Security Engineer
Builds application security features, assesses and remediates vulnerabilities, and embeds secure development practices across the SDLC. The role requires production software experience, proficiency in TypeScript or Python, AWS and cloud-security familiarity, and strong communication skills.
About the job
Responsibilities
- Design and implement security features within the Granola app to protect user data and strengthen the product's security posture.
- Use AI-assisted tooling for security assessments, code reviews, threat modeling, and penetration testing to identify application vulnerabilities.
- Partner with development teams to integrate secure coding practices throughout the software development lifecycle.
- Track, analyze, and manage application vulnerabilities, using AI-assisted triage and prioritization to guide remediation.
- Support incident response by investigating application-related security incidents.
- Stay current on security threats, vulnerabilities, and technologies.
Requirements
- Extensive experience building production software, including hands-on work with security-sensitive areas such as authentication, data handling, API design, or encryption.
- Genuine interest in application security and willingness to deepen security expertise.
- Familiarity with secure coding practices and at least one of threat modeling, risk assessments, or incident response.
- Proficiency in TypeScript, Python, or a similar programming language.
- Experience with cloud platforms and cloud security, particularly AWS.
- Strong communication skills, including the ability to explain complex security issues to technical and non-technical audiences.
- Willingness to work in person from the London office most of the time.
- Interest in working in a fast-paced startup environment.
Compensation and Benefits
- Salary paid slightly above market, with above-market equity.
- Relocation assistance for candidates moving to London.
- In-person work five days per week at the Old Street office.
Skills
Application Security, TypeScript, Python, AWS, Cloud Security, Secure Coding, Threat Modeling, Risk Assessments, Incident Response, Penetration Testing, Code Review, Encryption
Similar jobs
Security Engineering jobsBuild and scale application security for an enterprise AI platform through threat modeling, secure architecture, automated controls, code review, penetration testing, and AI/ML threat research. Requires 4+ years of application security experience and proficiency in at least two programming languages.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads technical response to security events across cloud infrastructure, services, and applications, covering triage, containment, remediation, automation, and post-incident improvements. Requires 3+ years of cloud security incident response experience and expertise with SIEM, SOAR, and major cloud platforms.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.