Lead Security Engineer
LawnStarter
About LawnStarter
LawnStarter is the nation's leading on-demand marketplace for lawn care and outdoor services, with over $100M in annual bookings. We're expanding beyond lawn care to become the one-stop shop for all home services — operating across three brands (LawnStarter, Lawn Love, Home Gnome) on a single shared platform, with customers and pros on both sides and real money moving every day.
About Security at LawnStarter
Security is already part of how we build — today it's owned by our Cloud & DevOps team, who've kept it solid as we've scaled. As we grow a $100M+ marketplace that processes payments, holds customer and pro data, and runs on AWS — and as AI agents let us ship faster than ever — we're ready to take security to the next level with a dedicated leader.
You'd be that person: the lead who takes security from a distributed, informal practice to a deliberate, instrumented one, and who sets the multi-year direction the org — and eventually a team — follows. You'll partner closely with the delivery teams and with Cloud & DevOps, and you'll start by doing most of the heavy lifting yourself, with the autonomy of a founding hire and the backing of an engineering org that already cares about getting this right. Part of the job is building security so it can outgrow one person: the standards, playbooks, and hiring bar you lay down now are the foundation for the team you'll grow into leading.
The Role
You lead security at LawnStarter end-to-end: the PHP/Laravel and TypeScript/React codebase, the AWS infrastructure, the payments and customer-data flows, and the compliance posture. You set the multi-year direction, build the controls, and are the person the org looks to on every security question.
You start hands-on — security-of-one for now — with an explicit path to leading a small team within roughly 12-18 months, once the foundation is solid and the first hire makes sense. This isn't a hands-off management role: you lead by doing first. You'll collaborate heavily with the delivery teams and lean on Cloud & DevOps where it helps, but most of the heavy lifting is yours today. So you'll prioritize ruthlessly, automate hard, and pick the few things that actually reduce risk over the long list that merely looks thorough.
What makes this role different:
- You lead the function. You'll take security from a distributed, informal practice to a deliberate, instrumented one — threat models, automated scanning, incident runbooks — all bearing your design, and all built to scale past you.
- You span every layer. AppSec one day, AWS IAM the next, PCI scoping the day after. Breadth is the job, not a stretch.
- You secure an AI-agent codebase. Most new code here is authored by AI agents. Keeping that safe — at speed — is a problem most security engineers haven't faced yet.
- You build for the team you'll grow. You're not just solving today's problem; you're laying the standards, playbooks, and hiring bar for the security team you'll lead next.
- You set the bar. You're the lead security voice, and the standard for the org — and its future team — is the one you define and champion.
Requirements
What You'll Own
- Application security — threat modeling the critical path, secure-SDLC practices, code and design review, SAST/secret-scanning/dependency-scanning in CI, and a vulnerability-management loop that actually closes findings.
- Cloud & infrastructure security — AWS posture (IAM, network, encryption), secrets management, EKS/Kubernetes hardening, partnering with Cloud & DevOps on the guardrails that keep misconfigurations out of production.
- Compliance & data protection — mapping PCI scope for payments, driving SOC 2 and LGPD readiness, vendor risk, and being the person who can confidently answer a customer or auditor security questionnaire.
- Detection & response — strengthening detection coverage on the critical path (Datadog, Sentry, AWS signal), an incident runbook, and the muscle to lead a response when something fires.
- The security bar for AI-agent code — the scans, review gates, and conventions that let agent-authored code ship fast and safely.
- The foundation for the team you'll lead — the standards, playbooks, and hiring bar that let security scale beyond one person.
Problems to Solve
Leading security across a $100M marketplace
The surface is broad — payments, customer and pro PII, three brands, a shared codebase, live AWS infra — and for now it's just you. The hard part isn't knowing what to do; it's sequencing it well when you can't do everything at once, and automating enough that one person can hold a high bar while planning for the team that comes next. How do you find the risks that matter most, burn them down first, and build in a way that a second and third engineer can pick up cleanly?
