MiddleRemoteRemote
Security Engineer
О роли
Описание вакансии
About the company
- PostHog equips every developer to build successful products.
- Started with open-source product analytics, launched out of Y Combinator's W20 cohort.
- Shipped more than a dozen products, including a built-in data warehouse, a customer data platform, and Max AI.
- Open source, product led, and a default alive company that is well funded.
Responsibilities
- Triage and Tune: own Wiz alerts, turn noise into actionable findings.
- Incident detection, response: lead the charge on security incidents, coordinate response and lead post-mortems, build IR runbooks.
- Build Observability: build detection pipelines, close network-based observability gaps.
- Threat Hunting: proactively hunt for threats in AWS environment, define what "good" looks like and build telemetry.
- The VDP: support Vulnerability Disclosure Program, triaging reports from researchers and transitioning toward a formal bug bounty program.
- Enable the Team: support product squads with threat modeling and secure design reviews.
- Help build security culture.
Requirements
- Cloud Native: 3-5+ years of experience in security engineering with a heavy focus on AWS.
- Know your way around IAM, VPC logs, and CloudTrail.
- Expert security generalist: building secure libraries, writing semgrep rules, hardening cloud deployments, improving network observability, and leading incident response.
- Experience with detection pipelines and observability.
- Ability to work autonomously and move fast.
Conditions
- Remote (EMEA).
- Natively remote company, default to async communication.
- Tuesdays and Thursdays are meeting-free days.
- Prioritize heads down building time.
Стек и навыки
С чем работаем