About InstaLILY
InstaLILY is an AI products and infrastructure company that puts execution at the frontier of enterprise AI. That work begins with Lily™, the world's first AI Forward Deployed Engineer, which learns how a business works, builds the software it needs, and goes live in days. It does not leave when the work ships; it stays and keeps the software working as the business changes. Lily runs wherever the work happens, in the cloud, on-premise, or at the edge, through InstaLILY's Small Data Center, built with NVIDIA technology. Founded in 2023 by Amit Shah and Sumantro Das, InstaLILY has raised nearly $100 million from Energize Capital, Insight Partners, and Home Depot Ventures. Headquartered in New York, with offices in San Francisco, London, and Toronto, InstaLILY serves leading companies across construction, industrial distribution, logistics, healthcare, and other operationally intensive industries. Learn more at https://instalily.ai/.
The Traction
Revenue grew 5x over the past year, and Lily has driven over $200M in new annual sales for a single customer. We serve some of the largest operators in our industries, including SRS Distribution (part of The Home Depot family), United Rentals, and Henry Schein, and we work closely with the Google DeepMind and NVIDIA ecosystems.
How We Work
We work in small teams with real ownership: clear problems, direct access to the customers whose work you're changing, and room to ship. Your code runs in live production systems inside billion-dollar operations, so you see your impact directly. People who do well here want that proximity to the work. We're growing fast, and the people who join now shape what this company becomes. Everything runs on three principles: Customers, Culture, and Code.
The Role: Own Security for Agents That Do Real Work
We're hiring our first dedicated security leader, reporting directly to the CEO. Lily operates inside the systems of some of the largest enterprises in distribution, construction, healthcare, and logistics. That makes security a core part of the product and a lever on every enterprise deal we close.
This isn't a cold start. We hold SOC 2 Type II and HIPAA, an Okta rollout is underway, and a CNAPP evaluation is in progress. What we need is one accountable owner who can take a strong foundation and turn it into a proactive, evidence-backed security program.
This is a player-coach role. You'll spend 30–50% of your time writing code (automation, infrastructure-as-code, security tooling, remediation PRs), and most of the rest threat-modeling, reviewing architecture and PRs, and hardening cloud and IAM. You'll also be the face of security to enterprise customers, spending roughly 25–30% of your time on CISO calls, audits, and security reviews.
What You'll Do
- Own Customer Trust: Run enterprise security reviews end to end. Build one source of truth for security answers, launch a trust center and security package, and lead CISO and InfoSec calls, audits, and RFP security sections, often on short notice.
- Run the Compliance Program: Keep SOC 2 Type II and HIPAA healthy in Drata: continuous control monitoring, policy refreshes, and access reviews. Lead us through our next audit window and stand up a GDPR program.
- Harden the Cloud: Partner with SRE to prioritize and close critical and high cloud findings. Make org-level guardrails the default: org policies, secrets management, and least-privilege IAM across GCP and AWS.
- Secure the Agents: Build security into Lily from the start: threat models, prompt-injection defenses, tenant isolation, agent authorization, and security checks in CI as part of a secure SDLC.
- Test and Respond: Commission and run our independent pen-test program and drive remediation. Refresh the incident response plan, run tabletop exercises, and serve as the escalation point for security incidents.
- Build Identity and Endpoint Foundations: Complete SSO (Okta) coverage for tier-1 apps, run quarterly access reviews, and put device management (MDM) in place.
- Set the Operating Model: Decide whether to partner with a vCISO or GRC service for paperwork-heavy work, complete the CNAPP evaluation, and deliver a 12-month security roadmap to the CEO and leadership.
- Grow the Function: Hire and lead 1–2 security or AppSec engineers as the program scales.
What Success Looks Like in Year One
- A clean SOC 2 Type II and HIPAA renewal with no exceptions, and ≥95% of controls passing continuously.
- Standard security questionnaires returned in 3 business days or less, customer CISO calls covered within 1 business day, and every answer backed by evidence.
- An annual independent pen test completed, with critical findings remediated within SLA.
- Critical and high cloud findings closed, with secure-by-default guardrails enforced across the org.
- SSO on all tier-1 apps, quarterly access reviews, and MDM in place.
