Software Engineer - Security
Builds security tools, automations, and AI agents to enhance detection, response, vulnerability management, and overall security posture. Requires 4+ years experience in software engineering with security focus, proficiency in Python/Go/TypeScript, and familiarity with SIEM/EDR/cloud systems.
About the job
Responsibilities
- Design, build, and maintain software and automation that improves our detection and response program, including alert enrichment, triage workflows, and investigation tooling.
- Implement and enhance internal AI agents and security bots that assist with monitoring, investigations, reporting, and other security operation tasks.
- Develop and operate systems and workflows that support the bug bounty and vulnerability disclosure program, including intake, triage, prioritization, and remediation tracking.
- Partner with product and engineering teams to threat model new features and systems, propose mitigations, and add guardrails into designs and implementations.
- Contribute to secure-by-default libraries, services, and patterns that make it easy for teams to build secure features.
- Integrate security signals from cloud, endpoints, SaaS, and applications into cohesive pipelines and data models that support detection and analysis.
- Build automation to reduce manual work in incident response, containment, and remediation.
- Collaborate with security engineers and other software engineers to review designs and code, and to continuously improve our security tooling and platforms.
Qualifications
- 4+ years of experience as a software engineer with significant time spent building security-related tools, platforms, or automations, or in a security engineering role with strong software development responsibilities.
- Proficiency in at least one major programming language (Python, Go, or TypeScript) and experience building production services, CLIs, or internal tools.
- Experience integrating with security-relevant systems such as logging pipelines, SIEMs, EDR, cloud APIs, or identity platforms.
- Practical experience with threat modeling, secure design, or application security reviews for services or features.
- Experience operating or contributing to bug bounty or vulnerability management programs is a plus.
- Familiarity with cloud infrastructure (AWS preferred) and modern SaaS environments.
- Ability to work closely with cross-functional teams, own projects end-to-end, and ship pragmatic, high-impact improvements.
- Bonus: Experience designing or improving AI-powered agents or automation used for security operations.
Skills
Python, Go, TypeScript, SIEM, Edr, AWS, Threat Modeling, AI Agents, Vulnerability Management, Bug Bounty
Similar jobs
Security Engineering jobsThis role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.