← WorkMundi · 1 milhão+ de vagas do mundo, ao vivoEntrarCriar conta grátis

Lead Security Engineer

LawnStarter · Brazil

📅 20/08/2026
🔔 Avise-me sobre vagas como esta
Sem senha, sem cadastro. É só o e-mail — e você sai da lista quando quiser.
🔓 Candidatar-se — grátis →
Abre esta vaga no WorkMundi. A conta é grátis e leva menos de um minuto.

Ver e candidatar-se na WorkMundi →

🎁 Antes de se candidatar, treine esta entrevista. Crie sua conta grátis no WorkMundi e ganhe um Treinamento de Entrevista no HelpsYouSpeak — sem custo, sem cartão. Quero meu treinamento →
About LawnStarter LawnStarter is the nation's leading on-demand marketplace for lawn care and outdoor services, with over $100M in annual bookings. We're expanding beyond lawn care to become the one-stop shop for all home services — operating across three brands (LawnStarter, Lawn Love, Home Gnome) on a single shared platform, with customers and pros on both sides and real money moving every day. About Security At LawnStarter Security is already part of how we build — today it's owned by our Cloud & DevOps team, who've kept it solid as we've scaled. As we grow a $100M+ marketplace that processes payments, holds customer and pro data, and runs on AWS — and as AI agents let us ship faster than ever — we're ready to take security to the next level with a dedicated leader. You'd be that person: the lead who takes security from a distributed, informal practice to a deliberate, instrumented one, and who sets the multi-year direction the org — and eventually a team — follows. You'll partner closely with the delivery teams and with Cloud & DevOps, and you'll start by doing most of the heavy lifting yourself, with the autonomy of a founding hire and the backing of an engineering org that already cares about getting this right. Part of the job is building security so it can outgrow one person: the standards, playbooks, and hiring bar you lay down now are the foundation for the team you'll grow into leading. The Role You lead security at LawnStarter end-to-end: the PHP/Laravel and TypeScript/React codebase, the AWS infrastructure, the payments and customer-data flows, and the compliance posture. You set the multi-year direction, build the controls, and are the person the org looks to on every security question. You start hands-on — security-of-one for now — with an explicit path to leading a small team within roughly 12-18 months, once the foundation is solid and the first hire makes sense. This isn't a hands-off management role: you lead by doing first. You'll collaborate heavily with the delivery teams and lean on Cloud & DevOps where it helps, but most of the heavy lifting is yours today. So you'll prioritize ruthlessly, automate hard, and pick the few things that actually reduce risk over the long list that merely looks thorough. What Makes This Role Different You lead the function. You'll take security from a distributed, informal practice to a deliberate, instrumented one — threat models, automated scanning, incident runbooks — all bearing your design, and all built to scale past you You span every layer. AppSec one day, AWS IAM the next, PCI scoping the day after. Breadth is the job, not a stretch You secure an AI-agent codebase. Most new code here is authored by AI agents. Keeping that safe — at speed — is a problem most security engineers haven't faced yet You build for the team you'll grow. You're not just solving today's problem; you're laying the standards, playbooks, and hiring bar for the security team you'll lead next You set the bar. You're the lead security voice, and the standard for the org — and its future team — is the one you define and champion Requirements What You'll Own Application security — threat modeling the critical path, secure-SDLC practices, code and design review, SAST/secret-scanning/dependency-scanning in CI, and a vulnerability-management loop that actually closes findings Cloud & infrastructure security — AWS posture (IAM, network, encryption), secrets management, EKS/Kubernetes hardening, partnering with Cloud & DevOps on the guardrails that keep misconfigurations out of production Compliance & data protection — mapping PCI scope for payments, driving SOC 2 and LGPD readiness, vendor risk, and being the person who can confidently answer a customer or auditor security questionnaire Detection & response — strengthening detection coverage on the critical path (Datadog, Sentry, AWS signal), an incident runbook, and the muscle to lead a response when something fires The security bar for AI-agent code — the scans, review gates, and conventions that let agent-authored code ship fast and safely The foundation for the team you'll lead — the standards, playbooks, and hiring bar that let security scale beyond one person Problems to Solve Leading security across a $100M marketplace The surface is broad — payments, customer and pro PII, three brands, a shared codebase, live AWS infra — and for now it's just you. The hard part isn't knowing what to do; it's sequencing it well when you can't do everything at once, and automating enough that one person can hold a high bar while planning for the team that comes next. How do you find the risks that matter most, burn them down first, and build in a way that a second and third engineer can pick up cleanly? Keeping pace with AI-agent-authored code Most of our code is now written by AI agents, which means more code shipping faster than any human reviewer can read. Manual security review alone doesn't scale to that. How do you build automated gates, secure-coding conventions, and evals that catch real vulnerabilities at agent speed — without becoming the bottleneck the engineering org routes around? Maturing our compliance posture We take payments and protect customer data with care; the next step is formalizing that into structured, audit-ready compliance (PCI scope, SOC 2, LGPD). You'll map what's in scope, decide what's worth doing now versus later, and get us audit-ready without turning the company into a checkbox factory. What's the right program that protects customers and unblocks deals? Becoming the trusted security voice — and building the team behind it You'll partner with engineers across the org rather than command them. If security is seen as the thing that slows everyone down, it loses. How do you make secure the easy path, build controls people actually adopt, mentor the engineers around you, and set yourself up to hire and lead a team that carries that same standard forward? What Success Looks Like (Year 1) Risk is mapped and the top of it is gone. A threat model and risk register exist for the critical path, and the highest-severity risks you found are closed — with evidence, not assertions Security is in the pipeline. SAST, secret scanning, and dependency scanning run in CI, with a review loop tuned for AI-agent code. Findings get triaged and fixed Compliance has a real baseline. PCI scope is mapped, SOC 2 / LGPD readiness has a credible plan or a first milestone passed, and you can answer a security questionnaire with confidence We can detect and respond. Detection coverage spans the critical path, an incident runbook is written and rehearsed, and you've established baseline MTTD/MTTR The team has a plan. A credible multi-year security roadmap exists, along with a concrete plan and business case for the first security hire(s) — scope, level, and timing — so the org can decide when to grow the function No P1 from a known gap. No customer- or pro-facing security incident traceable to a risk you'd identified and deprioritized without flagging it Who You Are AI-native. You use AI tools daily in security work — triaging findings, threat modeling, reviewing agent-authored code, drafting detections and policy. You have opinions about where AI sharpens security and where it creates new risk. This is unlikely to be a good fit if you're skeptical of AI tools or prefer to do everything by hand. Deep across most of the stack. You have real, hands-on expertise in at least three of appsec, cloud, compliance, and response — not surface familiarity, but the kind of depth where you've built and owned controls in each — and the range to pick up the fourth fast. This is unlikely to be a good fit if you only want to work one narrow lane and hand off the rest. A builder and a leader-in-training. You're energized by shaping a practice and leveling it up — taking it from informal to instrumented — and by setting standards that make
Ler o resto da vaga →
For people searching Engineer