Keeping pace with AI-agent-authored code
Most of our code is now written by AI agents, which means more code shipping faster than any human reviewer can read. Manual security review alone doesn't scale to that. How do you build automated gates, secure-coding conventions, and evals that catch real vulnerabilities at agent speed — without becoming the bottleneck the engineering org routes around?
Maturing our compliance posture
We take payments and protect customer data with care; the next step is formalizing that into structured, audit-ready compliance (PCI scope, SOC 2, LGPD). You'll map what's in scope, decide what's worth doing now versus later, and get us audit-ready without turning the company into a checkbox factory. What's the right program that protects customers and unblocks deals?
Becoming the trusted security voice — and building the team behind it
You'll partner with engineers across the org rather than command them. If security is seen as the thing that slows everyone down, it loses. How do you make secure the easy path, build controls people actually adopt, mentor the engineers around you, and set yourself up to hire and lead a team that carries that same standard forward?
What Success Looks Like (Year 1)
- Risk is mapped and the top of it is gone. A threat model and risk register exist for the critical path, and the highest-severity risks you found are closed — with evidence, not assertions.
- Security is in the pipeline. SAST, secret scanning, and dependency scanning run in CI, with a review loop tuned for AI-agent code. Findings get triaged and fixed.
- Compliance has a real baseline. PCI scope is mapped, SOC 2 / LGPD readiness has a credible plan or a first milestone passed, and you can answer a security questionnaire with confidence.
- We can detect and respond. Detection coverage spans the critical path, an incident runbook is written and rehearsed, and you've established baseline MTTD/MTTR.
- The team has a plan. A credible multi-year security roadmap exists, along with a concrete plan and business case for the first security hire(s) — scope, level, and timing — so the org can decide when to grow the function.
- No P1 from a known gap. No customer- or pro-facing security incident traceable to a risk you'd identified and deprioritized without flagging it.
Who You Are
AI-native. You use AI tools daily in security work — triaging findings, threat modeling, reviewing agent-authored code, drafting detections and policy. You have opinions about where AI sharpens security and where it creates new risk. This is unlikely to be a good fit if you're skeptical of AI tools or prefer to do everything by hand.
Deep across most of the stack. You have real, hands-on expertise in at least three of appsec, cloud, compliance, and response — not surface familiarity, but the kind of depth where you've built and owned controls in each — and the range to pick up the fourth fast. This is unlikely to be a good fit if you only want to work one narrow lane and hand off the rest.
A builder and a leader-in-training. You're energized by shaping a practice and leveling it up — taking it from informal to instrumented — and by setting standards that make the engineers around you better, even before you have a title that says "manager." This is unlikely to be a good fit if you only want to be heads-down with no interest in growing a function or the people on it.
A pragmatic risk-prioritizer. You ship the control that reduces the most risk for the least friction, and you're comfortable saying "not now" to a real-but-low risk. This is unlikely to be a good fit if you treat every finding as equally urgent or chase a perfect posture over a shippable one.
A hands-on engineer. You write the script, build the pipeline, configure the AWS guardrail, ship the detection. This is unlikely to be a good fit if your security experience is policy, audits, and slide decks without building the controls yourself.
A strong collaborator. You work shoulder-to-shoulder with delivery teams and Cloud & DevOps, bringing them along rather than throwing findings over the wall. This is unlikely to be a good fit if your instinct is to gatekeep, block, and police rather than enable.
Payments- and marketplace-minded. You care that real customers and pros and real money flow through this platform, and you reason about risk in those terms. This is unlikely to be a good fit if you think about security in the abstract, detached from the business it protects.
This Role Is NOT
- Not a specialist lane. If you want to do only appsec, or only cloud, or only GRC, this isn't it. You'll touch all of it.
- Not a gatekeeper seat. Your job isn't to block releases and say no — it's to make shipping safely the easy path.
- Not a paper-and-policy role. Compliance is part of the job, but if you can't build the technical controls behind the policy, you'll struggle here.
- Not a hands-off management role. You lead by doing first: you start as an individual contributor, security-of-one, and you're explicitly hired to build and lead a small team within roughly 12-18 months — hiring, mentoring, and setting the standard they'll work to. If you want to skip straight to managing without doing the work yourself, this isn't it.
