About the role
We're looking for a Security Engineer who is equal parts breaker and maker — someone who can think like an attacker, find the weak points in our systems before anyone else does, and then build the tooling and guardrails that make those weaknesses impossible to hit again.This is a hands-on, code-first role. You won't be writing policy documents from the sidelines. You'll be reading our services, breaking them in a lab, scripting the exploit, and then shipping the fix or the automation that closes the gap permanently. You'll work across our Kubernetes platform, CI/CD pipelines, on-premises and air-gapped deployments, and our AI/LLM-powered product surface.If you get restless when security work stops at "filing a ticket" and you'd rather automate the problem out of existence, you'll fit right in.What you'll doAs a breaker
- Run internal penetration tests against our services, APIs, gateway layer, cloud infrastructure (AWS/Azure, EKS/AKS), and on-prem deployments.
- Threat-model new features and architectures, then prove out the threats with working proof-of-concept exploits rather than theoretical findings.
- Attack our AI/LLM surface: prompt injection, data exfiltration through agents, insecure tool use, model/endpoint abuse, and supply-chain risks in the AI stack.
- Continuously assess our public footprint — monitor for leaked secrets, credentials, and proprietary code across org and developer public repositories.
As a maker
- Write code and automation (Python, Go, or similar) to turn one-off security findings into repeatable, self-service tooling and CI/CD gates.
- Build and maintain secret scanning, SAST/DAST, dependency and container scanning, and IaC scanning into the pipeline so issues are caught pre-merge, not post-incident.
- Harden our Kubernetes platform, secrets management, and release process; contribute security controls directly into infrastructure-as-code.
- Develop internal security tooling and libraries that make the secure path the default path for engineers.
- Use AI to accelerate your own work — triage, detection engineering, exploit prototyping, log analysis, and reducing security review toil.
Across both
- Partner with platform, DevOps, and product engineering on secure-by-design architecture and remediation.
- Support compliance and audit efforts (SOC 2, HIPAA) with real technical controls and evidence, not just checkboxes.
- Drive incident response for security events, and build the automation to detect and contain them faster next time.
What we're looking forMust have
- Strong software engineering fundamentals — you can build, not just script. Comfortable in at least one of Python, Go, or a similar language, and can read code in several others.
- Demonstrated offensive security experience: penetration testing, red teaming, bug bounty, CTFs, or equivalent hands-on breaking.
- Solid grasp of web/API security (OWASP Top 10, auth flows, common misconfigurations) and cloud security (AWS and/or Azure).