cover
Full Time

Lead Security Engineer/ 14 hours ago

LawnStarter
Attractive
Application ends: 2026-10-29

Quick Summary

LawnStarter seeks a fully remote Lead Security Engineer ($80k-$100k USD) to transform security from informal to a deliberate, instrumented function for a $150M+ marketplace. This hands-on role, with a path to lead a team in 12-18 months, requires deep expertise in at least three of AppSec, Cloud Security (AWS, EKS), Compliance (PCI, SOC 2, LGPD), and Incident Response, with a focus on securing PHP/Laravel/TypeScript/React codebase and AI-agent authored code.

LawnStarter is the nation's leading on-demand marketplace for lawn care and outdoor services, boasting over $150M in annual bookings. We are expanding our reach beyond lawn care to become a comprehensive hub for all home services, operating under three distinct brands: LawnStarter, Lawn Love, and Home Gnome. These brands share a unified platform, facilitating daily transactions between customers and service professionals.

Security is an integral part of our development process, currently managed by our Cloud & DevOps team, who have ensured its robustness during our growth. As we scale a marketplace processing over $150M, handling sensitive customer and professional data, and operating on AWS, with AI agents accelerating our shipping capabilities, we are committed to elevating our security posture with a dedicated leader.

This role is for a lead who will transform security from a distributed, informal practice into a deliberate, instrumented function. You will define the multi-year strategic direction for the organization and, eventually, for a dedicated security team. You will collaborate closely with delivery teams and Cloud & DevOps, initially undertaking significant hands-on work. This position offers the autonomy of a founding hire, supported by an engineering organization dedicated to robust security. A key aspect of this role involves establishing security practices that can scale beyond a single individual, laying down the standards, playbooks, and hiring criteria that will form the foundation for the team you will ultimately lead.

The Role

You will lead security at LawnStarter comprehensively, covering the PHP/Laravel and TypeScript/React codebase, AWS infrastructure, payment and customer data flows, and overall compliance posture. Your responsibilities include setting the multi-year security direction, building necessary controls, and serving as the primary point of contact for all security-related inquiries within the organization.

This position begins with a hands-on approach, functioning as a security-of-one, with a clear progression path to leading a small team within approximately 12-18 months, once a solid foundation is established and the first hire is justified. This is not a hands-off management role; leadership is demonstrated through direct involvement. While you will collaborate extensively with delivery teams and leverage Cloud & DevOps support, the majority of the initial heavy lifting will be yours. Therefore, you will prioritize rigorously, automate diligently, and focus on critical actions that genuinely reduce long-term risk, rather than pursuing an exhaustive list of less impactful tasks.

What makes this role different:

  • You will lead the security function, transforming it from an informal practice into a deliberate, instrumented one, encompassing threat models, automated scanning, and incident runbooks, all designed and built by you to scale effectively.
  • You will span every layer of security, addressing Application Security (AppSec) one day, AWS Identity and Access Management (IAM) the next, and PCI scoping the day after. Broad expertise is a core requirement, not an optional stretch.
  • You will secure an AI-agent codebase. A significant portion of new code is generated by AI agents, presenting a unique challenge in maintaining security at speed that most security engineers have not yet encountered.
  • You will build the foundation for the future team you will lead. Your work extends beyond solving immediate problems; you will establish the standards, playbooks, and hiring benchmarks for the security team you will subsequently lead.
  • You will set the security bar. As the lead security voice, you will define and champion the security standards for the organization and its future team.

Requirements

What You'll Own

  • Application security: This includes threat modeling critical paths, implementing secure-SDLC practices, conducting code and design reviews, integrating SAST/secret-scanning/dependency-scanning into CI, and managing a vulnerability-management loop that effectively closes findings.
  • Cloud & infrastructure security: Responsibilities cover AWS posture (IAM, network, encryption), secrets management, EKS/Kubernetes hardening, and partnering with Cloud & DevOps to establish guardrails preventing misconfigurations in production.
  • Compliance & data protection: This involves mapping PCI scope for payments, driving SOC 2 and LGPD readiness, managing vendor risk, and confidently responding to customer or auditor security questionnaires.
  • Detection & response: You will strengthen detection coverage on critical paths (Datadog, Sentry, AWS signal), develop an incident runbook, and build the capability to lead a response when an incident occurs.
  • The security bar for AI-agent code: This entails defining the scans, review gates, and conventions that enable fast and safe deployment of agent-authored code.
  • The foundation for the team you'll lead: You will establish the standards, playbooks, and hiring criteria necessary for security to scale beyond a single individual.

Problems to Solve

  • Leading security across a $150M marketplace: The security surface is extensive, encompassing payments, customer and professional PII, three brands, a shared codebase, and live AWS infrastructure, with you as the sole security professional initially. The challenge lies not in identifying tasks, but in effective sequencing when resources are limited, and automating sufficiently to maintain high standards while planning for future team growth. You will determine how to identify and mitigate the most critical risks first, building scalable solutions for subsequent engineers.
  • Keeping pace with AI-agent-authored code: A majority of our code is now generated by AI agents, leading to faster code deployment than manual human review can accommodate. Manual security review alone is not scalable. You will develop automated gates, secure-coding conventions, and evaluations to detect real vulnerabilities at agent speed, without becoming a bottleneck for the engineering organization.
  • Maturing our compliance posture: We prioritize careful handling of payments and customer data. The next step involves formalizing these practices into structured, audit-ready compliance (PCI scope, SOC 2, LGPD). You will map the scope, prioritize initiatives, and achieve audit readiness without creating excessive bureaucracy. The goal is to establish a program that effectively protects customers and facilitates business deals.
  • Becoming the trusted security voice — and building the team behind it: You will collaborate with engineers across the organization, fostering partnership rather than issuing commands. If security is perceived as a hindrance, its effectiveness diminishes. You will make secure practices the easy path, build controls that are readily adopted, mentor engineers, and prepare to hire and lead a team that upholds these same standards.

