cover
Full Time

Lead Security Engineer/ 1 week ago

LawnStarter
Attractive
Application ends: 2026-09-19

Quick Summary

LawnStarter, a $100M+ on-demand home services marketplace, seeks a Lead Security Engineer in Curitiba, Paraná, Brazil, to transform its security function from informal to instrumented. This hands-on role involves end-to-end ownership of application, cloud, and compliance security across PHP/Laravel, TypeScript/React, and AWS, including securing AI-agent authored code and driving PCI, SOC 2, and LGPD readiness. You will define the multi-year security strategy, build controls, and establish the foundation to lead a dedicated security team within 12-18 months, operating as a fully remote independent contractor with top-of-market compensation and AI tooling.

About LawnStarter

LawnStarter is the nation's leading on-demand marketplace for lawn care and outdoor services, boasting over $100M in annual bookings. We are expanding our reach beyond lawn care to become a comprehensive one-stop shop for all home services. This expansion operates across three distinct brands: LawnStarter, Lawn Love, and Home Gnome, all powered by a single shared platform. Our ecosystem involves active customers and service professionals, with real financial transactions occurring daily.

About Security at LawnStarter

Security is an integral part of our development process, currently managed by our Cloud & DevOps team, who have maintained a robust posture as we've scaled. As we continue to grow a marketplace exceeding $100M, processing payments, safeguarding customer and professional data, and operating on AWS, coupled with the accelerated shipping capabilities enabled by AI agents, we are poised to elevate our security capabilities with a dedicated leader.

This role is for that leader: an individual who will transform security from a distributed, informal practice into a deliberate, instrumented function. You will define the multi-year strategic direction for the organization and, eventually, for a dedicated security team. You will collaborate closely with delivery teams and the Cloud & DevOps team. Initially, you will undertake most of the hands-on work, benefiting from the autonomy of a founding hire and the support of an engineering organization committed to robust security. A key aspect of this position involves building a security framework that can scale beyond a single individual, establishing the standards, playbooks, and hiring criteria that will form the foundation for the team you will ultimately lead.

The Role

As the Lead Security Engineer, you will oversee security at LawnStarter end-to-end. This includes the PHP/Laravel and TypeScript/React codebase, the AWS infrastructure, payment and customer data flows, and the overall compliance posture. You will be responsible for setting the multi-year security direction, building essential controls, and serving as the primary point of contact for all security-related inquiries within the organization.

You will begin in a hands-on capacity, functioning as a "security-of-one" with a clear trajectory to lead a small team within approximately 12-18 months, once a solid foundation is established and the first hire is justified. This is not a hands-off management position; your leadership will be demonstrated through direct action. While you will collaborate extensively with delivery teams and leverage the Cloud & DevOps team as needed, the majority of the initial heavy lifting will be yours. Therefore, you will prioritize ruthlessly, automate diligently, and focus on critical initiatives that genuinely reduce risk, rather than pursuing a comprehensive but less impactful list of tasks.

What makes this role different:

  • Lead the Security Function: You will evolve security from an informal, distributed practice into a deliberate, instrumented one, encompassing threat models, automated scanning, and incident runbooks, all designed and built by you to scale.
  • Span Every Layer: Your responsibilities will cover Application Security (AppSec) one day, AWS Identity and Access Management (IAM) the next, and PCI scoping the day after. Breadth of expertise is fundamental to this role.
  • Secure an AI-Agent Codebase: A significant portion of new code is generated by AI agents. Ensuring the security of this rapidly produced code presents a unique challenge that many security engineers have not yet encountered.
  • Build for Team Growth: Beyond solving immediate problems, you will establish the standards, playbooks, and hiring benchmarks for the future security team you will lead.
  • Set the Security Bar: You will be the primary security voice, defining and championing the security standards for the entire organization and its future security team.

Requirements

What You'll Own

  • Application Security: Threat modeling critical paths, implementing secure Software Development Life Cycle (SDLC) practices, conducting code and design reviews, integrating SAST (Static Application Security Testing), secret scanning, and dependency scanning into CI/CD, and managing a vulnerability management loop that effectively closes findings.
  • Cloud & Infrastructure Security: Managing AWS posture (IAM, network, encryption), secrets management, EKS/Kubernetes hardening, and collaborating with Cloud & DevOps to establish guardrails preventing misconfigurations in production.
  • Compliance & Data Protection: Mapping PCI scope for payment processing, driving SOC 2 and LGPD readiness initiatives, managing vendor risk, and confidently responding to customer or auditor security questionnaires.
  • Detection & Response: Enhancing detection coverage on critical paths (using Datadog, Sentry, AWS signals), developing an incident runbook, and building the capability to lead a response during security incidents.
  • Security Bar for AI-Agent Code: Defining the scans, review gates, and conventions necessary for shipping agent-authored code both quickly and securely.
  • Foundation for Team Leadership: Establishing the standards, playbooks, and hiring criteria that will enable the security function to scale beyond a single individual.

