Stand out for this role — generate a tailored resume and cover letter in about a minute.
AegisAI, Inc. is seeking a Security Engineer to accelerate our security program. You will build the systems for scanning, vulnerability management, posture and identity controls across our cloud estate, and the guardrails in our pipelines that stop problems before they ship.
This is a building role; you will work directly with engineering and DevOps teams and with the head of security, owning real surface from week one as the scope grows with your impact.
We're a team of ex-Google engineers who built some of the largest defensive platforms on the planet — Safe Browsing and reCAPTCHA. Now, we're striking out on our own to tackle an even bigger challenge: stopping the new wave of adversarial AI attacks already hitting organizations today.
We're going after a $5B+ market, ripe for disruption. Traditional detection methods are too slow to keep up. Adversaries are using AI to craft customized, high-evasion attacks — and old-school rules-based systems don't stand a chance.
We're looking for a Security Engineer to accelerate AegisAI's security program. Our customers trust us with their most sensitive data, and you'll build the systems that keep it protected: the scanning and vulnerability management that covers all of engineering, the posture and identity controls across our cloud estate, and the guardrails in our pipelines that stop problems before they ship.
This is a building role, not a gatekeeping one. The best security engineering here looks like paved roads: predefined pipelines, logging and auth paths that make the secure way the fast way, so product teams move quicker because security already did the thinking. You'll work directly with our engineering and DevOps teams and with the head of security, and your fingerprints will be on how a security company secures itself.
You'll own real surface from week one, and the scope grows as fast as you can take it.
Vulnerability management at the source: Own scanning across code, dependencies, images, cloud config and our external surface; automate the triage, the routing to owners, and the remediation itself wherever it's safe; keep what's left inside our SLAs.
CI/CD security: Own and expand the security gates in our build and deploy pipelines, so vulnerable dependencies and misconfigurations are blocked before they ship.
Cloud security posture: Define secure baselines for our cloud estate, detect drift from them, and automate remediation.
Cloud identity and access: Drive least privilege and zero trust by default, across every system, credential and workload we operate.
Application security: Run design and code reviews and threat modeling for new features and products.
Paved roads: Partner with DevOps on reusable, secure-by-default paths for CI/CD, logging and auth, so every new service starts at our baseline and teams ship faster.
Incident response: Be a technical lead when something needs investigating, and build the tooling that makes the next investigation faster.
Automate: If you do it twice by hand, you build it the third time.
Bonus points: