All roles
Engineering
Security Engineer
Summary
Own and mature security across our infrastructure, product, and internal systems. You will work hands-on to reduce risk across our cloud environment and voice pipeline, support our compliance program, and partner directly with engineering to build security into the product rather than bolt it on afterward. This is a hands-on, individual-contributor role. You will be one of the first dedicated security hires at Guava, with real ownership over how our security program is built.
What you'll do
- Own security architecture and hardening across our cloud infrastructure, voice pipeline, and internal systems.
- Design and implement security controls for identity and access management, network segmentation, encryption, and secrets management.
- Partner with engineering on secure design reviews, threat modeling, and code-level security guidance for new features.
- Provide technical guidance on application, API, cloud, platform, and AI security.
- Support Guava's compliance program (SOC 2 Type II, HITRUST i1, PCI DSS Level 1, the BAA obligations that come with healthcare deployments, and customer security questionnaires), including evidence collection and control implementation.
- Build and maintain security monitoring, logging, and alerting across production systems; lead incident response when issues arise.
- Manage relationships with external security vendors, auditors, and penetration testers, and drive remediation of findings.
- Own security-related tooling and automation (SAST/DAST, dependency scanning, CSPM, SIEM) as the team and platform scale.
- Contribute to security policy, employee security training, and vendor risk assessments in partnership with People Ops and compliance.
What we're looking for
- 4+ years of experience in security engineering, application security, or a related infrastructure/security role.
- Hands-on experience securing cloud infrastructure (AWS, GCP, or Azure): IAM, networking, encryption, and secrets management.
- Experience supporting a compliance framework such as SOC 2, HITRUST, HIPAA, ISO 27001, or PCI DSS.
- Comfortable reading and reviewing code for security issues, and working directly with engineers to fix them.
- Practical experience with vulnerability management, security monitoring/SIEM tooling, and incident response.
- Strong written communication; you can explain risk and tradeoffs clearly to both engineers and auditors.
- Based in or willing to work from Guava's Downtown Los Angeles (Arts District) office.
Nice to haves
- Experience securing real-time or telephony/voice systems (SIP/PSTN, WebRTC, or similar).
- Experience at a company selling into healthcare, financial services, insurance, or other highly regulated industries.
- Relevant certifications (OSCP, CISSP, GIAC, or similar). Not required, but a plus.
- Experience building a security program from an early stage, rather than maintaining an established one.
Why Guava
- Own security for a voice AI platform running in real, regulated production, not a research demo.
- Direct access to engineering leadership and real influence over how the security program is built.
- Join at a stage where you can shape the architecture and process, not just maintain someone else's.