Sr. Security Engineer
OpenSpace
| Company | OpenSpace |
| Category | Engineering |
| Location | U.S. |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 25 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
At OpenSpace, we’re redefining how the world’s most complex projects are built. Our AI-powered Visual Intelligence Platform uses computer vision and spatial AI to give construction teams a real-time view of what’s happening on-site, helping them build faster, safer, and with greater confidence.
But what truly sets us apart is our people. We hire curious, driven teammates who love solving hard problems, taking ownership, and making a real-world impact. Great people build great culture—and apparently it shows. Forbes has named OpenSpace one of America’s Best Startup Employers five years in a row. Come see what all the fuss is about ✨
Brief summary of role:
Security is in OpenSpace's DNA. A significant portion of our core engineering team — including several of our most senior engineers — came together at a security SaaS company before OpenSpace, and that shows up in how we design systems, review code, and think about customer data. We run a mature program today: an external security partner handles pen testing and structured assessments, our DevOps and IT team owns infrastructure security, IAM, and endpoint, and product engineers carry real ownership of the code they ship.
What we don't yet have is a dedicated in-house security engineer, and the surface area is growing fast — particularly as AI changes how code gets written and where sensitive data flows. This role is about going from strong to elite: building the proactive security review muscle that lives day-to-day inside the engineering org, rather than at the cadence of an external engagement.
You'll partner with our existing security consultant rather than replace them. They keep running pen tests and structured assessments; you build the in-house practice that catches issues long before they reach one.
What you will be doing:
Run proactive security reviews of new features, architectures, and third-party integrations before they ship
Build out our application and product security practice: threat modeling, design review, secure SDLC integration
Own our approach to AI-related security risk, including:
Securing our own AI/ML systems and the data flowing through them
Governing internal use of AI dev tools (Claude Code and similar) so we move fast without leaking sensitive data
Reviewing AI-assisted code contributions and helping us evolve our policies as the tooling matures
Partner with engineering teams to triage and remediate vulnerabilities from pen tests, customer findings, and internal discovery
Support our SOC 2 and ISO 27001 programs as a key technical contributor (compliance ownership lives elsewhere, but you'll be the engineering voice in the room)
Help mature our incident response practice and run security tabletop exercises
Build internal tooling and automation that scales security review without bottlenecking shipping
Work with our consultant on scoping pen tests, vendor assessments, and customer security reviews
What we are looking for:
5+ years in security engineering, application security, or product security
Hands-on experience doing proactive security review (threat modeling, design review, secure code review) on production systems
Strong fundamentals in web application security, cloud security (we run primarily on AWS and GCP), and modern auth patterns
Comfortable reading and reviewing code across at least one of our stacks (Python, Java/Kotlin, TypeScript)
A real point of view on how AI changes the security landscape, both as a new risk surface and as new tooling for defenders
Track record of working effectively in a startup or fast-moving environment where you have to prioritize ruthlessly and make tradeoffs
Ability to influence engineers without owning their roadmap
Nice to have:
Experience as the first or early security hire at a growth-stage company
Hands-on contributor experience with SOC 2 and/or ISO 27001
Background in sec
You found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →