Our Security & Compliance Engineering team builds and maintains the security foundations that keep our products, infrastructure, AI systems, and operational workflows running safely. We work across application security, cloud security, IAM, vulnerability management, monitoring, incident response, and compliance engineering hands-on with engineering teams, not just running audits from the sidelines.Because we build AI-powered products that process sensitive enterprise and healthcare data, security is a core engineering requirement, not an after-the-fact check. A gap here can mean a data exposure, an outage, or lost customer trust so we expect sharp attention to detail, disciplined execution, and a genuinely proactive approach to risk.
About the Role
You'll work directly with engineering, infrastructure, product, and operations to strengthen our security and compliance posture sitting at the intersection of application security, cloud security, IAM, vulnerability management, security automation, and modern AI infrastructure. You'll help find vulnerabilities, implement controls, automate checks, monitor systems, investigate events, and support compliance with the goal of preventing recurrence, not just flagging problems.Additionally, you will be expected to continuously explore and evaluate modern AI-assisted security workflows, automated testing tools, and emerging security practices, using them directly to widen security coverage and improve engineering efficiency.
What You'll Do
- Secure Applications & APIs: Identify and help remediate application and API vulnerabilities across our products, services, and internal systems.
- Conduct Security Assessments: Perform vulnerability assessments, security reviews, configuration checks, and basic penetration testing across applications, infrastructure, APIs, and cloud environments.
- Strengthen Cloud Security: Help secure cloud infrastructure through appropriate IAM policies, network controls, secrets management, encryption, logging, monitoring, and secure configuration practices.
- Implement Identity & Access Controls: Assist in designing and maintaining role-based access control, least-privilege access, authentication mechanisms, service accounts, and access review processes.
- Automate Security Controls: Build scripts, tools, and automated checks that continuously identify misconfigurations, vulnerabilities, excessive permissions, exposed secrets, and policy violations.
- Secure AI Systems: Assess security risks associated with LLM applications, AI agents, RAG systems, APIs, tools, prompts, data access, and autonomous workflows.
- Monitor & Investigate Security Events: Work with security logs, alerts, monitoring systems, and incident data to identify suspicious activity and support investigations.
- Support Vulnerability Management: Track vulnerabilities from discovery through remediation, validate fixes, prioritize risk, and help engineering teams resolve issues.
- Build Security Into Development: Collaborate with developers to introduce security checks into CI/CD pipelines, code reviews, dependency management, and infrastructure deployment.
- Support Compliance & Audit Readiness: Help maintain security documentation, evidence, policies, control mappings, risk registers, and audit readiness for applicable frameworks.
- Leverage Cutting-Edge Security & AI Tools: Systematically identify, evaluate, and integrate modern security tooling, AI-assisted workflows, and automated assessment tools to improve coverage and efficiency.
- Develop Security Documentation: Create and maintain security procedures, architecture documentation, incident playbooks, access control docs, risk assessments, and technical guidelines.
- Take Full End-to-End Ownership: Own assigned security initiatives from risk identification through remediation, validation, documentation, and continuous monitoring.
What We're Looking For
Technical
- Security Fundamentals: Strong understanding of authentication, authorization, encryption, hashing, network security, application security, access control, and secure development.
- Application & API Security: Understanding of common web/API vulnerabilities OWASP Top 10, injection, broken access control, auth issues, insecure configs, SSRF, XSS, CSRF, sensitive data exposure.
- Cloud & Infrastructure Security: Basic understanding of cloud infrastructure, IAM, networking, firewalls/security groups, secrets management, encryption, logging, monitoring, containers, and secure deployment.
- Identity & Access Management: Understanding of authentication, authorization, RBAC, least privilege, service accounts, API keys, OAuth, tokens, and access management.
- Security Testing & Vulnerability Management: Familiarity with vulnerability scanners, dependency scanning, static/dynamic analysis, and remediation workflows.
- Security Automation: Ability to write scripts and automation that improve security visibility, perform checks, collect evidence, or enforce controls.
- Linux & Networking Fundamentals: Strong working knowledge of Linux and core networking TCP/IP, DNS, HTTP/HTTPS, TLS, ports, proxies, segmentation.
- Security Tooling & Efficiency: Strong interest in modern security tooling, AI-assisted security analysis, and automated testing you actively seek better ways to find and fix issues.
- Compliance Awareness: Basic understanding of frameworks such as SOC 2, ISO 27001, GDPR, or HIPAA is desirable.
Good to Have
- Experience with Burp Suite, OWASP ZAP, Nmap, Wireshark, Metasploit, or similar security testing tools.
- Hands-on exposure to AWS, Azure, or GCP security services and cloud security best practices.
- DevSecOps experience integrating SAST, DAST, SCA, secret scanning, or container scanning into CI/CD.
- Experience with Docker, Kubernetes, Terraform, or infrastructure-as-code security.
- Familiarity with SIEM platforms, centralized logging, threat detection, or security monitoring workflows.
- Exposure to incident investigation, log analysis, triage, containment, or root-cause analysis.
- Experience exploring LLM security prompt injection, data leakage, insecure tool use, excessive agent permissions, AI red teaming, or agentic AI security.
- Familiarity with SOC 2, ISO 27001, HIPAA, GDPR, risk assessments, or GRC platforms.
- Security certifications (Security+, CEH, CCNA Security, cloud security certs) or equivalent practical experience.
- Participation in CTFs, bug bounty programs, security communities, or independent security research.
Mindset
- Extreme Ownership: You take responsibility for identifying, understanding, and helping resolve risks not just reporting them.
- Security by Design: You think about security from the start of a project, not as a final checklist before deployment.
<