a16z

Partner 20, Staff Engineer, Enterprise Security

San Francisco, California · Posted today

Opens a16z.com

Get a version of your resume written for this job.

Salary
Not listed
Job type
Not specified
Work mode
Not specified
Source
Greenhouse (employer's hiring system)

Skills mentioned

SaaS, iOS, Databricks, Cybersecurity, Zero Trust, Incident Response, Figma

About the role

Founded in Silicon Valley in 2009 by Marc Andreessen and Ben Horowitz, Andreessen Horowitz (aka a16z) is a venture capital firm that backs bold entrepreneurs building the future through technology. We are stage agnostic. We invest in seed to venture to growth-stage technology companies, across AI, bio + healthcare, consumer, crypto, enterprise, fintech, games, and companies building toward American dynamism. a16z has $100B+ under management across multiple funds.

We’ve established a team that is defined by respect for the entrepreneur and the company-building process; we know what it’s like to be in the founder’s shoes. We’ve invested in companies like Anduril, Airbnb, Coinbase, Cursor, Databricks, Deel, Figma, GitHub, Roblox, SpaceX, and Stripe. Our team is at the forefront of new technology, helping founders and their companies impact and change the world.

The Role

We're hiring a Staff Engineer to own enterprise security at a16z: insider risk, data protection, SaaS security, and the secure adoption of AI across the firm. This is a program-ownership role. You'll set the strategy for how the firm protects its most sensitive data, pick and implement the tooling, write the policies with IT, and see them through to working controls.

The threats here are not theoretical. We handle material nonpublic information on deals and portfolio companies, and we see social engineering, data exfiltration risk, and threat actors who specifically target venture capital firms. At the same time, the firm is adopting AI tools and agents faster than almost any company of its size, and doing that safely is a core part of this job. Your work protects the firm, our LPs, and our portfolio companies. You'll work day to day with the Head of Cybersecurity, Security Engineering, IT, Legal, and Compliance.

This role requires an in-office presence 2 days a week, Tuesday and Thursday, in our San Francisco, CA office, with occasional days in our Menlo Park, CA office.

To join our team, you should be excited to:

  • Own the firm's insider risk and data protection program end to end, including selecting and implementing our next DLP platform and pioneering AI-augmented DLP with LLM-based investigative tooling and automated analysis
  • Drive secure AI adoption across the firm: Secure the AI tools and agents the firm uses, define guardrails for agentic systems acting on firm data, and build the governance that lets a16z adopt AI quickly without exposing sensitive information
  • Own SaaS security posture across the firm's vendors: A prioritized vendor inventory, SSPM, secure configuration baselines, and monitoring for risky changes
  • Set authentication and authorization policy with IT, including Okta, device trust, MFA enforcement, and access reviews, and drive it through to enforcement
  • Manage EDR across the fleet, covering deployment, coverage, and rulesets on macOS, Windows, and iOS, and work with IT on MDM policies
  • Own security through the joiner, mover, and leaver lifecycle, with particular depth on offboarding: Access revocation, data holds, and exfiltration checks
  • Run and improve the firm's vendor security due diligence process so new tools get a consistent, fast, risk-based review
  • Monitor, investigate, and respond to data exfiltration and insider risk events, partnering with Incident Response and Legal
  • Participate in the Security team’s oncall rotation

Minimum Qualifications

  • 7+ years of experience in security engineering or enterprise security roles
  • Deep expertise across Identity and Access Management, authentication and authorization, DLP and insider risk tooling, SaaS security posture management, and endpoint management
  • A track record of owning security programs like DLP, insider risk, or SaaS security end to end: setting strategy, selecting vendors, driving implementation across teams you don't control, and being accountable for the outcome
  • Hands-on experience securing AI tools and agentic systems in an enterprise environment, including data flow controls, model and tool access governance, and evaluating AI vendors
  • Experience with modern enterprise infrastructure and SaaS ecosystems, including Google Workspace, Okta, MDM solutions, SSPM, zero trust architecture, and cloud-native environments
  • Experience running third-party and vendor security assessments at scale
  • Experience translating technical risk into language non-technical stakeholders can act on
  • Low ego, high empathy, and the capacity to collaborate effectively with diverse teams

The anticipated salary range for this role is between $243,000 - $284,000, actual starting pay may vary based on a range of factors which can include experience, skills, and scope.

This role is eligible to participate in the a16z carry program and various discretionary bonus programs as well as benefit and perquisite plans including health, dental, vision, disability, life insurance, 401K plan, vacation, and sick leave.

a16z culture 

  • We do only first class business and only in a first class way
  • We take a long view of relationships, because we are in the relationship business 
  • We believe in the future and bet the firm that way
  • We are all different, we recognize that, and we win
  • We celebrate the good times
  • We do it for the team
  • We play to win

At a16z we are always looking to hire the absolute best talent and recognize that diversity in our experiences and backgrounds is what makes us stronger. We hire candidates of any race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, Veteran status, and any other status. These differences are what enables us to work towards the future we envision for ourselves, our portfolio companies, and the World.

Our organization participates in E-Verify. Click here to learn about E-Verify.

Andreessen Horowitz hereby reserves the right to make use of any unsolicited resumes received from outside recruiting agencies and / or individual recruiters without being responsible for payment of any fees asserted from the use of unsolicited resumes.

Job ID gh-a16z-8004626003 · Original posting ↗