
Lead Security Engineer/ 14 hours ago
Quick Summary
About LawnStarter
LawnStarter is the nation's leading on-demand marketplace for lawn care and outdoor services, boasting over $150M in annual bookings. We are expanding beyond lawn care to become the ultimate one-stop shop for all home services, operating across three brands (LawnStarter, Lawn Love, Home Gnome) on a single shared platform. Our platform facilitates daily transactions between customers and service professionals.
About Security at LawnStarter
Security is an integral part of our development process, currently managed by our Cloud & DevOps team, who have maintained robust security as we've scaled. As we grow a marketplace exceeding $150M, processing payments, safeguarding customer and professional data, and running on AWS—especially with AI agents enabling faster shipping—we are ready to elevate our security posture with a dedicated leader.
You will be this leader: the individual who transforms security from a distributed, informal practice into a deliberate, instrumented function. You will define the multi-year strategic direction for the organization, and eventually a dedicated team. You will collaborate closely with delivery teams and Cloud & DevOps, initially undertaking most of the hands-on work. This role offers the autonomy of a founding hire, supported by an engineering organization committed to robust security. A key aspect of this position is building a security framework that can scale beyond a single person, establishing the standards, playbooks, and hiring criteria for the future team you will lead.
The Role
You will lead security at LawnStarter comprehensively, covering the PHP/Laravel and TypeScript/React codebase, AWS infrastructure, payment and customer data flows, and compliance posture. You will set the multi-year strategy, implement controls, and serve as the primary point of contact for all security inquiries within the organization.
This role begins hands-on, functioning as a security-of-one, with a clear path to leading a small team within approximately 12-18 months once the foundation is solid and the first hire is justified. This is not a hands-off management position; you will lead by example. You will collaborate extensively with delivery teams and leverage Cloud & DevOps support where beneficial, but the majority of the initial heavy lifting will be yours. Therefore, you will prioritize ruthlessly, automate diligently, and focus on critical actions that genuinely reduce risk, rather than pursuing an exhaustive list of less impactful tasks.
What makes this role different:
- Lead the function: You will evolve security from an informal practice to a deliberate, instrumented one, including threat models, automated scanning, and incident runbooks, all designed and built by you to scale.
- Span every layer: Your responsibilities will encompass Application Security (AppSec) one day, AWS IAM the next, and PCI scoping the day after. Breadth is fundamental to this role, not an additional challenge.
- Secure an AI-agent codebase: A significant portion of new code is generated by AI agents. Ensuring the security of this code at speed presents a unique challenge that most security engineers have not yet encountered.
- Build for the team you'll grow: You are not merely solving current problems; you are establishing the standards, playbooks, and hiring benchmarks for the security team you will eventually lead.
- Set the bar: You will be the primary security voice, defining and championing the security standards for the organization and its future team.
Requirements
What You'll Own
- Application security: Threat modeling critical paths, implementing secure-SDLC practices, conducting code and design reviews, integrating SAST/secret-scanning/dependency-scanning in CI, and managing a vulnerability-management loop that effectively closes findings.
- Cloud & infrastructure security: Managing AWS posture (IAM, network, encryption), secrets management, EKS/Kubernetes hardening, and collaborating with Cloud & DevOps on guardrails to prevent misconfigurations in production.
- Compliance & data protection: Mapping PCI scope for payments, driving SOC 2 and LGPD readiness, managing vendor risk, and confidently responding to customer or auditor security questionnaires.
- Detection & response: Enhancing detection coverage on critical paths (Datadog, Sentry, AWS signal), developing an incident runbook, and building the capability to lead a response when an incident occurs.
- The security bar for AI-agent code: Establishing scans, review gates, and conventions that enable fast and safe shipping of agent-authored code.
- The foundation for the team you'll lead: Defining the standards, playbooks, and hiring criteria that will allow security to scale beyond a single individual.
Problems to Solve
Leading security across a $150M marketplace
The security surface is extensive, encompassing payments, customer and professional PII, three brands, a shared codebase, and live AWS infrastructure—and initially, it's just you. The challenge lies not in knowing what to do, but in effectively sequencing tasks when you cannot do everything simultaneously, and automating sufficiently to maintain high standards while planning for future team growth. How do you identify the most critical risks, mitigate them first, and build a system that can be seamlessly adopted by subsequent engineers?
Keeping pace with AI-agent-authored code
Most of our code is now generated by AI agents, leading to faster code deployment than any human reviewer can manually inspect. Manual security review alone is not scalable. How do you implement automated gates, secure-coding conventions, and evaluations that effectively detect real vulnerabilities at agent speed, without becoming a bottleneck for the engineering organization?