Problems to Solve

  • Leading Security Across a $100M Marketplace: Managing a broad security surface area—including payments, customer and professional Personally Identifiable Information (PII), three brands, a shared codebase, and live AWS infrastructure—initially as a sole contributor. The challenge lies in effective sequencing and automation to maintain a high security bar while planning for team expansion.
  • Keeping Pace with AI-Agent-Authored Code: Addressing the security implications of AI agents generating most new code at high velocity. This requires building automated gates, secure-coding conventions, and evaluations to detect vulnerabilities at agent speed without becoming a bottleneck.
  • Maturing Our Compliance Posture: Formalizing existing data protection practices into structured, audit-ready compliance (PCI scope, SOC 2, LGPD). This involves mapping scope, prioritizing efforts, and achieving audit readiness efficiently.
  • Becoming the Trusted Security Voice and Building the Team: Partnering with engineers to make security an enabler, building controls that are adopted, mentoring colleagues, and establishing a foundation for hiring and leading a security team that upholds high standards.

What Success Looks Like (Year 1)

  • Risk Management: A comprehensive threat model and risk register for critical paths are established, and the highest-severity risks identified are demonstrably closed.
  • Pipeline Security: SAST, secret scanning, and dependency scanning are integrated into CI/CD, with a review loop optimized for AI-agent code, ensuring findings are triaged and resolved.
  • Compliance Baseline: PCI scope is clearly mapped, a credible plan or initial milestone for SOC 2 / LGPD readiness is achieved, and security questionnaires can be answered with confidence.
  • Detection & Response Capability: Detection coverage spans critical paths, an incident runbook is developed and rehearsed, and baseline Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR) metrics are established.
  • Team Growth Plan: A credible multi-year security roadmap is in place, along with a concrete plan and business case for the first security hire(s), including scope, level, and timing.
  • Proactive Risk Mitigation: No P1 customer- or pro-facing security incidents occur due to a known gap that was identified and deprioritized without proper flagging.

Who You Are

  • AI-Native: You regularly utilize AI tools for security tasks such as triaging findings, threat modeling, reviewing AI-authored code, and drafting detections and policies. You possess informed opinions on AI's role in enhancing security and introducing new risks.
  • Deep Across Most of the Stack: You have substantial, hands-on expertise in at least three areas among application security, cloud security, compliance, and incident response, demonstrating depth in building and owning controls, with the ability to quickly master the fourth.
  • A Builder and Leader-in-Training: You are motivated by shaping and elevating security practices from informal to instrumented, and by setting standards that improve the capabilities of fellow engineers, even before holding a formal management title.
  • A Pragmatic Risk-Prioritizer: You prioritize implementing controls that offer the greatest risk reduction with the least friction, and you are comfortable deferring real but low-priority risks.
  • A Hands-On Engineer: You actively write scripts, build pipelines, configure AWS guardrails, and implement detections yourself.
  • A Strong Collaborator: You work closely with delivery teams and Cloud & DevOps, fostering collaboration rather than simply escalating issues.
  • Payments- and Marketplace-Minded: You understand the importance of securing real customer and professional transactions and data on the platform, and you assess risk with these business implications in mind.

This Role Is NOT

  • Not a Specialist Lane: This role requires broad engagement across application security, cloud security, and GRC, not a narrow focus.
  • Not a Gatekeeper Seat: Your primary function is to enable safe and efficient shipping, not to block releases.
  • Not a Paper-and-Policy Role: While compliance is a component, the ability to build technical controls is essential.
  • Not a Hands-Off Management Role: You will lead by example, starting as an individual contributor with a clear path to building and leading a small team within 12-18 months.
  • Not a Caretaker Role: This position involves actively shaping and advancing the security practice, not merely maintaining an existing program.

Benefits

  • Lead Security Transformation: A unique opportunity to define a company's security function, advocate for its first dedicated team, and influence every strategic decision.
  • Top-of-Market Cash Compensation: Remuneration exceeds senior-level security engineering rates, reflecting the leadership scope and technical expertise required.
  • Fully Remote (Brazil): Work with a US-distributed engineering team. The role emphasizes deep focus and asynchronous work, trusting you to manage your own environment.
  • Contractor (PJ) Engagement: A Brazil-based independent contractor arrangement, without equity.
  • AI Tooling Provided: Access to Claude Code and the same AI agent stack utilized by the rest of the engineering team, including for security tasks.

Share

LawnStarter

LawnStarter

  • Address
    São Paulo, Estado de São Paulo
View Profile
Your experience on this site will be improved by allowing cookies Cookie Policy