Posted today · be early
Security Engineer [IC3]
Sourcegraph
WorldwideremotePosted today
Skill Required
Security-EngineeringSecurity-OperationsApplication-SecurityInfrastructure-SecurityCloud-SecuritySecurity-EngineerIT-Security-EngineerInfrastructure-Security-EngineerCybersecurity-EngineerSecurity EngineersecuritySOCEngineeringTypeScriptKubernetesISO 27001developingObservabilityTerraformbuildingTestNGCloudSIEMGCPandGoAIFulltime
Key highlights
- Starting salary by zone: Zone 2: $144,000 USD, Zone 3: $108,000 USD, Zone 4: $72,000 USD
- Equity included alongside competitive cash compensation
- Level: IC3
- Must overlap with EST for at least 10 hours/week
- Total interview time expected under 5 hours
- Globally distributed; preference for Europe but open to all locations
Role overview
Responsibilities
- Be onboarded to our alerting and monitoring stack
- Participate in on-call rotations
- Discover, fix, and mitigate infrastructure vulnerabilities by updating libraries, base images, and analyzing containers
- Maintain internal systems, such as automations that assist in alert triaging
- Work with other teams to triage, troubleshoot, and mitigate customer concerns and questions about our security
- Enhance our application security with audits, best practices, code fixes, and continuous education
- Perform reactive incident response if a security event occurs
- Work with your manager on a career plan with actionable goals
- Perform proactive research to detect new attack vectors
- Perform threat modeling for existing and future applications
- Assess and integrate new tools and technologies to improve operational efficiencies
- Help maintain compliance with SOC 2, ISO 27001 & GDPR standards
Requirements
- Practical experience reviewing SIEM alerts and participating in on-call rotations
- Practical experience securing SaaS applications as a security generalist, including infrastructure security, application security, and/or compliance
- Experience with Go, including writing and maintaining internal tooling along with code reviews
- Experience with Elastic stack and GCP
- Experience using and automating a wide range of defensive security tools
- Experience working across engineering teams to secure projects across the organization
- High agency
- Effective communicator in writing and documentation
Nice to have
- Experience developing software as an engineer (i.e., writing code and contributing directly to applications)
- Experience working in a startup environment
- Experience with TypeScript and Terraform
- Experience with Kubernetes
- Experience securing AI products
Benefits
- Above-market salaries
- Meaningful equity
- Generous perks & benefits
- Compensation philosophy and pay bands are visible to every teammate; approach is equitable, explainable, and competitive
- Globally distributed team
- Preference for Europe but welcome applicants regardless of location
- Must overlap with EST for at least 10 hours/week
Additional details
- Job level: IC3
- Interview process takes less than 5 hours total, consisting of: 20m Recruiter Screen, 45m Hiring Manager Screen / Resume Deep Dive, 60m Technical Interview: General, 60m Technical Interview: Complex Problem Deep Dive, 45m Cross-functional Team Collaboration / Values, 15m Leadership, reference checks, and background check
- Company mission: bring clarity and control to the world's most complex codebases; provides Code Search, Deep Search, MCP, and Agentic Batch Changes
- Companies like Stripe, Reddit, and Leidos rely on Sourcegraph; backed by a16z, Sequoia, and Redpoint
- Equal opportunity workplace; participates in E-Verify for U.S. Employees
- Originally posted on Himalayas