Senior Security Engineer
Build detection, investigation, and incident-response systems protecting LangChain’s production platform, cloud infrastructure, and agentic workloads. The role requires 5+ years of security engineering experience, strong Python or Go skills, cloud and Kubernetes detection expertise, and hands-on incident response experience.
About the job
Responsibilities
- Own the detection lifecycle by translating threat models, incidents, and attacker behavior into telemetry requirements and detections-as-code.
- Validate detection coverage, measure signal quality, tune false positives, and continuously test defenses.
- Design end-to-end security telemetry pipelines across GCP, AWS, Kubernetes, and the LangSmith/LangGraph control plane.
- Instrument services and define reliable, useful security signals.
- Build investigation and threat-hunting tools and workflows for proactive hunting, evidence collection, incident scoping, and containment.
- Turn investigation findings into detections and lasting improvements.
- Build reliable internal AI agents and automation to triage alerts, enrich findings, gather evidence, scope incidents, and accelerate security work.
- Design human-in-the-loop controls and evaluations for safe, observable, trustworthy automation.
- Triage, scope, contain, and remediate security incidents; participate in an incident on-call rotation.
- Lead postmortems that produce durable engineering changes.
- Partner with Product Security to turn threat models and vulnerability findings into production monitoring.
Requirements
- 5+ years of security engineering experience, including meaningful detection engineering, security operations, or incident response experience.
- Strong software engineering skills in Python or Go; TypeScript is a plus.
- Experience with GCP or AWS logging, Kubernetes audit and runtime telemetry, workload identity, and actionable detections.
- Ability to model attacker behavior, conduct threat hunting, test detection coverage, and distinguish meaningful signals from noise.
- Hands-on incident response experience, including on-call participation, incident leadership, and postmortems.
- Experience building reliable automation or developer-facing systems, including APIs, workflows, instrumentation, quality evaluation, and production operations.
- Pragmatic product mindset with the ability to identify users and requirements, prioritize high-leverage problems, define success, and ship iteratively.
Nice-to-haves
- Experience building or operating AI agents for security workflows such as alert triage, investigation, evidence collection, or human-in-the-loop response.
- Proficiency using AI tooling to accelerate security investigations and engineering work.
- Understanding of AI threats, adversarial testing, and security boundaries of LLM and agent workloads.
- Exposure to SOC 2 or ISO 27001 monitoring and evidence automation.
- Experience with infrastructure as code such as Terraform or Helm.
- Experience securing SaaS and self-hosted or air-gapped deployments.
Compensation and Benefits
- Annual salary range: $180,000-$240,000 USD.
- Compensation includes base salary, variable compensation for relevant roles, meaningful equity, benefits, and perks.
- Benefits include medical, dental, and vision coverage, flexible vacation, a 401(k) plan, and meals on in-office days in the US.
Skills
Python, Go, TypeScript, GCP, AWS, Kubernetes, Kubernetes Audit Telemetry, Threat Hunting, Incident Response, AI Agents, Terraform, Helm, SOC 2, ISO 27001
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.
Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.
Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.
The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.