As a key player in a tight-knit team of specialists, your contributions will directly impact our cloud landscape and security posture. Your core responsibilities will include:
-
Developer-Driven SecOps: Leverage your programming background to transition manual security and infrastructure processes into automated, self-service APIs and internal tooling, speaking the same language as our product engineers.
-
Platform Operations: Design, implement, and operate cloud infrastructure (primarily AWS) as a secure, reliable platform, enabling self-service for engineering teams to deploy and run applications.
-
Infrastructure Hardening: Apply defense-in-depth and zero-trust principles, implementing layered security controls across network, compute, identity, and data tiers.
-
Security Standards & Governance: Develop, document, and enforce security standards, guidelines, and hardening baselines for software development (SDLC) and platform operations, driving adoption across the organization.
-
Incident Response: Detect, triage, manage, and respond to cyber security incidents, owning the process from initial signal through resolution and post-mortem.
-
Hands-on Security Engineering: Actively address vulnerabilities, implement security features (WAF rules, SIEM monitors, access policies), and improve overall platform resilience.
-
Continuous Threat Review: Conduct ongoing reviews of security tooling (such as our CNAPP Wiz), processes, and controls in response to new threats, architecture changes, and internal risk assessments.
-
Harness Engineering: Extend and improve our tooling that supports the Agent-Harnesses to safeguard AI-assisted development workflows across the SDLC.
-
Stakeholder Collaboration: Coordinate, communicate, and align seamlessly with key stakeholders including the CTO, CISO, Engineering Managers, Tech Leads, and cross-functional product teams.
-
Building custom internal integrations and automation scripts using Go and TypeScript to streamline platform operations.
-
Laying the secure cloud boundaries, API gateways, and guardrails required for engineering teams to safely experiment with and integrate AI models.
-
Cloud infrastructure setup, migration, and hardening (AWS networking, IAM, ECS, storage).
-
Zero-trust architecture and identity/access management (IAM) across platform and SaaS tooling.
-
SIEM and detection coverage (rulebook design, alert tuning, gap analysis).
-
Secrets management, certificate lifecycle automation, and WAF/DDoS perimeter security.
-
Developer security enablement via secure defaults, pipeline integrations, harness improvements and guardrails.