--- title: 'Sr. Security Engineer at C1' canonical: 'https://feeny.ai/job/sr-security-engineer-c1-san-francisco-rdt5td39fez8' type: 'job' last_seen: '2026-09-12' --- # Sr. Security Engineer at C1 - **Company:** C1 - **Location:** San Francisco, CA - **Employment:** full-time - **Posted:** 2026-09-09 - **Last confirmed live:** 2026-09-12 - **Apply:** https://jobs.ashbyhq.com/c1/d03cc2f5-e577-4854-a192-f9ff5f39d660 ## Job description C1 is the first AI-native identity security platform that protects every identity: human, non-human, and AI. With powerful automation, platform-level AI, and out-of-the-box connectors, it centralizes access visibility, enforces fine-grained controls, enables just-in-time access, and automates user access reviews across all apps. It's easy to use, quick to deploy, and trusted by enterprises like DigitalOcean, Instacart, Ramp, and Zscaler. ## The Role We're hiring a Senior Security Engineer to join a small, early-stage security team with a broad remit - spanning security engineering, application and cloud security, and compliance. This is a generalist role: you'll have the opportunity to go deep in one domain over time while staying hands-on and supportive across others. Our stack is primarily Go and AWS. Little of this job is manual. Instead of hand-reviewing every ticket, spec, or deploy, you'll spend your time building the purpose-built agents and skills that do that work continuously, and using them to orchestrate security into the development lifecycle through a risk-based approach. Our goal is to bake security into design specs up front, not catch it in post-deploy review. You don't just want to hand engineering teams a list of findings - you want to roll up your sleeves and help implement the fix. You care about solving problems systemically, not just patching individual instances, and you want your work to make it easier for everyone at the company to build securely by default. ## What You'll Do - Define and drive security standards and secure-by-default solutions, serving as a subject matter expert for application and/or cloud security. - Build purpose-built agents and skills that orchestrate security into the development lifecycle through a risk-based approach, automating the manual, repetitive work (triage, enrichment, review) so the team can focus on judgment calls, not queues. - Shift security left by baking risk-based review into design specs and architecture decisions, rather than relying on post-deploy audits to catch issues. - Build security tooling and automation that scales security practices across engineering, and help implement meaningful, actionable security observability and detection signals. - Lead threat modeling and risk assessment for high-risk features and platform changes. - Assess and help mitigate security risks introduced by agentic development practices and AI-powered product features running in production. - Partner with engineering teams to prioritize and remediate critical threats, help define API security standards, and conduct security code reviews. - Continuously explore and adopt open-source tools to assess the security of and test our services, rather than defaulting to manual review. - Identify systemic security risks and lead multi-team remediation efforts end-to-end, not just the initial recommendation. - Partner across security, compliance, and engineering on cross-domain problems — be a go-to point of contact when a hard security question needs clarity. - Contribute to compliance and trust initiatives (e.g., SOC 2, ISO 27001/42001) as they intersect with your area of focus. - Invest in the growth of teammates and in raising the security bar across the broader engineering org. ## What We're Looking For - Proven experience securing enterprise SaaS applications, including authentication flows, authorization patterns, and input validation at API boundaries. - Demonstrated experience securing deployment and change-management mechanisms for software and infrastructure. - Background in Software Engineering, Platform Engineering, Systems Engineering, Network Engineering, Cloud Security, or Application Security. - Hands-on code review experience, ideally in Go, Python, or Rust. - Experience with AWS (or another major cloud provider) and comfort working across cloud infrastructure. - Comfortable working both independently and collaboratively in a fast-paced, high-growth environment. - Curious and current on modern security practices, tooling, and emerging threats, including how AI is changing the threat landscape. - Someone to participate quarterly in-person in one of our primary offices San Francisco, or Portland Oregon. Show Us Your Agent Work This role expects real, hands-on experience building agents and automation for security, so we ask candidates to show it rather than just claim it. As part of the process, be ready to share one or more of the following: - A project, demo, or repo where you built an agent, skill, or automation that replaced manual security work (triage, review, detection, etc.). - Examples of how you use AI coding tools or agentic workflows in your day-to-day work. - A short walkthrough - live or recorded - of a security automation you shipped, including the problem, your approach, and the impact. We care about practical results and good judgment in where (and where not) to apply automation, not just familiarity with the latest tools. ## Nice to Have - Experience with Kubernetes, service mesh, or PKI/network technologies (Consul, Envoy, Cilium, Vault, Istio, etc.). - Experience building or extending internal security tooling, automations, or agents. - Prior experience at a high-growth SaaS or identity/access management company. ## Why This Role This is a high-leverage role on a small, early-stage security team: your scope will be broad, your ownership will be real, and the systems you build will shape how a security-first company secures its own products and development lifecycle. You'll have the chance to specialize in the domain you care most about while still touching the full breadth of the security program. ## Compensation & Benefits C1 offers a competitive salary, meaningful equity, and comprehensive