Security Lead

Remote: 
Full Remote
Contract: 

Offer summary

Qualifications:

7+ years in a security engineering or compliance role, Experience leading vendor risk assessments and building compliance frameworks, Strong background in API design, DevSecOps, and incident response, Knowledge of cloud security, particularly AWS, and familiarity with standards like SOC 2 and ISO 27001..

Key responsibilities:

  • Complete and submit vendor risk assessments and identify compliance gaps
  • Engage with stakeholders to collect data for submissions and deliver scalable processes
  • Define and implement security auditing procedures and maintain documentation of security controls
  • Lead initiatives for incident monitoring, intrusion detection, and vulnerability management.

LocalStack logo
LocalStack https://localstack.cloud
11 - 50 Employees
See all jobs

Job description

We are a fast-growing Series A startup building cutting-edge technology to revolutionize cloud development processes and support highly efficient dev&test feedback loops. We’ve closed our last $25mil round in Q4 2024, led by Notable Capital, CRV and Heavybit.

At its core, LocalStack provides a high-fidelity emulator and local cloud development platform. Imagine developing cloud applications and data pipelines entirely on your local machine within a lightweight cloud sandbox, running in Docker!

Our mission is to empower developers to rapidly build and test their cloud applications, allowing for a more enjoyable dev experience, and saving valuable time and resources.

LocalStack has a large and active open-source community (57k+ stars on GitHub) with over 100k active users worldwide and 290M+ downloads to date. Our customer base ranges from SMBs to Global Fortune 500 companies.

We are sustainably growing our globally distributed team across sectors

LocalStack is headquartered in Zurich/Switzerland 🇨🇭, with a main engineering office in Vienna/Austria 🇦🇹 and remote team members from 🇺🇸the US, 🇫🇷FR, 🇬🇧UK, 🇨🇦CA, 🇪🇸ES, and many more countries.

👉Check our Notion Candidate Handbook and our GitHub!

This is the right opportunity for a person with 7+ years in a security engineering or security compliance role, experience leading vendor risk assessments and building compliance frameworks from the ground up, a strong background in API design and build, as well as a strong background in DevSecOps, incident response, and pragmatic, risk-driven security leadership.

Requirements

✅ What you will be working on/responsible for

  • Take full responsibility for completing and submitting vendor risk assessments.
  • Identify gaps between claimed and actual compliance and propose corrective actions.
  • Engage with internal stakeholders to collect data and evidence for submissions.
  • Deliver a sustainable, scalable process (e.g., via tooling, delegation, or automation).
  • Define and implement regular security auditing procedures across systems and access controls.
  • Maintain documentation of security controls, configurations, and policies
  • Generate and distribute internal audit and compliance reports quarterly.
  • collaborate with engineering to ensure secure configurations and permission models
  • Contribute to design and oversight of security-related features or mitigations in product environments.
  • Lead initiatives for incident monitoring, intrusion detection, and vulnerability management.

✅ Experience we expect you to bring to the role

  • Knowledge of threat modelling, vulnerability management, and tools like intrusion detection, network security, or Linux/Unix OS hardening.
  • Must have practical experience with cloud security (AWS preferred).
  • Should be familiar with common standards (e.g., SOC 2, ISO 27001, GDPR), even if not formally certified.
  • Strong documentation skills and ability to make complex topics accessible to non-experts.
  • Should understand US and EU security and compliance expectations.
  • Strong preference for candidates with prior engineering experience (even if no longer coding daily).
  • Should be proactive, pragmatic, and capable of risk-based decision-making.

🪢 Values we hold in LocalStack

care: we create with compassion. We prioritize empathy and understanding in every interaction. By genuinely caring for our team, customers, and community, we create an environment where people thrive and impactful work flourishes

ownership: we own the outcome. We take responsibility for our work and are passionate about its impact. We foster autonomy, inspire ambition, encourage ownership, and empower everyone to unlock their potential and make an impact.

openness: we build trust together. We build trust through open communication and honest feedback. By sharing ideas and embracing diverse perspectives, we create stronger, more connected teams that work toward shared goals.

courage: we dare to innovate. We embrace bold challenges and take calculated risks to move the needle. We step outside our comfort zones, experiment fearlessly, and turn setbacks into springboards for growth.

excellence: we chase the extraordinary. We chase excellence by pushing boundaries and delivering results that go beyond the ordinary, constantly raising the bar and striving for greatness in everything we do. Excellence is not just the outcome, itʼs how we approach every task with purpose, passion, and a commitment to delivering exceptional value.

Benefits

    • Fully remote
    • Competitive salary
    • Performance bonus
    • Competitive share options
    • Annual company retreat
    • The best equipment for your role
    • Learning budget

Why Join LocalStack?

At LocalStack, we are at the forefront of shaping cloud DevX and redefining how developers interact with cloud platforms. By joining our team, you’ll have the opportunity to:

  • Lead a critical engineering function in a fast-growing company with huge open source traction and global customer base.
  • Work on cutting-edge technology with a talented and passionate team.
  • Shape the evolution of a product used and loved by thousands of developers worldwide.

Sounds like a good match?

We'd love to hear from you! Join us in shaping the future of cloud development at LocalStack.

To apply, follow the LI application process or apply on our career page. Make sure to include a short motivation outlining why you are the perfect candidate for this role.

We aim to come back to applicants within 2 weeks. Please note, that due to a high volume of candidates, we cannot offer personalized feedback to each candidate.

Required profile

Experience

Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Proactivity

Related jobs