Lead Security Engineer

CipherData

Bellevue (WA)

On-site

USD 160,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CipherData seeks a Lead Security Engineer to own the company’s security program, from product-level detections to incident response and compliance. You’ll lead a small founding team, define the ground truth for detections, and build a scalable security lakehouse that drives product security and customer trust.

The role reports to the CEO/CISO and sits in Bellevue, WA, with ownership of security posture, incident response, and SOC 2/ISO 27001 readiness.

Qualifications

  • 8+ years in security engineering or detection engineering with outcomes
  • Proven production detections: written, tuned, retired detections with FP trade-offs
  • Deep hands-on with SIEM and security data platforms, EDR/XDR, and cloud/identity telemetry
  • Strong Python and engineering codebase experience
  • Incident response leadership on real intrusions with customer/executive communication
  • Ability to articulate what separates a good investigation from a bad one precisely enough that it can be written down and measured

Responsibilities

  • Own security lakehouse roadmap and detection platform
  • Develop detection logic and correlation rules
  • Curate benchmark datasets from real investigations
  • Track attacker tradecraft and translate into agent capability
  • Deploy and validate AIDR in customer environments; integrate feedback
  • Own incident response and playbooks; manage security assessments and pen tests

Skills

Security engineering
Detection engineering
Incident response
Python
Cloud security

Tools

SIEM platforms
EDR/XDR
Cloud telemetry
CI/CD pipelines

Job description

About the Role

You will own security at CipherData — the product's detection brain and the company's own security posture — reporting directly to the CEO, who is also our CISO. We are building our founding security team now, and this is the lead seat: there is no function to inherit, you set the standard, and you hire and lead the engineers who join you.

The center of gravity is the product. AIDR's multi-agent engine investigates and correlates security data — logs, events, alerts, and context from across a customer's stack — on a SIEM-less security lakehouse, and someone has to decide what a correct investigation looks like: which alerts matter, what evidence a conclusion must carry, and how to tell when an agent is confidently wrong. You define the detection content the agents reason over, the ground truth they are measured against, and the next generation of our security lakehouse and detection capabilities. You will work directly with the AI engineering team: they build the reasoning, you build what it reasons over and the bar it is held to.

Around that core you also carry what a CISO's first engineer carries at a company our size: our own infrastructure and product security, customer-facing incident response, and the compliance work (SOC 2, ISO 27001, and customer-specific requirements) that our enterprise customers require. These are real responsibilities, not footnotes — but they are sized for a startup. You will automate and delegate them, not staff a GRC team.

If you have wanted to own a security function end to end, encode what you know about triage once instead of repeating it every shift, and do it at a company small enough that your decisions ship the same week — this is that role.

What You'll Do

Product — detection, lakehouse, and ground truth (the majority of your time)

  • Security lakehouse and detection platform: Drive the roadmap for our SIEM-less security lakehouse — schema and normalization across multi-vendor security data, retention and query strategy, and the detection and correlation layer that runs on it. Partner with product engineering on the data plane; own what "correct" means on top of it.
  • Detection and correlation engineering: Build and maintain the detection logic and correlation rules that turn multi-vendor security data into signal our agents can reason over.
  • Ground truth and evaluation: Curate and label real investigations into the benchmark datasets that tell us whether agent output is right — the standard the AI team builds against.
  • Threat research into product: Track attacker tradecraft and convert it into agent capability, detection content, and test cases.
  • Production SOC deployment: Deploy, tune, and validate AIDR in customer environments; own the loop that carries analyst feedback back into detection and evaluation.