health benefits. Specific compensation will be commensurate with experience. ConductorOne, Inc. is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status or any other category protected by law. ## About C1 ## Company Overview - **One-liner**: C1 provides a unified identity and access governance platform designed to secure and manage access for humans, workloads, and AI agents in the modern enterprise. - **Entity Type**: Private (Series B) - **Headquarters**: San Francisco, California, United States - **Founded**: 2021 - **Founders**: Not publicly available ## Core Business - **Primary industry/industries**: Identity and Access Management (IAM), Cybersecurity, AI Infrastructure - **Target customers**: B2B, Enterprise, and Mid-Market organizations undergoing AI transformation - **Mission or purpose statement**: To empower organizations to adopt AI securely and at speed by delivering the right access and context to every human, workload, and agent. ## Products & Services - **C1 Platform**: A unified identity and access governance platform that manages access for humans, services, and AI agents. It provides a universal identity graph, real-time activity monitoring, policy-as-code guardrails, and just-in-time access. The platform is designed to be "headless" and exposes all capabilities via API, MCP, CLI, and Terraform, allowing it to be integrated into any tech stack. - **AI Access Management**: A specific module for governing access for AI agents and tools across data, cloud apps, and infrastructure. It includes self-service MCP access, identity-aware gateways, and support for custom and on-prem MCPs. - **Intelligent Access Reviews**: AI-driven, risk-based access reviews to automate and streamline compliance. ## Market Standing - **Valuation/Market Cap**: Not disclosed - **Key Metric**: Total Funding of $111M (as of Series B in November 2025) - **Notable Investors/Partners**: Greycroft (lead, Series B), Accel, Felicis, CrowdStrike, Fuel Capital, Fathom Capital, Active Capital. - **Growth Signals**: Raised a $79M Series B in November 2025, signaling strong investor confidence and a focus on scaling the platform for the "agentic era." The company is actively hiring across engineering, sales, and operations roles. ## Competitive Advantages - **First-Mover in AI Identity**: C1 is specifically built for the "agentic era," managing access for AI agents and tools alongside human users, which is a nascent but rapidly growing market. - **Headless & API-First Architecture**: Unlike traditional IAM tools, C1 is built as a "headless identity infrastructure," exposing all capabilities via API, MCP, CLI, and Terraform. This makes it highly flexible and embeddable for engineering teams. - **AI-Native Platform**: The platform itself uses AI to drive governance workflows, access reviews, and policy creation, making it faster and more scalable than legacy IAM solutions. - **Strong Investor Backing**: Backed by top-tier VCs (Accel, Greycroft, Felicis) and a strategic investor in CrowdStrike, providing both capital and credibility. ## Strategic Focus - **Agentic Identity**: C1 is doubling down on the "agentic era," building the infrastructure to govern access for non-human identities (AI agents, services, API keys) which is a key growth area. - **Platform Expansion**: Moving beyond traditional IAM to become the "access and context delivery layer" for the entire enterprise, integrating deeply with AI tools and workflows. - **Go-to-Market**: Scaling sales and channel partnerships (hiring Channel Account Managers) to capture enterprise customers undergoing AI transformation. ## Why Work Here - **High-Growth Environment**: As a well-funded Series B startup ($111M total), C1 offers the opportunity to work on cutting-edge problems at the intersection of AI and security. - **Mission-Driven Work**: Employees contribute to building the infrastructure for the "agentic era," a highly relevant and impactful space. - **Culture & Values**: The company emphasizes empathy, authenticity, and collaboration. It has been recognized by Newsweek as one of "America's Greatest Workplaces 2024" and received a Platinum Bell Seal for workplace mental health. - **Benefits**: Comprehensive benefits include health coverage, a 401(k) plan with a 35% match up to 10%, 17 days PTO in the first year, paid parental leave, fertility coverage, and flexible work hours. - **Work Model**: Offers virtual office opportunities and flexible work hours. - **Engineering Culture**: The platform is built for engineers, with a strong emphasis on API-first, headless architecture, and infrastructure-as-code (Terraform, CLI). This suggests a deep technical culture. ## Sources 1. [c1.ai](https://www.c1.ai) 2. [c1.ai/platform-overview](https://www.c1.ai/platform-overview) 3. [linkedin.com](https://www.linkedin.com/company/c1-ai) 4. [onec1.com/careers](https://www.onec1.com/careers) 5. [careers-c1.icims.com](https://careers-c1.icims.com/) ## Other roles at C1 - [Sr. Solutions Engineer - United Kingdom](https://feeny.ai/job/sr-solutions-engineer-united-kingdom-c1-united-kingdom-7sj3fqvksc0x) — United Kingdom - [Technical Support Engineer](https://feeny.ai/job/technical-support-engineer-c1-remote-062gzft63eek) - [Senior Product Manager - Core IGA](https://feeny.ai/job/senior-product-manager-core-iga-c1-san-francisco-2k8tqvqrjmby) — San Francisco, CA - [Solutions Engineer](https://feeny.ai/job/solutions-engineer-c1-san-francisco-pn3xev003x6v) — San Francisco, CA - [Site Reliability Engineer](https://feeny.ai/job/site-reliability-engineer-c1-portland-2wrs2vd2wwn4) — Portland - [Group Product Manager](https://feeny.ai/job/group-product-manager-c1-san-francisco-wjnvdpe4agj1) — San Francisco, CA - [Software Engineer](https://feeny.ai/job/software-engineer-c1-san-francisco-h3x0yj3h1y38) — San Francisco, CA - [Senior Product Marketing Manager](https://feeny.ai/job/senior-product-marketing-manager-c1-san-francisco-9ze4365wescm) — San Francisco, CA - [Sr. Solutions Engineer](https://feeny.ai/job/sr-solutions-engineer-c1-remote-1c8mpwwmg8bv) - [Sales Development Representative](https://feeny.ai/job/sales-development-representative-c1-san-francisco-qj9tg5v6xba3) — San Francisco, CA