Luma AI · 1 day ago
Security Engineer - Tech Lead
Luma AI is a leading generative AI company focused on building multimodal AI to expand human imagination and capabilities. The Security Engineer - Tech Lead will be responsible for establishing the security function, driving the security posture of products and services, and leading compliance efforts for security certifications.
Responsibilities
Own Product & Application Security: Define and drive Luma’s approach to secure product development from design reviews to automated scanning to runtime protections
Secure GenAI Systems: Analyze and secure the full lifecycle of generative models (image, video, multimodal), including data ingestion, model inference, and API surface
Lead Threat Modeling & Security Architecture Reviews: Run deep security reviews on new features, architectures, and model capabilities, with a focus on abuse prevention, data leakage, and content safety
Build Security Infrastructure: Stand up tools and systems for static analysis, dependency scanning, secrets detection, and CI/CD hardening with a heavy focus on automation
Drive Compliance Readiness: Lead the technical and procedural efforts to get Luma through critical security certifications, including SOC 2, ISO 27001, HIPAA, and FedRamp
Architect and Implement Identity & Access Management (IAM): Design and deploy a robust IAM framework to govern access to critical systems and data, addressing current organizational challenges
Define Misuse & Abuse Guardrails: Partner with ML and product teams to mitigate prompt injection, jailbreaks, adversarial inputs, and misuse of generative outputs
Lead Security Incident Detection & Response Management: Lead investigations and forensics for security incidents, vulnerabilities, or model abuse cases
Build the Function: Establish best practices, influence an org-wide security culture, and help hire and grow a high-caliber security team as the company scales
Qualification
Required
10+ years of deep experience in security engineering, with a heavy focus on product and application security
A successful and verifiable track record of personally leading a company through security certifications, such as SOC 2, ISO 27001, HIPAA, and FedRamp
Proven ability to operate as a hands-on builder and technical leader in a fast-moving startup environment
Strong understanding of generative AI systems or high-complexity ML applications and their related risks (e.g., prompt injection, data leakage)
Proficiency in secure development in at least one of our core languages (Python, Go, or C++)
Experience securing systems, networks, and cloud-native environments (e.g., AWS, GCP) and infrastructure (e.g., Docker/Kubernetes)
Deep experience with threat modeling, secure design, modern application security tooling (SAST, DAST, IaC scanning), and a strong focus on automation
Excellent communication skills and experience successfully leading cross-functional teams to drive security initiatives
Preferred
You hold relevant industry certifications such as CISSP, CISM, CISA, or OSCP
You have been the first security hire or a founding security engineer at a high-growth startup
Experience with red teaming, adversarial ML, or AI safety frameworks
Company
Luma AI
Luma AI develops tools that let users generate photorealistic images and videos from text, image, or video prompts.
H1B Sponsorship
Luma AI has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (10)
2024 (3)
Funding
Current Stage
Growth StageTotal Funding
$1.06BKey Investors
HUMAINAndreessen HorowitzAmplify Partners
2025-11-19Series C· $900M
2024-12-06Series B· $90M
2024-01-09Series B· $43M
Recent News
2026-01-06
Crunchbase News
2025-12-10
Company data provided by crunchbase