Startups · AI

Staff Security Software Engineer

Luma AI · Redwood City, CA · Remote

← All jobs
About Luma AI

Luma AI is the creative AI platform for video generation and image creation. Powered by the world's leading video generation models, Ray and Uni, and creative agents handling end-to-end workflows. Trusted by leading agencies and brands. Try it free. Backed by General Catalyst, a16z and CRV.

About the role

You'll build the security foundations under Luma's models and products: identity, access control, secrets, encryption, and how autonomous AI systems are granted and constrained in their authority. This is a hands-on, senior security-builder role.

What they're looking for

  • You've built and operated security foundations in real production environments
  • Excellent at writing code, reviewing infrastructure, and shipping systems
  • You think in systems and trust boundaries, and understand that software can act with real authority
  • Deep thought about how services, automations, or models are scoped, constrained, and observed
  • High agency, and the ability to balance pragmatism with long-term rigor
More about this role

You'll build the security foundations under Luma's models and products: identity, access control, secrets, encryption, and how autonomous AI systems are granted and constrained in their authority. This is a hands-on, senior security-builder role.

As adoption scales, Luma's models are becoming critical infrastructure for enterprises, and AI systems are becoming actors that retrieve data, call tools, and take actions on their own. You'll design secure-by-default systems rather than bolt security on afterward. It fits an engineer who writes code, thinks in trust boundaries, and drives problems to resolution. If you want a policy-only or review-only security role, this is a builder seat instead.

Design and govern how access to production systems is granted, with scalable RBAC/ABAC across infrastructure and products.

Build robust secrets management, credential lifecycle, encryption, and key-management patterns.

Define how agents and automated systems receive, scope, and lose authority.

Create auditability and forensic visibility for user and system actions.

Lead threat modeling across infrastructure, product, and research, and strengthen incident detection and response.

Make secure...

Read the full posting on Luma AI's site ↗

Product & Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.