Summary
Anaconda advances artificial intelligence through open-source platforms for Python, data science, and AI. The Security Engineer will design and implement security controls, automation, and secure-by-default systems across hybrid and multi-cloud environments while reducing systemic risk and enabling engineering teams to deliver efficiently.
Responsibilities
- Design and implement security controls across firewalls, IAM, endpoint detection and response, and secrets management in hybrid and multi-cloud environments
- Build security automation and tooling using Python, Go, and Bash, managing infrastructure as code with Terraform to scale security baselines and reduce manual toil
- Conduct vulnerability and threat management by triaging scanner output, investigating root causes, and driving risk reduction with clear operational guidance
- Perform code reviews and architecture assessments to identify security risks early and collaborate with engineering teams to design secure solutions
- Embed security into CI/CD pipelines through SAST, DAST, and dependency scanning, creating developer-friendly workflows that catch issues before production
- Respond to security incidents as an escalation point, performing forensic analysis and maintaining tested runbooks for calm, effective containment during critical events
- Partner with Legal, IT, Platform Engineering, and Developer Experience teams to translate security risks into business impacts and deliver controls that add velocity
- Develop secure-by-default templates, libraries, and tooling that make it easier for developers to do the right thing without friction
Skills
- 3+ years of hands-on experience in systems administration, DevOps, network engineering, or software development prior to or alongside security work
- Proficiency with cloud platforms including AWS, Azure, or GCP, and experience managing infrastructure as code using Terraform
- Experience writing scripts and automation in Python, Go, or Bash to integrate tools and reduce manual security tasks
- Working knowledge of core security disciplines including IAM, PKI, cryptography basics, network protocol analysis, and threat modeling frameworks
- Demonstrated ability to communicate technical security risks to non-security audiences and design workflows that respect developer experience
- Experience working in containerized environments with Docker or Kubernetes
- You embody our values of Clarity, Care and Candor
- You care deeply about fostering an environment where people of all backgrounds and experiences can flourish
- You have offensive security experience through penetration testing, red teaming, bug bounty programs, or reverse engineering, and can think like an attacker to build better defenses
- You've worked with advanced container security tools such as Falco or eBPF, or implemented zero trust architecture and network isolation in production environments
- You bring a production engineering, SRE, or software engineering background with experience writing custom SAST or DAST rules, or managing SBOM and supply chain security
- You have specialized expertise in HSMs, hardware tokens like YubiKeys or FIDO2, applied cryptography, or identity provider integrations with platforms like Okta or Azure AD
- You've contributed to security culture through training programs, threat modeling workshops, CTF events, conference talks, or open-source security projects
- You've thrived in fast-paced startup environments where you balanced speed with thoughtful risk management
- Experience working in a fast-paced startup environment
- Experience working in an open-source, AI, or data science-oriented company
Qualifications
Must Haves
- 3+ years of hands-on experience in systems administration, DevOps, network engineering, or software development prior to or alongside security work
- Proficiency with cloud platforms including AWS, Azure, or GCP, and experience managing infrastructure as code using Terraform
- Experience writing scripts and automation in Python, Go, or Bash to integrate tools and reduce manual security tasks
- Working knowledge of core security disciplines including IAM, PKI, cryptography basics, network protocol analysis, and threat modeling frameworks
- Demonstrated ability to communicate technical security risks to non-security audiences and design workflows that respect developer experience
- Experience working in containerized environments with Docker or Kubernetes
- You embody our values of Clarity, Care and Candor
- You care deeply about fostering an environment where people of all backgrounds and experiences can flourish
Nice to Haves
- You have offensive security experience through penetration testing, red teaming, bug bounty programs, or reverse engineering, and can think like an attacker to build better defenses
- You've worked with advanced container security tools such as Falco or eBPF, or implemented zero trust architecture and network isolation in production environments
- You bring a production engineering, SRE, or software engineering background with experience writing custom SAST or DAST rules, or managing SBOM and supply chain security
- You have specialized expertise in HSMs, hardware tokens like YubiKeys or FIDO2, applied cryptography, or identity provider integrations with platforms like Okta or Azure AD
- You've contributed to security culture through training programs, threat modeling workshops, CTF events, conference talks, or open-source security projects
- You've thrived in fast-paced startup environments where you balanced speed with thoughtful risk management
- Experience working in a fast-paced startup environment
- Experience working in an open-source, AI, or data science-oriented company
Benefits
- Annual bonus potential
- Equity participation
- Flexible Vacation Policy
- Medical, Dental, and Vision Insurance
- Short Term and Long Term Disability
- Paid Parental Leave
- Monthly Wellness Stipend
- Employee Assistance Program and Mental Health Resources
- Flexible hours
- Fully remote setup
- A genuine commitment to your wellbeing and growth