- AI and agent security built into the platform, not bolted on.
- A GDPR program running and a clear decision on ISO 27001 and HITRUST.
What You'll Need
- 8+ Years in Security Engineering: Including hands-on ownership of a security or compliance program at a SaaS company, ideally at the Series B–C stage.
- Hands-On Cloud and AppSec Depth: Strong in GCP and AWS IAM, Kubernetes, and infrastructure-as-code (Terraform/OpenTofu). You can threat-model a multi-tenant, multi-cloud architecture and review code, not just run scanners.
- A Builder, Not Just a Reviewer: You write production-quality Python or TypeScript and ship your own automation, tooling, and fixes. You'd rather build and harden systems than monitor alerts or manage checklists.
- End-to-End SOC 2 Type II Ownership: You've run the program yourself: audits, controls, evidence, and GRC tooling. You treat compliance as real risk reduction. HIPAA experience is a strong plus.
- Credibility With Enterprise CISOs: You've led customer security reviews, questionnaires, and audits, and can hold your own in a room with a Fortune 500 security team.
- Real LLM Experience: You've built something real with LLMs and understand how agentic systems change the threat model.
- Player-Coach Mindset: You're energized by doing the work yourself. Tech-lead or program-lead experience is enough; formal people management is a plus, not a requirement.
- In-person availability. 5 days/week in our New York or San Francisco office.
Bonus Points
- You've built a security function from scratch at a Series B/C SaaS company and taken it through SOC 2 Type II.
- You've secured an LLM or agent product in production (prompt injection, agent authorization, OWASP Top 10 for LLMs).
- You've led a real incident response.
- Experience with multi-tenant isolation, pen-test programs, Okta or IdP rollouts, and CNAPP tooling such as Wiz or Aikido.
- Familiarity with GDPR, ISO 27001, HITRUST, NIST CSF, or the EU AI Act.
- Certifications such as CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Security Specialty, or OSCP. None are required.
- Public work: talks, writing, or open-source security tooling.
Our Stack
- Cloud: GCP primary (Cloud Run, Cloud SQL, GKE), AWS secondary (EKS); customer deployments also run in AWS and Azure
- Infra and code: Kubernetes, OpenTofu, Postgres, TypeScript/Next.js, Python
- Identity and compliance: Okta, WorkOS, Drata
- Observability and edge: Datadog, Grafana, Sentry, Cloudflare
You'll secure a multi-tenant platform with hundreds of cloud services across multiple clouds, at a company of roughly 100–150 people.
Why InstaLILY?
- Greenfield Ownership: You're the first dedicated security leader, reporting to the CEO, with real influence over how the company builds.
- Frontier Agent Security: AI agents that do real work inside enterprise operations create a new kind of attack surface. This is not another CRUD app.
- Security Is a Revenue Lever: Enterprise deals move on security, so your work is visible and valued across the company.
- A Foundation to Build On: SOC 2 Type II and HIPAA are in place, and core identity and cloud tooling work is already underway.
- Well Funded and Scaling: Fresh off a $60M Series B, with offices in New York, San Francisco, London, and Toronto.
Location, Travel, and On-Call
- Location: New York strongly preferred; San Francisco considered for exceptional candidates.
- Travel: Minimal. Occasional customer onsites or audits, plus periodic trips to New York if based in San Francisco.
- On-call: You'll be the escalation point for security incidents. This is not part of a routine ops rotation.
Compensation and Benefits
- Salary Range: $200,000 – $250,000 per year, commensurate with experience
- Equity: Generous stock option awards and refreshers for top performers
- Benefits: Medical, Dental, Vision, 401K, in-office lunch reimbursement, Wellness Stipend, generous parental leave, PTO and 10 US Federal Holidays, and more!
Quality Over Quantity
To ensure a focused, high-quality hiring experience, we kindly ask candidates to limit their applications to 3 open requisitions at any given time. Applying strategically to roles that best align with your skills and career goals gives you the highest chance of standing out. Have you interviewed with us in the past 12 months? We encourage you to reach out directly to your previous interviewer rather than submitting a new application.
InstaLILY is committed to providing an inclusive and barrier-free recruitment process. If you require an accommodation, please let us know, and we will work with you to meet your needs.