- Not a caretaker role. You're not inheriting a finished program to keep ticking — you're shaping and leveling up the practice, and that's the point.
Benefits
- Lead security and take it to the next level. This is the rare chance to define a company's security function, build the case for its first team, and take it forward with your fingerprints on every decision. The scope and autonomy are the draw.
- Top-of-market cash compensation. Paid above senior-level security engineering rates, reflecting the lead scope and the technical leadership this role expects.
- Fully remote (Brazil). You work with a US-distributed engineering team. Deep focus and asynchronous work are how security gets done here; we trust you to run your own environment.
- Contractor (PJ) engagement. Brazil-based independent contractor arrangement. No equity.
- AI tooling provided. Claude Code and the agent stack the rest of engineering uses — security included.
- ...! ABOUT THE ROLE We are looking for a Senior Quality Engineer to drive quality throughout the software development lifecycle... ...products using modern technologies alongside global teams and leading brands - Collaborative culture : join a supportive environment...
- ...ROLE We are looking for a Senior/Lead Salesforce Developer to develop and enhance... ...APIs. - Understanding of prompt engineering concepts or applying generative AI tools... ...with data preparation, governance, and security considerations for AI-enabled solutions....
- ...experienced Shopify professional to build and lead our e-commerce practice. This role... ...help clients turn Shopify into a growth engine, all within a remote-first environment.... ...integrations end-to-end; - Drive scalable and secure solutions, establish coding standards,...
- ...ExpertiseServe as the regional expert across fragrance, makeup, and skincare, ensuring deep product and brand storytelling knowledge. ●Lead all training-related aspects of product launches, ensuring teams are fully prepared prior to market activation. ●Elevate in-store...
- ...looking for a Seasoned Technical Product Owner (10+ years) to lead the roadmap and continuous improvement of our healthcare contact... ...platform. ● In this role, you will bridge business strategy and engineering—translating complex operational needs in the Provider/Payer...
- Regional Business Leader ( Us & Canada) - Detalhes da Vaga. ● This role is best suited for... .... ● Program & Project Delivery (Core)- Lead multiple transmission line projects (EPC... ...Build and lead the US project delivery and engineering team- Drive collaboration between local teams...
- ...best practices, data ingestion patterns, security and governance frameworks, CI/CD... ...Key ResponsibilitiesDesign scalable and secure Microsoft Fabric architectures aligned with... ...Fabric projects. ●Collaborate with data engineers, BI developers, business stakeholders, and...
- ...HDS teams such as R&D, CloudOps, Customer Success, Performance Engineering, and PMO. ●Partner with PMO to align project management... ...degree, preferred in Engineering or Computer Science2-4 years leading Agile or DevOps teams, preferably certified as Scrum Master. ●...
- Ocm (Organisational Change Management) Lead - Detalhes da Vaga. ● The OCM Lead will be accountable for the timely and high-quality execution of the OCM methodology and deliverables, ensuring activities remain aligned to the overall programme roadmap. ● The role will work...
- Technical Lead - Detalhes da Vaga. ● This will primarily involve auditing annotation outputs, onboarding and mentoring new hires, and analyzing datasets to identify trends or anomalies. ● This person must be able to translate complex technical concepts, manage project...
- ...Service - Act as the logistics point of contact, closely partnering with local sales teams to provide early feasibility assessments, lead-time, and cost commitments for orders and projects. ● Interface with end customers, synchronize logistics milestones, resolve...
- ...In Brazil and Latin America, we are building partnerships with leading media, telecom, digital platforms and brands to make Asian entertainment... ...role requires the ability to independently organize priorities, lead meetings, prepare proposals, follow up on opportunities and...
- ...before releases. ●Help analyze product performance metrics and prepare reports for stakeholders. ●Collaborate with Product, Design, Engineering, and Customer Success teams to improve the overall user experience. ●Stay current on emerging AI technologies and creator economy...
- ...technology teams, and project team members. ●Lead and support requirements-gathering... ...and collaborating with developers, data engineers, architects, quality assurance professionals... ...require the individual to be a developer, data engineer, or advanced technical specialist. ●Basic...
