We are seeking a highly skilled Security Engineer to join our Series A team as we scale from early product traction to broader customer adoption. You will play a foundational role in owning security engineering at Schemata — the architecture, controls, tooling and compliance posture that let a small startup handle sensitive customer and government data credibly.
At Schemata, we build spatial AI-powered products for blue collar and mission critical work. We combine state-of-the-art applied research in LLMs and spatial reasoning to power AI-enabled workflows used in regulated industries with high standards of accuracy and compliance.
This is a high‑impact, cross‑functional role: security here is both a product requirement and a sales requirement. You will build the technical controls that protect customer data and the evidence base that gets us through federal authorization, vendor security reviews and customer audits.
Core Responsibilities
- Own the security architecture: define and implement how identity, authorization, tenancy isolation, encryption and audit logging work across our platform, and review designs before they become expensive to change
- Red team our AI systems: probe the LLM and spatial reasoning surfaces the way an adversary would — prompt injection, jailbreaks, tool-use and agent abuse, retrieval and training data poisoning, model extraction, and the failure modes specific to grounding models in customer documents and 3D scenes..
- Keep the attack surface clean: own the security pipeline (SAST/DAST, dependency and container scanning, secrets detection, IaC policy checks) and the vulnerability management that follows from it: an accurate picture of what we run, what's actually exploitable, and remediation driven to closure on real timelines.
- Run detection and response: own the security monitoring pipeline day to day. Triage, investigation, containment and post-incident review. Be the person who gets paged, and make each incident produce a durable change: a new detection, a closed gap, a corrected runbook.
- Carry the compliance load: implement and evidence NIST SP 800-53 and SOC 2 controls, support FedRAMP and ATO efforts, and manage POA&M tracking and remediation.
Essential Skills & Experience
- 4+ years in security engineering, application security or cloud security with hands-on implementation ownership, not purely policy or GRC.
- Deep AWS security expertise: IAM design, VPC and network controls, KMS, GuardDuty/Security Hub, and least-privilege at scale.
- Strong applied knowledge of application security — authN/authZ design, common vulnerability classes, secure code review, threat modeling.
- Ability to write real code (Python) to automate controls, evidence collection and tooling.
- Working knowledge of at least one major compliance framework — NIST 800-53/RMF, FedRAMP, SOC 2, or ISO 27001 — and the practical work of evidencing controls.
- Container and Kubernetes security experience: image hardening, runtime policy, supply chain integrity.
- Enough backend or infrastructure ability to be a genuine extra pair of hands outside security: shipping a service, writing a Terraform module, fixing a CI pipeline.
- Clear communication with non-security engineers and with customer security teams alike.
Nice to Have
- Federal authorization experience — running or supporting an ATO, working with AOs and ISSOs, FISMA continuous monitoring.
- Certifications such as CISSP, OSCP, CCSP, CAP, or GIAC equivalents.
- Experience securing ML/AI systems — model supply chain, data governance, prompt injection and inference abuse.
- Familiarity with DISA STIGs, NIST 800-171, CMMC or CUI handling requirements.
- Experience being the first security hire at a startup and building the function from zero.
- Defense, aerospace, energy or other regulated‑industry experience; active or ability to obtain U.S. security clearance.
Why Join Us?
- Own & shape the spatial‑intelligence function at the frontier of multimodal AI and 3D simulation.
- Tackle cutting‑edge problems combining 3D perception, graphics and neural rendering to save lives and billions of dollars.
- Work with world‑class researchers and engineers in a fast‑paced, high‑ownership environment where your innovations ship directly to mission-critical users.
- Competitive upside, meaningful equity, top‑tier benefits and whatever gear you need to excel, with an in‑person culture in San Francisco and flexibility for extraordinary talent.