Назад
Company hidden
3 часа назад

Senior Corporate Security Engineer (Robotics)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Corporate Security Engineer (Robotics): Running and owning a corporate security program covering SOC 2 compliance, security operations, incident response, vulnerability management, technical risk, and security awareness with an accent on hands-on execution and cross-functional program ownership. Focus on operating CrowdStrike Falcon and SIEM detections, responding to incidents, hardening AWS IAM and logging, leading threat modeling, and maintaining audit readiness.

Location: On-site at the Cambridge, MA office; not available for remote work. Occasional travel to other hirify.global sites, including San Francisco, is required, with less than 10% expected travel.

Company

hirify.global develops general-purpose robots intended to improve quality of life across homes, workplaces, factories, farms, and other environments.

What you will do

  • Own day-to-day corporate security operations, including CrowdStrike Falcon, SIEM detections, EDR policies, alert triage, runbooks, and managed security services.
  • Lead security incident investigations, containment, technical coordination, post-incident reporting, and tabletop exercises.
  • Run vulnerability management across endpoints, SaaS applications, and identity systems, coordinating remediation and risk-based prioritization.
  • Perform vendor, SaaS, internal infrastructure, cloud, identity, endpoint, and network security assessments.
  • Implement and maintain AWS IAM, logging, and hardening baselines, and lead threat modeling for corporate and product systems.
  • Own SOC 2 execution, security policies, audit evidence, risk management, security awareness, phishing simulations, and consultant coordination.

Requirements

  • 5+ years of information security experience with increasing responsibility, hands-on operations, and program ownership.
  • Experience preparing for or maintaining SOC 2 programs, including control design, evidence collection, remediation, and auditor coordination.
  • Hands-on experience with an EDR platform and SIEM or modern detection platform, including policy tuning, detection rules, and end-to-end alert triage.
  • Experience leading incident response, vulnerability management, and security assessments.
  • Working knowledge of identity systems, AWS or another major cloud, corporate networking, and light scripting with Python, PowerShell, or Bash.
  • Ability to work on-site in Cambridge, Massachusetts, perform occasional physical infrastructure work, lift up to 40 lbs, work on ladders, and operate in network closets, IDFs, and lab spaces.

Nice to have

  • Experience as an early security hire at a growth-stage company or supporting robotics, embedded, ML, or similarly technical engineering teams.
  • Experience with CrowdStrike Falcon, Cisco Meraki, Fortigate, Google Workspace security, MDM, virtualization, infrastructure as code, or zero-trust access tools.
  • Experience leading threat modeling programs and evaluating the secure adoption of AI tools.
  • Relevant certifications such as CISSP, CISM, GIAC, AWS Security Specialty, or OSCP.

Culture & Benefits

  • Standard business hours with best-effort after-hours incident response; a formal on-call rotation is planned as the company grows.
  • Competitive total compensation including salary, annual cash bonus, company equity, and company-subsidized insurance.
  • 401(k) with company match, flexible PTO, daily lunch, and other benefits.
  • Collaborative environment focused on humility, technical excellence, and practical security decisions aligned with company goals.
  • Employment is subject to a standard pre-employment background check; hirify.global participates in E-Verify.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →