Skip to content

Open nowPosted 7 hours ago

Director, Security Engineering — Instalily Ai

Insight Partners portfolio3,265 open roles

Pay
$200,000 – $250,000 a year
Where
San Francisco, CA, USA
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDirector, Security Engineering — Instalily AiInsight Partners portfolio · San Francisco, CA, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Insight Partners portfolio's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. Insight Partners portfolio postings stay open a median of 28 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.5%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.1%30 days
This job: posted 7 hours ago

Insight Partners portfolio median: 28 days open

The posting

About InstaLILY

InstaLILY is an AI products and infrastructure company that puts execution at the frontier of enterprise AI. That work begins with Lily™, the world's first AI Forward Deployed Engineer, which learns how a business works, builds the software it needs, and goes live in days. It does not leave when the work ships; it stays and keeps the software working as the business changes. Lily runs wherever the work happens, in the cloud, on-premise, or at the edge, through InstaLILY's Small Data Center, built with NVIDIA technology. Founded in 2023 by Amit Shah and Sumantro Das, InstaLILY has raised nearly $100 million from Energize Capital, Insight Partners, and Home Depot Ventures. Headquartered in New York, with offices in San Francisco, London, and Toronto, InstaLILY serves leading companies across construction, industrial distribution, logistics, healthcare, and other operationally intensive industries. Learn more at https://instalily.ai/.

The Traction

Revenue grew 5x over the past year, and Lily has driven over $200M in new annual sales for a single customer. We serve some of the largest operators in our industries, including SRS Distribution (part of The Home Depot family), United Rentals, and Henry Schein, and we work closely with the Google DeepMind and NVIDIA ecosystems.

How We Work

We work in small teams with real ownership: clear problems, direct access to the customers whose work you're changing, and room to ship. Your code runs in live production systems inside billion-dollar operations, so you see your impact directly. People who do well here want that proximity to the work. We're growing fast, and the people who join now shape what this company becomes. Everything runs on three principles: Customers, Culture, and Code.

The Role: Own Security for Agents That Do Real Work

We're hiring our first dedicated security leader, reporting directly to the CEO. Lily operates inside the systems of some of the largest enterprises in distribution, construction, healthcare, and logistics. That makes security a core part of the product and a lever on every enterprise deal we close.

This isn't a cold start. We hold SOC 2 Type II and HIPAA, an Okta rollout is underway, and a CNAPP evaluation is in progress. What we need is one accountable owner who can take a strong foundation and turn it into a proactive, evidence-backed security program.

This is a player-coach role. You'll spend 30–50% of your time writing code (automation, infrastructure-as-code, security tooling, remediation PRs), and most of the rest threat-modeling, reviewing architecture and PRs, and hardening cloud and IAM. You'll also be the face of security to enterprise customers, spending roughly 25–30% of your time on CISO calls, audits, and security reviews.

What You'll Do

  • Own Customer Trust: Run enterprise security reviews end to end. Build one source of truth for security answers, launch a trust center and security package, and lead CISO and InfoSec calls, audits, and RFP security sections, often on short notice.
  • Run the Compliance Program: Keep SOC 2 Type II and HIPAA healthy in Drata: continuous control monitoring, policy refreshes, and access reviews. Lead us through our next audit window and stand up a GDPR program.
  • Harden the Cloud: Partner with SRE to prioritize and close critical and high cloud findings. Make org-level guardrails the default: org policies, secrets management, and least-privilege IAM across GCP and AWS.
  • Secure the Agents: Build security into Lily from the start: threat models, prompt-injection defenses, tenant isolation, agent authorization, and security checks in CI as part of a secure SDLC.
  • Test and Respond: Commission and run our independent pen-test program and drive remediation. Refresh the incident response plan, run tabletop exercises, and serve as the escalation point for security incidents.
  • Build Identity and Endpoint Foundations: Complete SSO (Okta) coverage for tier-1 apps, run quarterly access reviews, and put device management (MDM) in place.
  • Set the Operating Model: Decide whether to partner with a vCISO or GRC service for paperwork-heavy work, complete the CNAPP evaluation, and deliver a 12-month security roadmap to the CEO and leadership.
  • Grow the Function: Hire and lead 1–2 security or AppSec engineers as the program scales.

What Success Looks Like in Year One

  • A clean SOC 2 Type II and HIPAA renewal with no exceptions, and ≥95% of controls passing continuously.
  • Standard security questionnaires returned in 3 business days or less, customer CISO calls covered within 1 business day, and every answer backed by evidence.
  • An annual independent pen test completed, with critical findings remediated within SLA.
  • Critical and high cloud findings closed, with secure-by-default guardrails enforced across the org.
  • SSO on all tier-1 apps, quarterly access reviews, and MDM in place.
  • AI and agent security built into the platform, not bolted on.
  • A GDPR program running and a clear decision on ISO 27001 and HITRUST.

