- Lumaai
- Redwood City, MN
- Full-Time
- 72 days ago
- $235,000–$353,000
Staff Security Software Engineer.
Before you go
Before you leave us, sign up for our email alerts
We don't do job spam, just the best digital jobs delivered straight to your inbox.
Staff Security Software Engineer: our view in 3 lines...
- The Role:This role is for a staff-level security engineer focused on building security foundations for AI models and products.
- The Person:The person will design and build access control, secrets management, encryption, key management, agent permissioning, auditability, and threat modeling systems, while improving incident detection and enterprise security readiness.
- Requirements:The ideal candidate has built and operated security foundations, writes code, reviews infrastructure, and has deep experience with threat modeling and modern identity and secrets practices.
About the role
You'll build the security foundations under Luma's models and products: identity, access control, secrets, encryption, and how autonomous AI systems are granted and constrained in their authority. This is a hands-on, senior security-builder role.
As adoption scales, Luma's models are becoming critical infrastructure for enterprises, and AI systems are becoming actors that retrieve data, call tools, and take actions on their own. You'll design secure-by-default systems rather than bolt security on afterward. It fits an engineer who writes code, thinks in trust boundaries, and drives problems to resolution. If you want a policy-only or review-only security role, this is a builder seat instead.
What You'll Own
-
Design and govern how access to production systems is granted, with scalable RBAC/ABAC across infrastructure and products.
-
Build robust secrets management, credential lifecycle, encryption, and key-management patterns.
-
Define how agents and automated systems receive, scope, and lose authority.
-
Create auditability and forensic visibility for user and system actions.
-
Lead threat modeling across infrastructure, product, and research, and strengthen incident detection and response.
-
Make secure patterns easy and automatic for engineering teams, and drive enterprise security readiness.
First 90 Days
One way the first 90 could unfold.
-
Days 1–30 — Immerse & Diagnose: Map the current access, secrets, and trust boundaries, and where the biggest risks and enterprise gaps are.
-
Days 30–60 — Ship & Validate: Ship a foundational system (identity/access or secrets management) that engineers actually adopt.
-
Days 60–90 — Scale & Systemize: Extend to agent permissioning and audit, and build toward enterprise security readiness.
What You Bring
-
You've built and operated security foundations in real production environments.
-
Excellent at writing code, reviewing infrastructure, and shipping systems.
-
You think in systems and trust boundaries, and understand that software can act with real authority.
-
Deep thought about how services, automations, or models are scoped, constrained, and observed.
-
High agency, and the ability to balance pragmatism with long-term rigor.
Nice to Have
-
Experience evolving organizations toward mature, scalable security architectures.
-
Least-privilege access and modern identity models, and durable secrets and credential lifecycle practices.
-
Experience securing multi-tenant AI platforms and permissioning autonomous systems.
-
Detection and response in high-growth environments, and representing security in customer and partner discussions.
About Luma: Luma's mission is to build unified general intelligence that can generate, understand, and operate in the physical world. We believe multimodality is critical for intelligence — the next step beyond language models comes from vision. Luma is an equal opportunity employer.

