About the job
About Us
At XOXO, we are a pioneering research lab reshaping the interface of intelligence for daily life. Our stealth team, comprised of exceptional engineers, designers, and researchers, is dedicated to uncovering innovative solutions to challenges that arise beyond the workplace.
Following our recent advancements in infrastructure, architecture, and model layers, we are in search of talented builders to create the interface and application layers that will realize our vision.
About the Role
We are seeking a skilled Security Engineer to safeguard our systems and uphold user trust. In this role, you will fortify our cloud infrastructure, establish robust access controls, and create the tools and response mechanisms necessary to ensure safety as we grow. You will collaborate closely with our founders and engineering team to embed security as a fundamental principle in our development processes.
What You’ll Do
Collaborate with cross-functional teams including engineering, product, and research to integrate security throughout the development lifecycle (e.g., threat modeling, design reviews, and establishing secure defaults).
Enhance cloud infrastructure security and enforce network topology standards, including subnets, firewalls, routing, and organizational security policies.
Develop isolation and segmentation strategies to minimize blast radius and prevent lateral movement within the network.
Create and maintain security tools and automation for engineering teams (such as CI/CD checks, scanning, and guardrails) while driving remediation of security findings.
Enhance observability, detection, and incident response for security-related events (like intrusions, abuse patterns, DDoS attacks, and bot activity), including rapid containment measures.
Design and oversee identity and access management strategies for both users and services, as well as third-party integration controls, with a focus on private connectivity and the principle of least privilege.
Skills & Qualifications
Minimum qualifications include:
Proven experience in deploying security or infrastructure systems from design through to production, achieving measurable enhancements in risk management, reliability, or incident response outcomes.
In-depth knowledge of cloud security practices, including configuration baselines, network topology (subnets/firewalls), and policy enforcement.
Strong software engineering background with the capability to assess production code for security vulnerabilities.
Hands-on experience with securing web applications and APIs, particularly in authentication flows, access control, secrets management, input validation, and data protection practices.