- ...not only enhances operational efficiency but also reduces waste, leading to better outcomes for both businesses and the planet. ● Global... ..., Master Planning and S&OP. ●Characteristics: Strong ability to lead by example and demonstrate proficiency in both product and domain...
- ...ResponsibilitiesDrive revenue growth for Personal Care Actives and related ingredients across assigned territories. ●Identify, qualify, and secure new business with formulators, contract manufacturers, and brand owners. ●Expand business opportunities and share of wallet with...
- ...ZeroLayer Router Kafka (isolamento de tópicos por tenant), definindo estratégia de autenticação sem lock-in (OIDC, mTLS). ●Definir engines relacionais e não relacionais por célula, projetando sharding alinhado ao tenant key, com réplicas, failover e criptografia em repouso...
- Senior Fpga Developer - Detalhes da Vaga. ● A leader in light management technologies for 3D... ...are seeking a Principal/Staff-level FPGA Engineer — a recognized technical authority — to... ...Verilog/SystemVerilog/VHDL and industry-leading simulation, synthesis, place-and-route, and...
- ...are looking for a ServiceNow Discovery Engineer to join an enterprise-scale Discovery Engineering... ..., automated testing, code quality/security scanning, release management, and... ...technologies alongside global teams and leading brands - Collaborative culture : join...
- ...ABOUT THE ROLE We are looking for a Senior Site Reliability Engineer to provide core system administration and operational... ...products using modern technologies alongside global teams and leading brands - Collaborative culture : join a supportive environment...
- ...ABOUT THE ROLE We are looking for a Platform Engineer to own the administration and secure deployment of critical enterprise tooling across a large... ...using modern technologies alongside global teams and leading brands - Collaborative culture : join a...
- ...Atividades do Estagiário: - Apoio no gerenciamento da carteira de clientes (Lead x Operador); - Realização de atendimento telefônico ativo e receptivo; - Auxílio na prospecção de clientes por meio de WhatsApp, SMS, e-mail e chat; - Participação na elaboração e apresentação...
R$ 9.000
...: # Experiência em Segurança da Informação, Segurança de Aplicações ou Governança de TI; # Conhecimento de conceitos de SSDLC (Secure Software Development Life Cycle); # Conhecimento em gestão de riscos e frameworks de segurança; # Familiaridade com normas e frameworks...- ...HR Manager Pernambuco, Brazil (On-site) We are seeking an experienced HR Manager to support and lead human resources activities within a large-scale industrial operation undergoing a significant growth and transformation phase. This is a hands-on leadership...
- ...partnering with our Global Infrastructure, Security, Network, Enterprise, Application, and Data teams to ensure everything we ship is secure, compliant, and aligned with company... ...global cloud strategy. ●Day to day, you will:Lead application modernization — re-platform...
- ...shape the future with cutting-edge technology. We have evolved into a Global Financial Super App, delivering complete solutions and leading innovation. Here, work has purpose: creating real opportunities, transforming people’s lives, and reshaping the financial market....
- ...enterprise platforms? As a Senior Software Engineer on our Cloud team in Recife, you will... ...supervision ~Own production reliability: lead incident response, monitor SLOs/SLIs, and... ...experience across cloud environments. ~Embed security into the platform: secrets management,...
- ...strategic, results-driven enterprise sales leader who excels at navigating business... ...will cast a vision for your territory, leading partner-led demand generation and driving... ...bridge between Marketing, SDR, and Sales Engineering to ensure cohesive market execution, while...
- ...and systems and reliability engineering applied in a cloud environment... ...relatively early stage and help us engineer a scalable, hybrid-cloud... ...Cloud architecture; ~Close security gaps mapped by our InfoSec and... ...work culture ~Working at a leading open-source company Equal...
- ...users rely on every day? As a Frontend Engineer on our Cloud team in Recife, you will help... ...Cloud Architect, DevOps Engineer, Security Engineer, or Network Engineer What... ...collaborative work culture ~Working at a leading open-source company Equal Opportunities...
Deseja receber mais vagas?
Assine e receba vagas semelhantes a Lead Security Engineer. Seja o primeiro a se candidatar!

