Skip to content

Open nowPosted 7 days ago

Lead Corporate Security Engineer

Suno67 open roles

Pay
$165,000 – $220,000 a year
Where
Boston
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowLead Corporate Security EngineerSuno · Boston
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Suno's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. Suno postings stay open a median of 30 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.5%3 days
  3. 8.0%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 7 days ago

Suno median: 30 days open

The posting

ABOUT SUNO

We're building the world's first creative entertainment platform, where the entire world can feel the joy and fulfillment of making music. Music is for everyone: Our users include everyone from grandmothers creating songs for their loved ones, to Grammy winners using Suno Studio, our power tool, to make the most popular hits in the world.

Building the future of entertainment requires ambition. The pace is fast, the problems are hard, and the work demands ownership and intensity. For the right people, it’s incredibly rewarding: a chance to shape a new medium, work with a small team that cares deeply about quality, make music, drink too much coffee, and build something that millions of people use to express themselves in ways that were never before possible.

Suno is the fastest growing consumer entertainment company and the leader in AI music. We are backed by leading investors including Bond Capital, Menlo Ventures, Lightspeed Venture Partners, IVP, Forerunner, Union Square Ventures, Alkeon, Quiet, Matrix Partners, Schroders Capital and, NVentures (venture arm of NVIDIA).

ABOUT THE ROLE

The Lead Corporate Security Engineer will be our domain expert for securing our Corporate IT environment. You’ll work closely with colleagues in IT, Business Systems, Security, and Engineering to ensure that our corporate systems are implemented and maintained securely. As a senior member of the team, your impact will be split between building your team, enabling others, and doing hands-on work to mature our systems, processes, and behaviors.

You'll lead the corporate security domain end to end: identity and access governance, endpoint and vulnerability management, detection and response, third-party integration risk, vendor assessment, and SaaS posture. You'll set the standard, own the roadmap, and be accountable for the outcome. IT Engineering runs the platforms day to day and are your closest partners.

HOW THIS ROLE WORKS WITH IT

Ownership splits by layer, not by system. IT Engineering owns the run; you own the standard and the direction.

- You set the corporate security roadmap. What we secure, in what order, to what bar with buy-in from leadership and XFN stakeholders

- IT engineering owns platform operations. Our SaaS portfolio is administered and integrated by them. You define what those platforms must enforce

- You raise the bar around you. You make your reasoning explicit so that partners make good security calls without you in the room, and you build the tooling and defaults that make the secure path the default path

WHAT YOU'LL OWN

Identity and access governance

- Own the access model at Suno: the RBAC and entitlement design, least-privilege defaults, and the governance layer in Lumos that enforces them

- Set the standard for what access review, certification, and approval should look like here — then build toward it rather than importing someone else's framework

- Drive access lifecycle automation so joiner/mover/leaver is correct by default and exceptions are visible

- Get ahead of non-human identity: service accounts, agents, and automations are a growing share of what holds access at Suno, and we need a model for them before it's urgent

Endpoint security and vulnerability management

- Own the security standard for our fleet: hardening baseline, compliance signals, device trust, and how endpoint posture feeds access decisions

- Own third-party vulnerability management as a program — coverage, risk-based remediation SLAs, reporting, and the negotiation with teams whose tools are the problem

- Partner with the IT engineer who owns Kandji so the standard becomes deployed policy without degrading how people work

Detection and response

- Own our EDR deployment and maintenance

- Collaborate with Detection and Response on corporate security incidents to closure

Third-party and integration risk

- Own how Suno evaluates third-party access: integration and OAuth review for Slack, Google Workspace and the rest of the portfolio, plus vendor security assessment at purchase and renewal

- Define our risk appetite in practice and make it legible enough that others apply it without you

- Turn recurring decisions into policy, scope guidance, and tooling so the review queue shrinks as the company grows

SaaS security posture

- Build and own the program: the bar for our SaaS applications, the assessment cadence, and the remediation that follows

- Improve tenant-level configuration across the portfolio — SSO and SCIM coverage, MFA and session policy, admin role hygiene, OAuth grant and token management, data sharing defaults

Cross-functional leadership

- Work with IT, Security, Engineering, AI Enablement, and Legal to shape how Suno builds and buys

- Influence the scope of what comes next: how our GRC function plugs in, what we automate versus staff, where the next investment goes

- Mentor and raise the technical bar for people around you, including partners who aren't security specialists

WHAT SUCCESS LOOKS LIKE

- First 90 days: you've formed your own view of our security posture, built working relationships with the IT engineers the broader Security team, and told us the three things we're wrong about

- First 6 months: a corporate security roadmap exists that IT and the CISO are aligned behind, with the sequencing and the tradeoffs made explicit; the highest-risk items are already moving

- First year: entitlement sprawl and vulnerability backlog are measurably down, detection reflects our real risks, third-party review is fast enough that nobody routes around it, and the standard holds because it's built into tooling and shared judgment rather than into you

WHAT YOU'LL BRING

- ~8+ years in corporate/enterprise security or security engineering, including having owned identity, endpoint, or SaaS security as a domain rather than as a set of tickets

- Deep hands-on expertise with a modern IdP and with IGA or access-governance tooling (Lumos, Veza, ConductorOne, Opal, or similar)

- You've designed an entitlement or RBAC model across a large SaaS portfolio and lived with the consequences long enough to know what breaks

- Endpoint security depth in a macOS-primary fleet: MDM-delivered hardening, compliance and device trust, third-party patch and vulnerability management at scale

- Strong command of OAuth, SAML, OIDC, and SCIM, and of the risk model behind third-party integrations

- A track record of setting a security standard that other people applied without you enforcing it — written policy, tooling, defaults, or all three

- Experience influencing engineering and business teams who don't report to you, early enough in their process to change the outcome

- Automation fluency: Python or TypeScript, REST APIs, and a habit of building integrations and internal tooling as a normal part of the job

- Excellent writing and judgment under ambiguity. You can hold a position with an executive and change it when the evidence says to

- A calibrated sense of risk and how to communicate likelihood, impact, and tradeoffs

Helpful, not required: insider risk or DLP programs, zero-trust network access, SOC 2 or ISO program ownership, just-in-time access patterns or identity-as-code, securing AI agent and non-human identity access, prior experience as the first or second security hire at a fast-growing company.

HOW WE LEVEL THIS ROLE

This is an L6 individual contributor role. At Suno, L6 means you shape how a domain operates cross-functionally and set the standard of excellence within it. You identify problems before they become systemic or are named by others. You multiply the efforts and development of the people around you, and you improve the system that produces the work, not just the work itself. You make your principles explicit so others can make good calls independently, and you ensure what you learn travels beyond the immediate team.

Suno is proud to be an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, genetic information, veteran status, or any other legally protected basis under provincial, federal, state, and local laws, regulations, or ordinances. We will also consider qualified applicants with criminal histories in a manner consistent with the requirements of state and local laws, including the Massachusetts Fair Chance in Employment Act, NYC Fair Chance Act, LA City Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Suno's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Suno's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Suno's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.