Security Engineer
You will own the defensive and offensive security posture by operating the SIEM, building security dashboards, conducting penetration tests, managing vulnerabilities and dependencies, improving secure development practices, integrating security tools into CI, and partnering with compliance on audit evidence and controls.
Responsibilities
- Operate the SIEM
- Build a real-time SecOps dashboard
- Run continuous internal penetration tests
- Automate reconnaissance, fuzzing, code review, and exploit development
- Document findings and drive remediation
- Manage the vulnerability lifecycle
- Triage CVEs across package ecosystems
- Automate dependency upgrades
- Define secure-by-default patterns
- Review threat models
- Integrate SAST, DAST, and secret scanning into CI
- Produce compliance evidence and monitoring artifacts
Requirements
- 4+ years of experience in security engineering, product security, or DevSecOps
- Hands-on web application, API, cloud, and infrastructure penetration testing experience
- Production experience operating a SIEM and building security dashboards
- Fluency in TypeScript and Node.js
- Comfort with Rust, Go, or Python
- Experience with CVE triage, software composition analysis, and dependency upgrade automation
- Comfort with AI-native security tooling
Benefits
- Equity grant
- Health and wellness benefits
- 401(k) savings plan
- Flexible time off