Aegis AI Security logo
Aegis AI Security
Posted 2 days agoVerified live 1d ago

Security Engineer

Brief overview

Remote
UndergradOr in progress
4+ yrsMinimum
Security EngineeringPythonGoCloud IAMKubernetes SecurityCI/CD SecurityVulnerability ManagementApplication SecurityThreat ModelingCloud Security Posture ManagementIncident ResponseSupply Chain Security

About the company

Aegis AI Security logo
Aegis AI Securityaegisai.ai

Aegis AI is an AI-native Email Security platform.

Job description

Summary

Aegis AI Security is developing defensive platforms to address adversarial AI attacks affecting organizations. The Security Engineer will accelerate the company’s security program by owning vulnerability management, cloud security posture and identity controls, CI/CD security gates, application security, secure engineering paths, and incident response tooling.

Responsibilities

  • Vulnerability management at the source: Own scanning across code, dependencies, images, cloud config and our external surface; automate the triage, the routing to owners, and the remediation itself wherever it's safe; keep what's left inside our SLAs
  • CI/CD security: Own and expand the security gates in our build and deploy pipelines, so vulnerable dependencies and misconfigurations are blocked before they ship
  • Cloud security posture: Define secure baselines for our cloud estate, detect drift from them, and automate remediation
  • Cloud identity and access: Drive least privilege and zero trust by default, across every system, credential and workload we operate
  • Application security: Run design and code reviews and threat modeling for new features and products
  • Paved roads: Partner with DevOps on reusable, secure-by-default paths for CI/CD, logging and auth, so every new service starts at our baseline and teams ship faster
  • Incident response: Be a technical lead when something needs investigating, and build the tooling that makes the next investigation faster
  • Automate: If you do it twice by hand, you build it the third time

Skills

  • 4+ years in security engineering, or infrastructure engineering with real security ownership, at a cloud-native company
  • You write code. Python, Go or similar, and you'd rather build a guardrail than write a runbook
  • Deep in cloud IAM and Kubernetes security: you design for least privilege and short-lived credentials by default, and can walk engineers through the tradeoffs
  • Fluent in CI/CD: you've hardened pipelines, not just run tools in them
  • You work in the open with engineers: design reviews, pull requests and docs, not tickets thrown over a wall
  • You prioritize by real-world risk, not scanner severity, and can explain the call to engineers and leadership alike
  • You've secured systems that process email or other high-sensitivity customer data
  • You've built a vulnerability management program and automated it end to end
  • LLM application security: prompt injection, model pipelines, AI agent guardrails
  • Supply chain security: artifact signing, provenance, SBOMs
  • Detection engineering, or close partnership with a SOC
  • You've worked at a security vendor and know what it means to be the product

Qualifications

Must Haves

  • 4+ years in security engineering, or infrastructure engineering with real security ownership, at a cloud-native company
  • You write code. Python, Go or similar, and you'd rather build a guardrail than write a runbook
  • Deep in cloud IAM and Kubernetes security: you design for least privilege and short-lived credentials by default, and can walk engineers through the tradeoffs
  • Fluent in CI/CD: you've hardened pipelines, not just run tools in them
  • You work in the open with engineers: design reviews, pull requests and docs, not tickets thrown over a wall
  • You prioritize by real-world risk, not scanner severity, and can explain the call to engineers and leadership alike

Nice to Haves

  • You've secured systems that process email or other high-sensitivity customer data
  • You've built a vulnerability management program and automated it end to end
  • LLM application security: prompt injection, model pipelines, AI agent guardrails
  • Supply chain security: artifact signing, provenance, SBOMs
  • Detection engineering, or close partnership with a SOC
  • You've worked at a security vendor and know what it means to be the product

Benefits

  • Remote work
  • Flexible work environment

More jobs like this