LawnStarter logo

LawnStarter

Lead Security Engineer

Work from home

Remote role where the employee must remain based in a particular country.

Brazil only

Employer listed it 5 weeks ago · Found 1h ago

Been open since 5 weeks ago, still being checked, but it has been live a while.

Salary

$80k to $100k per year

Location

Brazil only

Work style

Async

Contract

Full-time

Experience

Lead

Category

Software

Stated by the employer in the job description

Remote flexibility

Work from home

This is a remote role, but the employee must be based in Brazil. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "Brazil, Remote"

What Nomaders makes of it

  • Residency required in Brazil
  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About LawnStarter

LawnStarter is the nation's leading on-demand marketplace for lawn care and outdoor services, with over $150M in annual bookings. We're expanding beyond lawn care to become the one-stop shop for all home services — operating across three brands (LawnStarter, Lawn Love, Home Gnome) on a single shared platform, with customers and pros on both sides and real money moving every day.

About Security at LawnStarter

Security is already part of how we build — today it's owned by our Cloud & DevOps team, who've kept it solid as we've scaled. As we grow a $150M+ marketplace that processes payments, holds customer and pro data, and runs on AWS — and as AI agents let us ship faster than ever — we're ready to take security to the next level with a dedicated leader.

You'd be that person: the lead who takes security from a distributed, informal practice to a deliberate, instrumented one, and who sets the multi-year direction the org — and eventually a team — follows. You'll partner closely with the delivery teams and with Cloud & DevOps, and you'll start by doing most of the heavy lifting yourself, with the autonomy of a founding hire and the backing of an engineering org that already cares about getting this right. Part of the job is building security so it can outgrow one person: the standards, playbooks, and hiring bar you lay down now are the foundation for the team you'll grow into leading.

The Role

You lead security at LawnStarter end-to-end: the PHP/Laravel and TypeScript/React codebase, the AWS infrastructure, the payments and customer-data flows, and the compliance posture. You set the multi-year direction, build the controls, and are the person the org looks to on every security question.

You start hands-on — security-of-one for now — with an explicit path to leading a small team within roughly 12-18 months, once the foundation is solid and the first hire makes sense. This isn't a hands-off management role: you lead by doing first. You'll collaborate heavily with the delivery teams and lean on Cloud & DevOps where it helps, but most of the heavy lifting is yours today. So you'll prioritize ruthlessly, automate hard, and pick the few things that actually reduce risk over the long list that merely looks thorough.

What makes this role different:

You lead the function. You'll take security from a distributed, informal practice to a deliberate, instrumented one — threat models, automated scanning, incident runbooks — all bearing your design, and all built to scale past you.

You span every layer. AppSec one day, AWS IAM the next, PCI scoping the day after. Breadth is the job, not a stretch.

You secure an AI-agent codebase. Most new code here is authored by AI agents. Keeping that safe — at speed — is a problem most security engineers haven't faced yet.

You build for the team you'll grow. You're not just solving today's problem; you're laying the standards, playbooks, and hiring bar for the security team you'll lead next.

You set the bar. You're the lead security voice, and the standard for the org — and its future team — is the one you define and champion.

Requirements

What You'll Own

Application security — threat modeling the critical path, secure-SDLC practices, code and design review, SAST/secret-scanning/dependency-scanning in CI, and a vulnerability-management loop that actually closes findings.

Cloud & infrastructure security — AWS posture (IAM, network, encryption), secrets management, EKS/Kubernetes hardening, partnering with Cloud & DevOps on the guardrails that keep misconfigurations out of production.

Compliance & data protection — mapping PCI scope for payments, driving SOC 2 and LGPD readiness, vendor risk, and being the person who can confidently answer a customer or auditor security questionnaire.

Detection & response — strengthening detection coverage on the critical path (Datadog, Sentry, AWS signal), an incident runbook, and the muscle to lead a response when something fires.

The security bar for AI-agent code — the scans, review gates, and conventions that let agent-authored code ship fast and safely.

The foundation for the team you'll lead — the standards, playbooks, and hiring bar that let security scale beyond one person.

Problems to Solve

Leading security across a $150M marketplace

Requirements

  • ·Application security — threat modeling the critical path, secure-SDLC practices, code and design review, SAST/secret-scanning/dependency-scanning in CI, and a vulnerability-management loop that actually closes findings.
  • ·Cloud & infrastructure security — AWS posture (IAM, network, encryption), secrets management, EKS/Kubernetes hardening, partnering with Cloud & DevOps on the guardrails that keep misconfigurations out of production.
  • ·Compliance & data protection — mapping PCI scope for payments, driving SOC 2 and LGPD readiness, vendor risk, and being the person who can confidently answer a customer or auditor security questionnaire.
  • ·Detection & response — strengthening detection coverage on the critical path (Datadog, Sentry, AWS signal), an incident runbook, and the muscle to lead a response when something fires.
  • ·The security bar for AI-agent code — the scans, review gates, and conventions that let agent-authored code ship fast and safely.

Benefits

  • ·Base salary: $80,000–$100,000 USD annually.
  • ·Top-of-market cash compensation. Paid above senior-level security engineering rates, reflecting the lead scope and the technical leadership this role expects.
  • ·Fully remote. You work with a US-distributed engineering team. Deep focus and asynchronous work are how security gets done here; we trust you to run your own environment.
  • ·AI tooling provided. Claude Code and the agent stack the rest of engineering uses — security included.

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at LawnStarter, mentioning your remote working experience and working hours (Async).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 1h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$80k to $100k per year · You'll be taken to the employer's careers page.