Astronomer is a company that empowers data teams to bring mission-critical software, analytics, and AI to life. They are seeking a passionate Security Engineer to innovate and build security solutions that monitor and protect their multi-cloud environment and critical assets.
Responsibilities:
- Implement, maintain, and upgrade security infrastructure for the monitoring, triage, and remediation of security events
- Engage with engineering and assist in the design and implementation of cloud workload and orchestration platforms and a secure cloud infrastructure
- Drive operational efficiencies with the skillful application of AI, ML, and automation, recreating processes to be non-human centric
- Work with product and engineering teams to mitigate risks and vulnerabilities in Astronomer products and infrastructure
- Work with engineering and IT teams to ensure and assist in collecting evidence of security and compliance controls
- Respond to emergencies when needed, coordinating with other technical teams to assess, scope, mitigate, and respond to threats or risks as they emerge
Requirements:
- At least 2 years of production experience in cybersecurity, cloud engineering, network engineering or site reliability engineering
- Strong scripting language skills (Python preferred) and familiarity with compiled programming languages
- Experience with common cybersecurity tools and platforms (SIEM, EDR, SOAR)
- Foundational experience with cloud platforms (GCP preferred)
- Exposure to container technologies and orchestration platforms such as Docker, Kubernetes, or OpenShift
- Demonstrated understanding of fundamental security principles and best practices for application design and deployment
- Ability to self-learn
- Strong written and verbal communication skills
- Experience designing and building microservice-based systems
- Familiarity with MLOps concepts or experience deploying AI/ML models
- Experience in data analysis platforms such as Splunk, Snowflake, Elasticsearch, or BigQuery
- Exposure to developing and securing web applications, APIs, and cloud workloads, with an emphasis on secure-by-design principles
- Experience in security monitoring and incident response activities, such as reviewing alerts, analyzing logs, performing basic investigations, or supporting incident response workflows in a SOC or similar environment