2 часа назад
Security Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Engineer (AI): Building cloud security foundations, SIEM detections, incident response capabilities, and SOC 2 Type II evidence processes with an accent on AWS/GCP security, MITRE ATT&CK coverage, and detection engineering. Focus on deploying CSPM and IaC controls, authoring mapped detection rules, leading P1/P2 response, and reducing MTTD to 60 minutes or less.
Location: Hybrid in San Francisco, CA or Seattle, WA
Company
is a San Francisco-based AI hardware and software company building intelligence interfaces for professionals, with more than 2,000,000 users worldwide.
What you will do
- Own the detection and response layer together with the cloud infrastructure security foundation.
- Remediate credential exposure across AWS and GCP production environments, deploy CSPM, add Checkov and Terraform security gates to CI/CD, and implement Zero Standing Privileges through JIT and CIEM.
- Deploy a SIEM platform and create more than 30 MITRE ATT&CK-mapped detection rules across cloud, endpoint, and SaaS telemetry.
- Own the incident response lifecycle, develop playbooks for at least four incident categories, and lead cross-functional response for P1/P2 events.
- Maintain SOC 2 Type II operational evidence, including log retention, alert records, control reviews, and control narratives.
- Publish security and risk governance reports and maintain at least 90% vulnerability SLA compliance.
Requirements
- 5–8 years of hands-on security engineering experience, with depth in cloud security or security operations and working fluency in the other area.
- Experience building security infrastructure from zero, including tool selection, baseline configuration, and policy definition.
- Strong knowledge of MITRE ATT&CK, CIS Benchmarks L1/L2, AWS/GCP security tooling, CSPM, and cloud and endpoint log-source integration.
- Familiarity with SOC 2 Type II requirements, especially CC6 logical access, CC7 monitoring and detection, and third-party audit evidence standards.
- Regular use of LLMs for alert summarization, detection rule generation, SOAR playbook drafting, or IaC policy automation.
Culture & Benefits
- Employee Stock Ownership Plan providing a stake in the company's long-term success.
- Access to AI tools including Cursor, GPT models, Gemini, and Claude.
- Choice of high-spec laptops, workstation setups, and devices.
- Annual company offsites, team events, and a culture focused on craftsmanship, ownership, and velocity.
- Fast-moving, product-driven environment with opportunities to work on AI productivity products and global expansion.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →