SECTION I · THE BRIEF
Brief #65113Updated 04 AUG 2026REMOTELeverSOFTWARE COMPANIES
Employbl Company Profile

Lead Security Engineer (Penetration Testing)

HighLevel help agencies & marketers thrive with their all-in-one sales & marketing platform. Capture leads using their landing pages, surveys, forms, calendars, inbound phone system & more.

Location
Remote
Company size
200–1,000
Posted
4w ago
Via
Lever
Section II · Full ProfileFree with an account
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

Free account · no card · 2 minutes

HighLevel logo

Lead Security Engineer (Penetration Testing) · HighLevel

View company profile
Job title
Lead Security Engineer (Penetration Testing)
Job location
India
Job description
About Us
HighLevel is an AI powered, all-in-one white-label sales & marketing platform that empowers agencies, entrepreneurs, and businesses to elevate their digital presence and drive growth. We are proud to support a global and growing community of over 1 million businesses, comprised of agencies, consultants, and businesses of all sizes and industries. HighLevel empowers users with all the tools needed to capture, nurture, and close new leads into repeat customers. As of mid 2025, HighLevel processes over 4 billion API hits and handles more than 2.5 billion message events every day. Our platform manages over 470 terabytes of data distributed across five databases, operates with a network of over 250 microservices, and supports over 1 million hostnames.
Our People
With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment. We are building more than software; we are building a global community rooted in creativity, collaboration, and impact. We take pride in cultivating a culture where innovation thrives, ideas are celebrated, and people come first, no matter where they call home.
Our Impact
As of mid 2025, our platform powers over 1.5 billion messages, helps generate over 200 million leads, and facilitates over 20 million conversations for the more than 1 million businesses we serve each month. Behind those numbers are real people growing their companies, connecting with customers, and making their mark - and we get to help make that happen.
About the Role
We are looking for a Lead Security Engineer– Application Security & AI Security with 8+ years of experience to help secure HighLevel’s products, platforms, and AI-powered capabilities. This is a hands-on technical leadership role focused on building and scaling Application Security practices while driving security initiatives for AI-enabled products.You will work closely with Engineering, Product, Infrastructure, and AI teams to embed security into every stage of the software development lifecycle. You’ll provide technical leadership, mentor engineers, influence secure architecture decisions, and help define the future of security across our engineering organization.
Learn more about us on our YouTube Channel or Blog Posts
What You’ll Be Doing:
  • Lead Application Security initiatives across HighLevel’s products and engineering teams.
  • Proliferate security standards recommended by central security team as best practices within Dev teams.
  • Conduct architecture reviews, secure design assessments, and threat modeling for new features and platforms.
  • Perform security assessments for Web, Mobile, and API-based applications.
  • Define and drive secure SDLC practices across engineering teams.
  • Partner with developers to identify, prioritize, and remediate security vulnerabilities.
  • Lead security reviews for AI/LLM-powered applications, agents, and AI integrations.
  • Develop security guardrails for AI systems, including protections against prompt injection, data leakage, insecure tool usage, model abuse, and emerging AI attack techniques.
  • Improve security tooling and automate security testing within CI/CD pipelines.
  • Champion secure coding practices through developer enablement, documentation, and training.
  • Drive vulnerability management efforts and improve remediation workflows.
  • Mentor engineers and foster a strong security-first engineering culture.
  • Drive cross-functional collaboration by communicating complex security risks to technical and non-technical stakeholders, influencing product roadmaps, and ensuring alignment between security priorities and engineering objectives.
  • Stay current with emerging threats, application security trends, and advancements in AI security.
  • What You’ll Bring:
  • 8+ years of experience in Cybersecurity, with deep expertise in Application Security and leading engineering-focused security initiatives.
  • Comprehensive technical knowledge in securing Web, Mobile (Android/iOS), and API (REST/GraphQL) environments, including OWASP standards and authentication protocols (OAuth 2.0, OIDC, JWT, SAML).
  • Proven experience performing security assessments including threat modeling, secure design/code reviews, penetration testing, and architecture reviews.
  • Hands-on DevSecOps proficiency: automating security in CI/CD pipelines, container security (Kubernetes/Docker), and managing security tooling (SAST, DAST, SCA, Secret Scanning).
  • Specialized expertise in AI/LLM security, including mitigation of prompt injection, data leakage, model misuse, and insecure agent/tool integration.
  • Proficiency in programming/scripting (Python, Go, JavaScript, or Bash) and strong communication skills to influence technical stakeholders across product and engineering teams.
  • Preferred Qualifications
    • Experience securing workloads on Google Cloud Platform (GCP).
    • Experience with Infrastructure as Code security (Terraform).
    • Familiarity with CSPM/CNAPP solutions.
    • Experience leading or participating in Red Teaming, adversary simulation, or purple team exercises.
    • Experience with DevSecOps and security automation.
    • Security certifications such as CEH, OSCP, GWAPT, CISSP, GCP Professional Cloud Security Engineer, or similar.
    • Contributions to open-source security projects, bug bounty programs, or security research.
    View job listing ↗
    The Saturday Briefing

    Get the Saturday tech briefing

    New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.

    HighLevel headquarters

    Dallas, TX

    Company size

    2001,000 employees

    Founded

    2018

    Total raised

    $60,000,000

    View company profile ↗

    Funding rounds