Security Engineer [ic3]

Sourcegraph Sourcegraph · Enterprise · Remote · Engineering

Sourcegraph is seeking a Security Engineer to build world-class security into their product offerings. This role involves security operations, monitoring, incident response, application security testing, bug bounty programs, and security reviews. The engineer will also work on improving the security of the codebase, product, cloud, and customer deployments, with a focus on Security Operations but also touching all facets of a security program. Responsibilities include maintaining internal systems, triaging customer concerns, enhancing application security, performing incident response, and proactive research into new attack vectors. The role also involves threat modeling, assessing new tools, and maintaining compliance with SOC 2, ISO 27001, and GDPR standards. The ideal candidate has practical experience with SIEM alerts, on-call rotations, securing SaaS applications, Go, Elastic stack, GCP, and automating defensive security tools. Experience securing AI products is a plus.

What you'd actually do

  1. working on security operations, maintaining and improving our monitoring and alerting stack, participating in on-call and responding to security incidents, application security testing, bug bounty programs, and security reviews for both application and infrastructure security.
  2. proactively improve the security of our codebase, product, cloud, and customers' on-premise deployments.
  3. Maintain internal systems, such as automations that assist in alert triaging
  4. perform reactive incident response if a security event occurs
  5. perform proactive research to detect new attack vectors

Skills

Required

  • Practical experience reviewing SIEM alerts and participating in on-call rotations
  • Practical experience securing SaaS applications as a security generalist, including infrastructure security, application security, and/or compliance
  • Experience with Go, including writing and maintaining internal tooling along with code reviews
  • Experience with Elastic stack and GCP
  • Experience using and automating a wide range of defensive security tools
  • Experience working across engineering teams to secure projects across the organization.

Nice to have

  • Experience developing software as an engineer (i.e., writing code and contributing directly to applications)
  • Experience working in a startup environment
  • Experience with TypeScript and Terraform
  • Experience with Kubernetes
  • Experience securing AI products

What the JD emphasized

  • world-class security
  • security operations
  • application security
  • infrastructure security
  • compliance
  • SOC 2
  • ISO 27001
  • GDPR
  • securing AI products