Mimica is a fast-growing scale-up focused on empowering enterprises through AI-powered task mining. They are seeking a Staff/Lead Security Engineer to build and operate core security capabilities, enhance their cloud-native SaaS platform, and improve their overall security posture.
Responsibilities:
- Lead the build-out and operation of core security capabilities: vulnerability management, patching, SIEM/logging, cloud security monitoring, and alert triage
- Deploy, configure, and tune security tooling (scanners, WAFs, CSPM, SIEM, endpoint protection)
- Partner with engineering to build security at App or Cloud level, with developer experience in mind
- Triage and assess vulnerabilities, drive remediation prioritisation, and reduce risk in a pragmatic yet rigorous way
- Design and implement tactical incident-response playbooks and improve detection coverage
- Periodically review major architectural changes and guide engineering on secure design trade-offs
- Continuously improve processes so security scales as the company grows
Requirements:
- Senior+/Lead/Staff experience (typically 7+ years) in security engineering or SecOps, with a strong preference for hands-on roles in startup or scale-up environments
- Strong expertise in AppSec or CloudSec
- Proven ability to independently deploy and manage cloud security solutions, especially in GCP (big plus), AWS, or Azure
- Experience preparing for SOC2, ISO 27001, or FedRAMP
- Deep expertise in one or ideally several of the following: vulnerability management programs, cloud-native SIEM/logging, CSPM/CNAPP tools, IaC security, secure SDLC integration, and incident response
- Strong communication skills - you can explain complex risks or trade-offs clearly to both technical and non-technical audiences
- OSCP, CISSP, or similar offensive/security certifications
- Leading a security function
- Experience in a successful startup/scale-up