineering organization.
Own and enhance application security domains, including authz, tenant isolation, SSRF and injection prevention, and secrets management.
Strengthen our cloud security posture, specifically focusing on GCP IAM and egress controls, while also bolstering supply-chain controls.
Coordinate and lead critical security activities such as penetration testing, threat modeling, and vulnerability management programs.
Lead incident response efforts and advance our compliance readiness, particularly for SOC 2 certification.

What You'll Bring

4+ years of dedicated experience in security engineering, with profound depth in application security.
Hands-on experience securing complex cloud-native, multi-tenant systems.
A comprehensive working knowledge of OWASP-class risks and a proven ability to implement effective prevention strategies in real code.
A collaborative spirit, capable of partnering seamlessly with engineers to integrate security practices that are practical and empowering, not blocking.

Bonus Points If You Have

Direct experience in detection & response or compliance/GRC.
Prior experience securing AI/LLM systems or products that handle regulated data.

Why Join Outmarket?

A high-impact role offering significant ownership from day one within a dynamic, AI-first company.
Competitive compensation and meaningful equity, aligning your success with ours.
Direct collaboration with our founders and real users, providing immediate feedback and influence.
Remote-first flexibility, supporting a healthy work-life balance.
The unique opportunity to help build an AI-native product from the ground up, shaping its security DNA.