What Success Looks Like (Year 1)

  • Risk is thoroughly mapped, and the highest-priority risks are eliminated. A threat model and risk register are established for critical paths, and the most severe identified risks are closed, with verifiable evidence.
  • Security is integrated into the pipeline. SAST, secret scanning, and dependency scanning run within CI, with a review loop optimized for AI-agent code. Findings are triaged and resolved efficiently.
  • Compliance has a robust baseline. PCI scope is mapped, SOC 2 / LGPD readiness has a credible plan or has achieved its first milestone, and you can confidently answer security questionnaires.
  • We possess detection and response capabilities. Detection coverage spans critical paths, an incident runbook is developed and rehearsed, and baseline Mean Time To Detect (MTTD) and Mean Time To Recover (MTTR) are established.
  • The security team has a clear plan. A credible multi-year security roadmap is in place, along with a concrete plan and business case for the first security hire(s), including scope, level, and timing, enabling the organization to decide on function growth.
  • No P1 incidents arise from known gaps. There are no customer- or professional-facing security incidents attributable to a risk you identified and deprioritized without proper flagging.

Who You Are

  • AI-native: You regularly utilize AI tools in your security work for tasks such as triaging findings, threat modeling, reviewing agent-authored code, and drafting detections and policies. You possess informed opinions on how AI enhances security and where it introduces new risks. This role is likely not a good fit if you are skeptical of AI tools or prefer manual methods exclusively.
  • Deep across most of the stack: You possess substantial, hands-on expertise in at least three areas among application security, cloud security, compliance, and incident response. This implies a depth beyond surface familiarity, having built and owned controls in these domains, with the ability to quickly master the fourth. This role is unlikely to be suitable if you prefer to specialize in a single narrow area and delegate the rest.
  • A builder and a leader-in-training: You are motivated by shaping and elevating security practices, transforming them from informal to instrumented, and by establishing standards that improve the capabilities of engineers around you, even before holding a management title. This role is not a good fit if you prefer to work heads-down without interest in growing a function or mentoring individuals.
  • A pragmatic risk-prioritizer: You implement controls that offer the greatest risk reduction with the least friction, and you are comfortable deferring real but low-priority risks. This role is unsuitable if you treat all findings with equal urgency or pursue a perfect security posture over a shippable one.
  • A hands-on engineer: You are capable of writing scripts, building pipelines, configuring AWS guardrails, and deploying detections. This role is not a good fit if your security experience is primarily limited to policy, audits, and presentations without direct involvement in building technical controls.
  • A strong collaborator: You work closely with delivery teams and Cloud & DevOps, engaging them in the process rather than simply handing off findings. This role is not suitable if your inclination is to gatekeep, block, or police rather than enable.
  • Payments- and marketplace-minded: You understand the significance of real customers, professionals, and financial transactions flowing through the platform, and you reason about risk in these practical terms. This role is not a good fit if your approach to security is abstract and detached from the business it protects.

This Role Is NOT

  • Not a specialist lane: This role is not for those who wish to focus exclusively on application security, cloud security, or GRC; you will engage with all these areas.
  • Not a gatekeeper seat: Your primary responsibility is not to block releases or issue denials, but to facilitate safe and efficient deployment.
  • Not a paper-and-policy role: While compliance is part of the job, you will struggle if you cannot build the technical controls that underpin the policies.
  • Not a hands-off management role: You will lead by example, starting as an individual contributor (security-of-one) with an explicit mandate to build and lead a small team within approximately 12-18 months, encompassing hiring, mentoring, and setting team standards. This role is not suitable if you seek to transition directly into management without prior hands-on work.
  • Not a caretaker role: You are not inheriting a fully established program to maintain; rather, you are tasked with shaping and elevating the security practice from its current state.

Benefits

  • Base salary: $80,000–$100,000 USD annually.
  • Lead security and elevate it to the next level. This is a unique opportunity to define a company's security function, build the case for its inaugural team, and guide its future direction with your direct influence on every decision. The scope and autonomy are significant attractions.
  • Top-of-market cash compensation. Compensation is set above senior-level security engineering rates, reflecting the lead scope and the technical leadership expected in this role.
  • Fully remote. You will collaborate with a US-distributed engineering team. Deep focus and asynchronous work are fundamental to how security is accomplished here; we trust you to manage your own work environment effectively.
  • AI tooling provided. Access to Claude Code and the agent stack utilized by the rest of the engineering team, including security functions.

Share

LawnStarter

LawnStarter

  • Address
    São Paulo, Estado de São Paulo
View Profile
Your experience on this site will be improved by allowing cookies Cookie Policy