Lead Security Engineer, Internal and IT

Artemis
New York, NY
On-site

Who this role is best for

Geared toward experienced security engineers comfortable with building internal security programs from scratch. This senior individual contributor role demands deep technical ownership in a New York City-based cybersecurity startup, reporting directly to leadership.

Best fit for

  • Candidates with 5+ years of hands-on security engineering experience at a top-tier software company.
    — “5+ years of hands-on experience in security engineering, IT security, or corporate security
  • Professionals who have led incident response and compliance audits from start to finish.
    — “Lead incident response for internal security events, from detection and containment
  • Individuals with autonomy to build security foundations without team management duties.
    — “You'll be building the program
  • Security experts with deep expertise in identity management or cloud security.
    — “Deep expertise in one or more of the following: identity and access management

Things to consider

  • This role requires hands-on ownership of both security and IT architecture responsibilities.
    — “Own the IT architecture
  • You will be the first security hire, building the program without existing team support.
    — “Artemis Security is hiring our first Security Engineer
  • The position involves partnering with founders and engineering teams while reporting to leadership.
    — “report into leadership, partner with our founders, engineering, and security teams

How to stand out

  • Demonstrate specific examples of building security programs from scratch at a startup.
    — “Prior experience as the first or founding internal security hire at a startup
  • Highlight hands-on experience with SOC 2 or ISO 27001 audit scoping and evidence collection.
    — “Hands-on experience with SOC 2 and/or ISO 27001 audits
  • Showcase familiarity with modern security tooling across EDR, SIEM, IAM, and MDM.
    — “Familiarity with modern security tooling across EDR, SIEM, IAM, MDM
  • Emphasize practical knowledge of attacker tradecraft beyond compliance frameworks.
    — “Strong understanding of modern attacker tradecraft
Pace · SteadyCollaboration · MediumAutonomy · HighDecision Impact · TeamLevel · Senior

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • owning Artemis's internal security posture
  • designing and running identity strategy
  • building and operating vulnerability management program
  • leading incident response
Typical background
5+ years of hands-on experience in security engineering, IT security, or corporate security

Skills & requirements

Required

Internal SecurityIdentity And Access ManagementVulnerability ManagementIncident ResponseComplianceSecurity AwarenessSecurity PoliciesVendor Risk ManagementIT ArchitectureSecurity Tooling

Preferred

SOC 2ISO 27001

Stack & domain

Internal SecurityEndpoint SecurityIdentity And Access ManagementNetwork SecurityEmail SecurityCloud SecurityVulnerability ManagementIncident ResponseComplianceCertificationSecurity AwarenessSecurity PoliciesStandardsVendor RiskThird-party SecurityProduct SecurityEngineering LeadershipIT ArchitectureGoogle WorkspaceSlackIdentity ProviderMDMOffice NetworkAVPhysical Access ControlsLeadershipCommunicationTeamworkProblem-solvingDecision-makingSecurityTechnology

About the role

Original posting from Artemis via Ashby

About The Role

Artemis Security is hiring our first Security Engineer to own internal security at the company. In a cybersecurity company, internal security isn't a checkbox — it's a reflection of everything we sell. Our customers trust us with their most sensitive telemetry, and how we run our own environment has to meet a bar higher than anyone else's.

This is a hands-on, senior IC role. You'll be the technical owner of Artemis's internal security posture, building the systems, controls, and programs that protect the company from the inside out. You'll also own the security-critical parts of our IT environment, working closely with our IT provider on execution. You'll report into leadership, partner with our founders, engineering, and security teams, and have the autonomy to build the security foundation the right way from day one.

You won't be managing a team. You'll be building the program.

Responsibilities

Security (primary focus)

  • Own Artemis's internal security posture end to end, including endpoint security, identity and access management, network security, email security, and cloud security for our corporate environment
  • Design and run our identity strategy across SSO, MFA, conditional access, and privileged access management
  • Build and operate our vulnerability management program, including patching, endpoint hardening, and continuous monitoring
  • Lead incident response for internal security events, from detection and containment through investigation and post-incident review
  • Drive our compliance and certification work (SOC 2 Type II, ISO 27001, and others as we grow), including scoping, evidence collection, and working with external auditors
  • Build and run the security awareness program, including ongoing training, phishing simulations, and role-specific education
  • Set and maintain security policies, standards, and internal documentation that scale with the company
  • Own vendor risk and third-party security reviews for tools and partners we bring in
  • Partner with product security and engineering leadership to keep internal and product security aligned
  • You’ll be working hands-on with the best security tool in the world, Artemis!

IT (secondary but critical)

  • Own the IT architecture
  • Selecting which IT provider we will use and making any changes, if necessary
  • Manage the tools and configurations that keep the team productive and secure across Google Workspace, Slack, our identity provider, MDM, and related systems
  • Contribute to the design and security of our office network, AV, and physical access controls

Qualifications

  • 5+ years of hands-on experience in security engineering, IT security, or corporate security, with real ownership of internal security programs at a top-tier software/tech company
  • Deep expertise in one or more of the following: identity and access management, endpoint security, cloud security (AWS/GCP/Azure), or SaaS security
  • Hands-on experience with SOC 2 and/or ISO 27001 audits, including scoping, evidence collection, and working with auditors
  • Strong understanding of modern attacker tradecraft — you know how real breaches happen, not just what the frameworks say
  • Direct experience leading incident response for internal security events, from detection through post-mortem
  • Familiarity with modern security tooling across EDR, SIEM, IAM, MDM, DLP, email security, and vulnerability management
  • Strong systems thinking — you can balance security rigor with the reality of a fast-moving startup
  • Clear communicator who can translate security tradeoffs to leadership and non-technical teams
  • Comfort operating with autonomy in an early-stage environment and building programs from scratch, without a manager or team backing you up

Nice to Have

  • Prior experience as the first or founding internal security hire at a startup
  • Background as a practitioner in cybersecurity — SOC, threat detection, red team, or product security experience
  • Relevant certifications (CISSP, OSCP, GCIA, GCIH, CISA, or equivalent)
  • Experience with security operations tooling that Artemis itself sells (SIEM, XDR, detection & response platforms)
  • Familiarity with regulated frameworks beyond SOC 2 and ISO (FedRAMP, HIPAA, PCI, GDPR)

Compensation

We offer a competitive compensation of $180,000-$230,000 per year, and a top-of-market equity component. A variety of factors are considered when determining the compensation, including a candidate’s professional experience. Final offer amounts may vary from the amounts listed.

Equal Opportunity

At Artemis, we believe the best ideas come from diverse teams. We’re committed to creating an inclusive environment where people of all backgrounds, experiences, and perspectives can do their best work. We welcome everyone, regardless of race, gender, age, religion, identity, or anything else that makes you, you.

Source: Artemis careers (Ashby)

Similar roles