Lead the build-out and operation of core security capabilities: vulnerability management, patching, SIEM/logging, cloud security monitoring, and alert triage.
Partner with engineering to build security at App or Cloud level, with developer experience in mind.
Triage and assess vulnerabilities, drive remediation prioritisation, and reduce risk in a pragmatic yet rigorous way.
Design and implement tactical incident-response playbooks and improve detection coverage.
Periodically review major architectural changes and guide engineering on secure design trade-offs.
Continuously improve processes so security scales as the company grows.
Requirements
Lead/Staff experience (typically 7+ years) in security engineering, AppSec or SecOps, with a strong preference for experience in startup or scale-up environments.
Strong expertise in AppSec or CloudSec
Proven ability to independently deploy and manage cloud security solutions, especially in GCP (big plus), AWS, or Azure.
Experience preparing for SOC2, ISO 27001, or FedRAMP
Deep expertise in one or ideally several of the following: vulnerability management programs, cloud-native SIEM/logging, CSPM/CNAPP tools, IaC security, secure SDLC integration, and incident response.
Strong communication skills
you can explain complex risks or trade-offs clearly to both technical and non-technical audiences.
Tech Stack
AWS
Azure
Cloud
Google Cloud Platform
SDLC
Benefits
Generous compensation + stock options
aligned with our internal framework, market data, and individual skills.
Distributed work: Work from anywhere
fully remote, in our hubs, or a mix.
Company-issued laptop, remote setup stipend, and co-working budget
Flexible schedules and location
Ample paid time off, in addition to local public holidays
Enhanced parental leave
Health & retirement benefits
Annual learning & development budget
Annual workaways and regular virtual & in-person socials
Opportunity to contribute to groundbreaking projects that shape the future of work