144,883 engineer jobs are open right now

Here's how to pick the right one and stand out in your application.

144.883Jobs
31.687IN
81%EN

That number is real. WorkMundi's database shows 144,883 open engineer roles across the world. India has the most with 31,687 jobs, followed by the United States with 30,084. If you just finished reading one job ad and felt paralyzed by choice, you're not alone—but this scale is actually an advantage. It means you can afford to be selective.

Start by geography and language. The majority of engineer ads—117,837 of them—have the job posting text written in English. Use that as one filter, but remember: the ad text language tells you nothing about whether the role actually requires you to speak English day-to-day. Read the job description carefully. Then check which countries have the volume you're targeting. Singapore, Poland, and Australia round out the top five after India and the US.

Next, learn who's hiring. Accenture has posted 2,801 engineer roles. andurilindustries, speechify, and jobgether are also actively recruiting. If you're applying to one of these names, research their hiring patterns and interview style before you apply. That homework pays off.

When you interview, expect the question every engineer hears: 'Tell me about a time you had to debug a problem that wasn't in your job description.' Have a specific story ready—not a general one. Name the tools, the deadline pressure, and what you learned. Hiring managers listen for whether you see problem-solving as part of the role itself, not a favour.

👁 21 have read this
0 comments
Want to comment?

Leave your e-mail to comment, react and follow the posts for your role. It is free.

Vagas parecidas

Vaga no WorkMundi — o maior portal de vagas do mundo. Veja mais vagas de todos os continentes, atualizadas ao vivo.

📢
🎁

Antes de se candidatar, treine esta entrevista.

Crie sua conta grátis no WorkMundi e ganhe um Treinamento de Entrevista no HelpsYouSpeak — sem custo, sem cartão.

Quero meu treinamento →