Maturing our compliance posture
We meticulously handle payments and protect customer data; the next step is formalizing this into structured, audit-ready compliance (PCI scope, SOC 2, LGPD). You will map the scope, prioritize actions, and achieve audit readiness without creating excessive bureaucratic overhead. What is the optimal program to protect customers and facilitate business deals?
Becoming the trusted security voice — and building the team behind it
You will collaborate closely with engineers across the organization, rather than dictating terms. If security is perceived as a hindrance, it loses effectiveness. How do you make secure practices the easy path, build controls that are genuinely adopted, mentor your fellow engineers, and position yourself to hire and lead a team that upholds these same standards?
What Success Looks Like (Year 1)
- Risk is mapped and the top of it is gone: A threat model and risk register will exist for the critical path, and the highest-severity risks identified will be closed, supported by evidence.
- Security is in the pipeline: SAST, secret scanning, and dependency scanning will run in CI, with a review loop optimized for AI-agent code. Findings will be triaged and resolved.
- Compliance has a real baseline: PCI scope will be mapped, SOC 2 / LGPD readiness will have a credible plan or a first milestone achieved, and you will be able to confidently answer security questionnaires.
- We can detect and respond: Detection coverage will span the critical path, an incident runbook will be written and rehearsed, and baseline MTTD/MTTR will be established.
- The team has a plan: A credible multi-year security roadmap will be in place, along with a concrete plan and business case for the first security hire(s)—including scope, level, and timing—to guide the organization's decision on function growth.
- No P1 from a known gap: There will be no customer- or pro-facing security incident attributable to a risk you identified and deprioritized without proper flagging.
Who You Are
- AI-native: You utilize AI tools daily in security work, including triaging findings, threat modeling, reviewing agent-authored code, and drafting detections and policies. You possess informed opinions on how AI enhances security and where it introduces new risks. This role is likely not a good fit if you are skeptical of AI tools or prefer manual methods.
- Deep across most of the stack: You have substantial, hands-on expertise in at least three areas among application security, cloud security, compliance, and incident response—demonstrating depth where you've built and owned controls in each—and the ability to quickly master the fourth. This role is likely not a good fit if you prefer to specialize in a narrow lane.
- A builder and a leader-in-training: You are energized by shaping and elevating a practice, transforming it from informal to instrumented, and by setting standards that improve the engineers around you, even before holding a management title. This role is likely not a good fit if you prefer a purely heads-down role without interest in growing a function or its people.
- A pragmatic risk-prioritizer: You implement controls that yield the greatest risk reduction with the least friction, and you are comfortable deferring real but low-priority risks. This role is likely not a good fit if you treat every finding with equal urgency or pursue perfect posture over shippable solutions.
- A hands-on engineer: You write scripts, build pipelines, configure AWS guardrails, and deploy detections. This role is likely not a good fit if your security experience is primarily limited to policy, audits, and presentations without building technical controls yourself.
- A strong collaborator: You work closely with delivery teams and Cloud & DevOps, fostering collaboration rather than simply delegating findings. This role is likely not a good fit if your instinct is to gatekeep, block, and police rather than enable.
- Payments- and marketplace-minded: You understand the significance of real customers, professionals, and financial transactions flowing through the platform, and you assess risk in these terms. This role is likely not a good fit if you approach security abstractly, detached from the business it protects.
This Role Is NOT
- Not a specialist lane: If your preference is exclusively appsec, cloud, or GRC, this role is not for you. You will engage with all these areas.
- Not a gatekeeper seat: Your primary responsibility is not to block releases or say no; it is to facilitate safe shipping as the easy path.
- Not a paper-and-policy role: While compliance is part of the job, you will struggle here if you cannot build the technical controls underpinning the policy.
- Not a hands-off management role: You will lead by doing first, starting as an individual contributor (security-of-one), with the explicit goal of building and leading a small team within approximately 12-18 months—including hiring, mentoring, and setting their operational standards. If you seek to bypass hands-on work directly into management, this role is not suitable.
- Not a caretaker role: You are not inheriting a fully established program to merely maintain; you are tasked with shaping and elevating the security practice, which is the core purpose of this position.
Benefits
- Base salary: $80,000–$100,000 USD annually.
- Lead security and take it to the next level: This is a unique opportunity to define a company's security function, build the case for its first team, and drive its evolution with your direct influence on every decision. The scope and autonomy are significant attractions.
- Top-of-market cash compensation: Paid above senior-level security engineering rates, reflecting the lead scope and the technical leadership expected in this role.
- Fully remote: You will work with a US-distributed engineering team. Deep focus and asynchronous work are fundamental to how security operates here; we trust you to manage your own environment.
- AI tooling provided: Access to Claude Code and the agent stack utilized by the rest of the engineering team, including security.

