Startups

DevSecOps Engineer

Pathos · New York, NY · On-site

← All jobs
About Pathos

Drug development shouldn’t be guesswork, not when patients are waiting. Pathos is building a next-generation biotech with AI at the core. Not as a feature, but as the operating system for how medicines get developed. Backed by NEA.

About the role

We handle some of the most sensitive data around: patient outcomes, clinical trial records, and the multimodal datasets behind our foundation model, all inside a company that runs on agents with broad, standing access to internal systems. That combination raises the stakes on security in a way most companies never have to think about.

What they're looking for

  • Threat models and security architecture for a system built around large numbers of autonomous AI agents with access to internal tools, data, and MCP-style servers
  • Guardrails, sandboxing, and permissioning for how agents talk to systems and each other, so they can act without excessive standing privileges
  • Secure CI/CD pipelines, infrastructure-as-code review, and automated security testing (SAST/DAST, dependency and secret scanning) built into how we ship, not added on after
  • Monitoring, detection, and incident response tooling tuned for AI-native infrastructure, including anomalous agent behavior, prompt injection attempts, and data exfiltration paths
  • Data governance and access controls for a governed warehouse and knowledge graph holding patient-level and clinical trial data, aligned with HIPAA and relevant regulatory frameworks
  • Cloud security posture across our GCP environment: IAM, network segmentation, encryption, audit logging
More about this role

We handle some of the most sensitive data around: patient outcomes, clinical trial records, and the multimodal datasets behind our foundation model, all inside a company that runs on agents with broad, standing access to internal systems. That combination raises the stakes on security in a way most companies never have to think about.

The threat landscape is moving fast too. Capable AI models have lowered the skill floor for finding and exploiting vulnerabilities, so the volume and sophistication of attacks aimed at companies like ours keeps climbing. We need someone who takes that seriously, builds for it before it's a problem, and doesn't treat security as something you check off at the end of a project.

We're hiring a DevSecOps engineer to own security architecture and practice across our AI and data infrastructure: the pipelines, agent tooling, and internal systems that power our BD, clinical development, computational biology, and lab teams. This isn't a compliance-only role. You'll design the guardrails, then get in the code and build them yourself.

What You'll Build

  • Threat models and security architecture for a system built around large numbers of autonomous AI agents...

Read the full posting on Pathos's site ↗

Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.