Security Operations Engineer
Indexed description
The Role
We're hiring our founding Security Operations Engineer to help build and scale our security program from the ground up. This is a hands-on role for a builder who wants to shape security from the ground up. As our first dedicated Security Engineer, you’ll partner with the IT & Security Leader to design and scale security across cloud, identity, applications, endpoints, and incident response.
You’ll lead technical execution while collaborating on architecture, priorities, and long-term strategy. This role offers meaningful ownership, active mentorship, and the opportunity to build a practical security program that grows with the company.
This role is on-site (hybrid OK) at our San Francisco office in the Dogpatch neighborhood.
Responsibilities
Security Operations & Incident Response
- Partner with the IT & Security Leader to build and mature the company's security operations program.
- Design, implement, and continuously improve SIEM, EDR, and endpoint security capabilities.
- Develop, tune, and maintain detections across cloud, endpoint, identity, and SaaS platforms.
- Lead technical incident investigations while collaborating on incident response planning and post-incident reviews.
- Partner on designing and continuously improving AWS and GCP security posture.
- Lead implementation of identity security across Okta, Google Workspace, cloud IAM, privileged access, MFA, and SSO.
- Secure Kubernetes, Docker, and Infrastructure-as-Code environments.
- Design and maintain centralized security logging and telemetry.
- Lead the vulnerability management program in partnership with Engineering and IT.
- Partner with Engineering to improve secure software development, API security, and application security.
- Lead security awareness initiatives, phishing simulations, and tabletop exercises.
- Evaluate emerging AI technologies that improve security operations while supporting secure AI adoption.
- 5+ years in Security Engineering, Security Operations, Incident Response, or related cybersecurity roles.
- Hands-on AWS and GCP security experience.
- Experience with SIEM, EDR, detection engineering, and threat hunting.
- Strong knowledge of identity security, cloud IAM, and Zero Trust.
- Experience securing Kubernetes, Docker, and Infrastructure-as-Code.
- Knowledge of API Security and OWASP Top 10.
- Experience developing security metrics, KPIs, dashboards, and executive-level reporting.
- Familiarity with SOC 2 or similar frameworks.
- Excellent communication and cross-functional collaboration.
- Experience using AI/LLMs to improve security operations, investigations, detection engineering, or automation.
- Experience designing, implementing, and tuning IDS/IPS, DLP, or related security controls.
- Experience developing and maintaining security policies, standards, runbooks, and SOPs for technical and business stakeholders.
- Competitive salary and equity
- Full healthcare coverage; we pay 100% of premiums for you and your dependents
- Support for growing families, including a yearly new parent stipend and fertility coverage through Carrot
- Mental health support through Rula, our in-network therapist and psychiatrist network with fast availability
- 12 weeks of paid parental leave for maternity, paternity, and adoption
- Pet care support with a yearly employer-funded stipend for your animal companions
- Commuter benefits so you can pay for transit and parking with pre-tax dollars
- 401(k) company matching
- $300 health and wellness benefit quarterly
- Lunch is on us every day you're in the office, and dinner is on us when you're working late
- Regular team off-sites and company events
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search