Security Engineer
Upload My Resume
Drop here or click to browse · PDF, DOCX, DOC, RTF, TXT
Requirements
• Broad Security Expertise. Strong foundation in web application security, cloud security (AWS, Azure, or GCP), and networking principles. • Coding and DevOps Skills. Hands-on experience with programming production software, scripting, and DevOps tools for automation. Familiarity with secure coding practices, threat modeling, vulnerability scanning, and incident response processes. • Adaptability and Resilience. Comfort working in a fast-paced startup environment, ability to adapt to changing priorities and handle ambiguity with grace. • Communication and Collaboration. Strong written and verbal communication skills with the ability to clearly explain risk trade-offs and convey complex technical topics to both technical and non-technical audiences. • Curiosity & Customer-First Mindset. Passion for deeply understanding customer needs and finding the right solutions from first principles. • Experience securing AI systems, with understanding of LLM and Agentic AI risks. • Prior success in securing cloud infrastructure with robust policies and automated enforcement, and familiarity with Infrastructure as Code (Terraform, CloudFormation). • History of building or integrating custom security tools, especially those leveraging AI/ML for detection or monitoring. • Familiarity with continuous compliance platforms and building control monitoring. • Experience designing strong foundations with secure-by-design and privacy-by-design practices such as data handling, anonymization, and de-identification • Trust: We build trust with our customers with our accountability, empathy, quality, and responsiveness. We build trust in AI by making it more accessible, safe, and useful. We build trust with each other by showing up for each other professionally and personally, creating an environment that enables all of us to do our best work. • Customer Obsession: We deeply understand our customers’ business goals and relentlessly focus on driving outcomes, not just technical milestones. Everyone at the company knows and spends time with our customers. When our customer is having an issue, we drop everything and fix it. • Craftsmanship: We get the details right, from the words on the page to the system architecture. We have good taste. When we notice something isn’t right, we take the time to fix it. We are proud of the products we produce. We continuously self-reflect to continuously self-improve. • Intensity: We know we don’t have the luxury of patience. We play to win. We care about our product being the best, and when it isn’t, we fix it. When we fail, we talk about it openly and without blame so we succeed the next time. • Family: We know that balance and intensity are compatible, and we model it in our actions and processes. We are the best technology company for parents. We support and respect each other and celebrate each other’s personal and professional achievements.
Responsibilities
• Lead Security for Our Platform by taking charge of application, cloud, network, and AI agent security. This includes performing secure design reviews, overseeing threat modeling, and building new security primitives into our product and platform. • Collaborate with Cross-Functional Teams to embed security throughout the software development lifecycle, communicate risks, prioritize fixes, and ensure that security requirements enable innovation. • Implement Automation & Tooling by integrating tooling into CI/CD pipelines and leveraging AI-based or next-gen solutions for automated scans, compliance checks, and infrastructure reviews to streamline processes. • Continuously improve Security Posture through regular audits of our cloud environment, review IAM configurations, stay on top of emerging AI security risks, recommend strategic initiatives, lead efforts in establishing best practices as the company scales up. • Enable Enterprise Customer Needs by presenting and explaining our security posture to enterprise clients, addressing concerns around healthcare or financial data with clear actionable insights.
Benefits
• We want our benefits to reflect our values and offer the following to full-time employees: • Flexible (Unlimited) Paid Time Off • Medical, Dental, and Vision benefits for you and your family • Retirement Plan (e.g., 401K, pension) with Sierra match • Fertility and family building benefits through Carrot • Lunch, as well as delicious snacks and coffee to keep you energized • Discretionary Benefit Stipend giving people the ability to spend where it matters most • Free alphorn lessons • These benefits are further detailed in Sierra's policies and are subject to change at any time, consistent with the terms of any applicable compensation or benefits plans. Eligible full-time employees can participate in Sierra's equity plans subject to the terms of the applicable plans and policies. • Be you, with us • Be you, with us