Company — security function owner

  • Customer incident response: Own the response to security incidents reported by customers or detected internally: analysis, root cause, remediation, customer communication, and post-incident review. Maintain the playbooks.
  • Product and infrastructure security: Secure how we ingest, isolate, and handle customer security data — a privacy or tenancy failure is not something you recover from. Run assessments and pen tests on the product and our cloud footprint; integrate security into how we ship.
  • Compliance and certifications: Own the technical side of SOC 2, ISO 27001, and customer security requirements, working with our Korea team and outside counsel. Automate evidence collection; don't build a paper program.
  • Team: Build and grow the founding security team — hire, lead, and develop the security engineers who join you.
Our Core Values

Five principles guide every decision at CipherData. We hire against them and evaluate against them:

  • Trustworthiness — be trustworthy to all people. Integrity, transparency, and dependability with colleagues, partners, and customers.
  • Growth Mindset — learn from anything, anyone, anytime. Past experience is data, not dogma. Curiosity over ego; first principles over status quo.
  • Proactive Ownership — do the right thing for the customer. Customer first, then company, then team, then self. Step beyond your role and hold yourself accountable.
  • Disagree and Commit — debate when it matters, execute with unity. Challenge high-impact decisions with data and conviction, regardless of title. Once decided, commit fully.
  • Impact-Driven Execution — ship, learn, iterate. Move fast, take calculated risks, and measure yourself by outcomes, not activity.
Minimum Qualifications
  • 8+ years in security engineering, detection engineering, threat hunting, or incident response, including senior-level SOC or detection-engineering work where you were accountable for outcomes
  • Demonstrated detection engineering in production: you have written, tuned, and retired detections and can explain the false-positive trade-offs you made
  • Deep hands-on experience with SIEM and security data platforms, EDR/XDR, and cloud and identity telemetry — including data modeling and normalization, not just query authoring
  • Strong Python and comfort in an engineering codebase: code review, tests, CI
  • Incident response leadership on real intrusions, including customer- or executive-facing communication
  • Ability to articulate what separates a good investigation from a bad one precisely enough that it can be written down and measured
  • Evidence of 0-to-1 ownership: you have built a function, program, or system from nothing, scoped your own work, and shipped without a large support structure
Preferred Qualifications
  • Experience designing or operating a security data lake or lakehouse at scale
  • Detection-as-code practice — version control, testing, and CI for detection content
  • Experience building labeled datasets, benchmarks, or evaluations for security tooling or ML systems
  • Familiarity with LLM-based systems and their failure modes (hallucination, prompt injection, fabricated evidence)
  • Multi-tenant or MSSP environments; cloud security depth across major cloud providers
  • SOC 2 / ISO 27001 experience from the engineering side
  • Purple team, adversary emulation, or offensive security background
  • Prior experience as a first or early security hire
Details
  • Position: Lead Security Engineer
  • Experience: 8+ years
  • Reports to: CEO & CISO
  • Employment type: Full-time
  • Location: Bellevue, WA

CipherData is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic.

CipherData · careers@cipherdata.ai

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

CipherData • Bellevue (WA)

On-site
USD 120,000 - 180,000
Founding Security Lead — Detection & Incident Response
Founding Security Lead — Detection & Incident Response

CipherData • Bellevue (WA)

On-site
USD 160,000 - 190,000
Senior Manager, Security Platform Engineering
Senior Manager, Security Platform Engineering

Todyl • Atlanta (GA)

On-site
USD 175,000 - 200,000
Senior Manager, Security Platform Engineering
Senior Manager, Security Platform Engineering

Todyl • Denver (CO)

On-site
USD 175,000 - 200,000
AI Engineer
AI Engineer

CipherData • Bellevue (WA)

On-site
USD 120,000 - 155,000
Security Operations Engineer
Security Operations Engineer

Reserv • Atlanta (GA)

Hybrid
USD 80,000 - 100,000
Generous health-insurance package
401(k) retirement plan with employer matching
Competitive PTO policy
+1
Cyber Security Entrepreneur in Residence
Cyber Security Entrepreneur in Residence

Human Agency • Boston (MA)

On-site
USD 150,000 - 200,000
Lead, Cybersecurity Architecture & Operations
Lead, Cybersecurity Architecture & Operations

Culligan International • Northern (KY)

Hybrid
USD 140,000 - 180,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

United States Digital Space LLC • New York (NY), Washington

On-site
USD 238,000 - 297,000
Health, dental & vision coverage
Retirement benefits
Learning & development stipend
+2
Cyber Security Entrepreneur in Residence
Cyber Security Entrepreneur in Residence

Human Agency • United States

Remote
USD 120,000 - 180,000