952,274open jobs
57,593companies
155,586added this week
Browse all
Salary
$277k – $364k per year
Location
In office (Boston)
Seniority
Staff · 8+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 29, 2026. First seen by Alion on Sep 29, 2026. Suno scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Suno is a generative artificial intelligence technology platform specializing in AI-driven music creation. Founded in 2022 by a team of machine learning experts and audio engineers in Cambridge, Massachusetts, the platform allows users to generate complete, high-quality songs - including vocals, instrumentation, and custom lyrics - from simple text prompts.

About Suno

We're building the world's first creative entertainment platform, where the entire world can feel the joy and fulfillment of making music. Music is for everyone: Our users include everyone from grandmothers creating songs for their loved ones, to Grammy winners using Suno Studio, our power tool, to make the most popular hits in the world.

Building the future of entertainment requires ambition. The pace is fast, the problems are hard, and the work demands ownership and intensity. For the right people, it’s incredibly rewarding: a chance to shape a new medium, work with a small team that cares deeply about quality, make music, drink too much coffee, and build something that millions of people use to express themselves in ways that were never before possible.

Suno is the fastest growing consumer entertainment company and the leader in AI music. We are backed by leading investors including Bond Capital, Menlo Ventures, Lightspeed Venture Partners, IVP, Forerunner, Union Square Ventures, Alkeon, Quiet, Matrix Partners, Schroders Capital and, NVentures (venture arm of NVIDIA).

About the role

The Lead Corporate Security Engineer will be our domain expert for securing our Corporate IT environment. You’ll work closely with colleagues in IT, Business Systems, Security, and Engineering to ensure that our corporate systems are implemented and maintained securely. As a senior member of the team, your impact will be split between building your team, enabling others, and doing hands-on work to mature our systems, processes, and behaviors. You’ll be building from 0 → 1 in some places and 1 → 10 in others.

What we don't have yet is someone who owns corporate security as a domain - who decides what the bar is, sequences the work to get there, and sees the next problem before it becomes a fire drill.

That's this role. You'll own the corporate security domain end to end: identity and access governance, endpoint and vulnerability management, detection and response, third-party integration risk, vendor assessment, and SaaS posture. You'll set the standard, own the roadmap, and be accountable for the outcome. Our senior IT engineers run the platforms day to day and are your closest partners - you make their work better, not harder.

How this role works with IT

Ownership splits by layer, not by system. Our senior IT engineers own the run; you own the standard and the direction.

  • You own the corporate security roadmap. What we secure, in what order, to what bar. You bring it to IT leadership and the CISO aligned, not for arbitration

  • IT engineering owns platform operations. Okta, Lumos, Kandji, and the wider SaaS portfolio are administered and integrated by them. You define what those platforms must enforce

  • You raise the bar around you. You make your reasoning explicit so IT engineers make good security calls without you in the room, and you build the tooling and defaults that make the secure path the default path

  • You're accountable for the outcome, not just the proposal. You decide, you communicate the tradeoff, and you own what happens next

The people who do well here get their plans stronger by exposing them to the people who run the systems, and they carry the room without needing the org chart to settle it.

What you'll own

Identity and access governance

  • Own the access model at Suno: the RBAC and entitlement design, least-privilege defaults, and the governance layer in Lumos that enforces them

  • Set the standard for what access review, certification, and approval should look like here - then build toward it rather than importing someone else's framework

  • Drive access lifecycle automation so joiner/mover/leaver is correct by default and exceptions are visible

  • Get ahead of non-human identity: service accounts, agents, and automations are a growing share of what holds access at Suno, and we need a model for them before it's urgent

Endpoint security and vulnerability management

  • Own the security standard for our fleet: hardening baseline, compliance signals, device trust, and how endpoint posture feeds access decisions

  • Own third-party vulnerability management as a program - coverage, risk-based remediation SLAs, reporting, and the negotiation with teams whose tools are the problem

  • Partner with the IT engineer who owns Kandji so the standard becomes deployed policy without degrading how people work

Detection and response

  • Own CrowdStrike Falcon Complete and our outsourced SOC relationship: coverage, tuning, escalation quality, and vendor performance against what we actually need

  • Define what good detection looks like at Suno and hold the provider to it, rather than accepting their default view of our environment

  • Lead corporate security incidents to closure, including the executive communication, and make sure what we learn changes the system rather than just the ticket

Third-party and integration risk

  • Own how Suno evaluates third-party access: integration and OAuth review for Slack, Google Workspace and the rest of the portfolio, plus vendor security assessment at purchase and renewal

  • Define our risk appetite in practice, in partnership with the CISO, and make it legible enough that others apply it without you

  • Turn recurring decisions into policy, scope guidance, and tooling so the review queue shrinks as the company grows

SaaS security posture

  • Build and own the program: the bar for our SaaS applications, the assessment cadence, and the remediation that follows

  • Improve tenant-level configuration across the portfolio - SSO and SCIM coverage, MFA and session policy, admin role hygiene, OAuth grant and token management, data sharing defaults

Cross-functional leadership

  • Work with IT, Security, Engineering, AI Enablement, and Legal to shape how Suno builds and buys, early enough to matter

  • Influence the scope of what comes next: how our future GRC function plugs in, what we automate versus staff, where the next investment goes

  • Mentor and raise the technical bar for people around you, including IT engineers who aren't security specialists

What success looks like

  • First 90 days: you've formed your own view of our security posture, built working relationships with the IT engineers and the SOC, and told us the three things we're wrong about

