Summary
Aegis AI Security is developing defensive platforms to address adversarial AI attacks affecting organizations. The Security Engineer will accelerate the company’s security program by owning vulnerability management, cloud security posture and identity controls, CI/CD security gates, application security, secure engineering paths, and incident response tooling.
Responsibilities
- Vulnerability management at the source: Own scanning across code, dependencies, images, cloud config and our external surface; automate the triage, the routing to owners, and the remediation itself wherever it's safe; keep what's left inside our SLAs
- CI/CD security: Own and expand the security gates in our build and deploy pipelines, so vulnerable dependencies and misconfigurations are blocked before they ship
- Cloud security posture: Define secure baselines for our cloud estate, detect drift from them, and automate remediation
- Cloud identity and access: Drive least privilege and zero trust by default, across every system, credential and workload we operate
- Application security: Run design and code reviews and threat modeling for new features and products
- Paved roads: Partner with DevOps on reusable, secure-by-default paths for CI/CD, logging and auth, so every new service starts at our baseline and teams ship faster
- Incident response: Be a technical lead when something needs investigating, and build the tooling that makes the next investigation faster
- Automate: If you do it twice by hand, you build it the third time
Skills
- 4+ years in security engineering, or infrastructure engineering with real security ownership, at a cloud-native company
- You write code. Python, Go or similar, and you'd rather build a guardrail than write a runbook
- Deep in cloud IAM and Kubernetes security: you design for least privilege and short-lived credentials by default, and can walk engineers through the tradeoffs
- Fluent in CI/CD: you've hardened pipelines, not just run tools in them
- You work in the open with engineers: design reviews, pull requests and docs, not tickets thrown over a wall
- You prioritize by real-world risk, not scanner severity, and can explain the call to engineers and leadership alike
- You've secured systems that process email or other high-sensitivity customer data
- You've built a vulnerability management program and automated it end to end
- LLM application security: prompt injection, model pipelines, AI agent guardrails
- Supply chain security: artifact signing, provenance, SBOMs
- Detection engineering, or close partnership with a SOC
- You've worked at a security vendor and know what it means to be the product
Qualifications
Must Haves
- 4+ years in security engineering, or infrastructure engineering with real security ownership, at a cloud-native company
- You write code. Python, Go or similar, and you'd rather build a guardrail than write a runbook
- Deep in cloud IAM and Kubernetes security: you design for least privilege and short-lived credentials by default, and can walk engineers through the tradeoffs
- Fluent in CI/CD: you've hardened pipelines, not just run tools in them
- You work in the open with engineers: design reviews, pull requests and docs, not tickets thrown over a wall
- You prioritize by real-world risk, not scanner severity, and can explain the call to engineers and leadership alike
Nice to Haves
- You've secured systems that process email or other high-sensitivity customer data
- You've built a vulnerability management program and automated it end to end
- LLM application security: prompt injection, model pipelines, AI agent guardrails
- Supply chain security: artifact signing, provenance, SBOMs
- Detection engineering, or close partnership with a SOC
- You've worked at a security vendor and know what it means to be the product
Benefits
- Remote work
- Flexible work environment