The posting, in Jellyfish's own words
archived Oct 8, 2026Jellyfish empowers engineering organizations to become as valuable and effective as possible by analyzing the data from tools and practices they already use. Our products help engineering leaders align their decisions with business initiatives and deliver software-- the right software, efficiently, and on time. We’re solving a real problem that people have today, and our growth is testament to the market potential. We are looking for a Staff Security Engineer to own and lead all Security Engineering activities at Jellyfish. In this pivotal role, you will define the vision, build the strategy, and scale our security engineering program. With a deep background in application security, automated vulnerability management, and SaaS platform security, you will be the ultimate technical authority for security across the organization. You will partner closely with engineering leadership to embed security into our DNA while continuing to stay hands-on by building security features and writing high-quality code. This is a unique opportunity to have complete ownership of security at a high-growth company. If this sounds exciting, we’d like to hear from you!
What you’ll do:
Define Security Strategy & Roadmap: Own and drive the strategic security roadmap, aligning overarching security initiatives with executive business objectives and mitigating top-tier organizational risks. Architectural Leadership: Own, design, and mandate scalable, resilient security architectures across our core infrastructure, platform, and product ecosystem. Own the SDLC: Define, implement, and govern the Secure Development Lifecycle (SDLC) company-wide, pioneering automated threat modeling, continuous risk assessments, and secure development practices. Secure AI Development & Governance: Partner closely with engineering and data science teams to establish and enforce secure development lifecycle (SDLC) practices specifically for both internal AI tools and customer-facing AI features. AI Threat & Risk Modeling: Lead comprehensive threat modeling and continuous risk assessments tailored to artificial intelligence and machine learning ecosystems, mitigating unique risks such as prompt injection, data poisoning, and sensitive data leakage. Drive Automation at Scale: Spearhead the overarching strategy and development for automated remedial workflows, comprehensive vulnerability management, and advanced software composition analysis solutions. Mentorship & Cross-Functional Influence: Act as the definitive security leader, mentoring engineers, advising executive leadership on security posture, and cultivating a pervasive culture of security and inclusion. Lead Threat & Incident Management: Direct the organizational response for critical security incidents, oversee manual and automated threat modeling, and dictate the strategy for pentesting and bug bounty programs.