  • First 6 months: a corporate security roadmap exists that IT and the CISO are aligned behind, with the sequencing and the tradeoffs made explicit; the highest-risk items are already moving

  • First year: entitlement sprawl and vulnerability backlog are measurably down, detection reflects our real risks, third-party review is fast enough that nobody routes around it, and the standard holds because it's built into tooling and shared judgment rather than into you

What you'll bring

  • ~8+ years in corporate/enterprise security or security engineering, including having owned identity, endpoint, or SaaS security as a domain rather than as a set of tickets

  • Deep hands-on expertise with a modern IdP (Okta preferred) and with IGA or access-governance tooling (Lumos, Veza, ConductorOne, Opal, or similar)

  • You've designed an entitlement or RBAC model across a large SaaS portfolio and lived with the consequences long enough to know what breaks

  • Endpoint security depth in a macOS-primary fleet: MDM-delivered hardening, compliance and device trust, third-party patch and vulnerability management at scale

  • Real EDR depth - CrowdStrike preferred - and experience holding a managed detection provider or outsourced SOC to a standard you defined rather than accepting theirs

  • Strong command of OAuth, SAML, OIDC, and SCIM, and of the risk model behind third-party integrations

  • A track record of setting a security standard that other people applied without you enforcing it - written policy, tooling, defaults, or all three

  • Experience influencing engineering and business teams who don't report to you, early enough in their process to change the outcome

  • Automation fluency: Python or TypeScript, REST APIs, and a habit of building integrations and internal tooling as a normal part of the job

  • Excellent writing and judgment under ambiguity. You can hold a position with an executive and change it when the evidence says to

  • A calibrated sense of risk. You know which risks to block on, which to document, and how to tell the difference in public

Helpful, not required: detection engineering, insider risk or DLP programs, zero-trust network access, SOC 2 or ISO program ownership, just-in-time access patterns or identity-as-code, securing AI agent and non-human identity access, prior experience as the first or second security hire at a fast-growing company.

Suno is proud to be an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, genetic information, veteran status, or any other legally protected basis under provincial, federal, state, and local laws, regulations, or ordinances. We will also consider qualified applicants with criminal histories in a manner consistent with the requirements of state and local laws, including the Massachusetts Fair Chance in Employment Act, NYC Fair Chance Act, LA City Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
952,274 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Boston
$225k per year • Hybrid • Full-Time • 12+ years exp • Bachelor's Degree • New York
DevOps
Incident Management
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
GDPR
SIEM
Apply
$112k – $179k per year • In office • TS/SCI • 15+ years exp • Bachelor's Degree • United States
Management
Microsoft Office
Apply
$115k – $150k per year • Remote (United States) • 8+ years exp
Cybersecurity
ISO 27001
MITRE ATT&CK
NIST CSF
Apply
$125k – $190k per year • Equity • In office • 8+ years exp • Chantilly
Apply
≈ $113k – $240k per year (Estimated) • In office • Bachelor's Degree • Miami
DevOps
CI/CD
IAM
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Defense in Depth
Least Privilege
SIEM
Apply
≈ $23k – $64k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bengaluru
Python
SAS
SPSS
AI/ML
Machine Learning
Analytics
ETL/ELT
Informatica
Talend
Apply
≈ $29k – $59k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Bengaluru
Python
SQL
Python
pySpark
Databases
Snowflake
Databricks
Apache Kafka
AI/ML
Spark
Feature Store
DevOps
GitHub Actions
AWS
Amazon EC2
Amazon S3
IAM
Analytics
ETL/ELT
Apply
$21k – $27k per year • In office • Moscow
Python
SQL
Databases
PostgreSQL
DevOps
Linux
Apply
≈ $62k – $137k per year (Estimated) • In office • Full-Time • 8+ years exp • Singapore
Python
SQL
SAS
Management
Microsoft Office
Apply
$23k per year (net) • Remote (EAEU) • Nizhny Novgorod
1C
DevOps
Rest API
Apply
$230k – $330k per year • Equity • In office • Full-Time • 6+ years exp • Boston • New York • San Francisco • Los Angeles
AI/ML
LLM
LLM Guardrails
DevOps
AWS
Platform Engineering
Apply
$277k – $364k per year • Equity • In office • Full-Time • Boston • New York • San Francisco • Los Angeles
DevOps
AWS
Platform Engineering
Apply
$230k – $300k per year • Equity • In office • Full-Time • 8+ years exp • Boston • New York
Apply
$140k – $180k per year • Remote (United States) • Contractor • Los Angeles • New York
Design
Adobe Photoshop
Figma
Adobe After Effects
Apply
$124k – $166k per year • In office • Contractor • 3+ years exp • New York
Apply
$50k – $70k per year • Remote (United States) • Boston
Python
SQL
AI/ML
Copilot
Claude
ChatGPT
Analytics
Power BI
Apply
$180k – $240k per year • Remote (United States, APAC time zones hours) • Contractor • 8+ years exp • Boston
Databases
Snowflake
Management
Smartsheet
Jira
Apply
Quality Controller 1 day ago
$34k per year • In office • Full-Time • Boston
Apply
Safety Supervisor 1 day ago
≈ $70k – $177k per year (Estimated) • Equity • In office • Boston
Apply
≈ $65k – $137k per year (Estimated) • Hybrid • 2+ years exp • Boston
Apply
See all jobs
This is one of many
952,274 more open roles from verified company boards, updated every day.