What You'll Need

  • 8+ Years in Security Engineering: Including hands-on ownership of a security or compliance program at a SaaS company, ideally at the Series B–C stage.
  • Hands-On Cloud and AppSec Depth: Strong in GCP and AWS IAM, Kubernetes, and infrastructure-as-code (Terraform/OpenTofu). You can threat-model a multi-tenant, multi-cloud architecture and review code, not just run scanners.
  • A Builder, Not Just a Reviewer: You write production-quality Python or TypeScript and ship your own automation, tooling, and fixes. You'd rather build and harden systems than monitor alerts or manage checklists.
  • End-to-End SOC 2 Type II Ownership: You've run the program yourself: audits, controls, evidence, and GRC tooling. You treat compliance as real risk reduction. HIPAA experience is a strong plus.
  • Credibility With Enterprise CISOs: You've led customer security reviews, questionnaires, and audits, and can hold your own in a room with a Fortune 500 security team.
  • Real LLM Experience: You've built something real with LLMs and understand how agentic systems change the threat model.
  • Player-Coach Mindset: You're energized by doing the work yourself. Tech-lead or program-lead experience is enough; formal people management is a plus, not a requirement.
  • In-person availability. 5 days/week in our New York or San Francisco office.

Bonus Points

  • You've built a security function from scratch at a Series B/C SaaS company and taken it through SOC 2 Type II.
  • You've secured an LLM or agent product in production (prompt injection, agent authorization, OWASP Top 10 for LLMs).
  • You've led a real incident response.
  • Experience with multi-tenant isolation, pen-test programs, Okta or IdP rollouts, and CNAPP tooling such as Wiz or Aikido.
  • Familiarity with GDPR, ISO 27001, HITRUST, NIST CSF, or the EU AI Act.
  • Certifications such as CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Security Specialty, or OSCP. None are required.
  • Public work: talks, writing, or open-source security tooling.

Our Stack

  • Cloud: GCP primary (Cloud Run, Cloud SQL, GKE), AWS secondary (EKS); customer deployments also run in AWS and Azure
  • Infra and code: Kubernetes, OpenTofu, Postgres, TypeScript/Next.js, Python
  • Identity and compliance: Okta, WorkOS, Drata
  • Observability and edge: Datadog, Grafana, Sentry, Cloudflare

You'll secure a multi-tenant platform with hundreds of cloud services across multiple clouds, at a company of roughly 100–150 people.

Why InstaLILY?

  • Greenfield Ownership: You're the first dedicated security leader, reporting to the CEO, with real influence over how the company builds.
  • Frontier Agent Security: AI agents that do real work inside enterprise operations create a new kind of attack surface. This is not another CRUD app.
  • Security Is a Revenue Lever: Enterprise deals move on security, so your work is visible and valued across the company.
  • A Foundation to Build On: SOC 2 Type II and HIPAA are in place, and core identity and cloud tooling work is already underway.
  • Well Funded and Scaling: Fresh off a $60M Series B, with offices in New York, San Francisco, London, and Toronto.

Location, Travel, and On-Call

  • Location: New York strongly preferred; San Francisco considered for exceptional candidates.
  • Travel: Minimal. Occasional customer onsites or audits, plus periodic trips to New York if based in San Francisco.
  • On-call: You'll be the escalation point for security incidents. This is not part of a routine ops rotation.

Compensation and Benefits

  • Salary Range: $200,000 – $250,000 per year, commensurate with experience
  • Equity: Generous stock option awards and refreshers for top performers
  • Benefits: Medical, Dental, Vision, 401K, in-office lunch reimbursement, Wellness Stipend, generous parental leave, PTO and 10 US Federal Holidays, and more!

Quality Over Quantity

To ensure a focused, high-quality hiring experience, we kindly ask candidates to limit their applications to 3 open requisitions at any given time. Applying strategically to roles that best align with your skills and career goals gives you the highest chance of standing out. Have you interviewed with us in the past 12 months? We encourage you to reach out directly to your previous interviewer rather than submitting a new application.

InstaLILY is committed to providing an inclusive and barrier-free recruitment process. If you require an accommodation, please let us know, and we will work with you to meet your needs.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Insight Partners portfolio's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Insight Partners portfolio's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Insight Partners portfolio's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.