@ 1001ai
Security Engineer — 1001 (1001.ai). First dedicated security hire at a $30M Series A AI company doing enterprise deployments (hybrid/on-prem/sovereign cloud, not clean SaaS). London/Europe based, hybrid, with travel to GCC.
Owns security across product, infrastructure, cloud environments, and corporate systems: secures company-wide SaaS/workspace accounts (Google Workspace, Slack, GitHub, cloud accounts, IdPs, device policies, access controls), leads customer-facing security reviews/questionnaires/procurement with enterprise security teams, defines and implements controls/threat models/policies, builds secure-by-default patterns into platform and deployment workflows, drives SOC 2 / ISO 27001, responds to incidents.
REQUIREMENTS: 5+ years security engineering with significant product or cloud security time at a B2B/enterprise SaaS company. CAN BREAK THINGS, not just write policies — offensive/hacker capability (pentesting, bug bounty, red team, CTF, vulnerability research) is the core archetype the client responds to. Strong cloud security (AWS/GCP/Azure), application security, identity and access. Credible in customer-facing security and compliance conversations. Hands-on — ships the controls themselves. Bonus: AI-specific risk (data handling, model/prompt security, agentic systems, MCP security).
CALIBRATION (apply ruthlessly — the client's words: "Our engineers are from top labs and top schools. I expect at least the same bar"): profiles that landed include a principal-level Apple security engineer, an ex-Audible/WhiteHat hacker-turned-engineer who built MCP-server security and ran bug bounties, and an Amazon/AWS security engineer. Target: security engineers at top tech companies (Apple, Google, Amazon, Meta, Stripe, Cloudflare, Datadog), frontier AI labs, elite startups, or standout offensive-security backgrounds (published research, conference talks, notable bug bounties). London strongly preferred; Europe acceptable; only exceptional profiles elsewhere. Comfortable with high-ownership early-stage scope. NOT compliance-only/GRC-only profiles, NOT SOC analysts, NOT consultancy pentesters with no engineering, NOT policy writers.