English summary for screening — check the original posting before applying.
Seeking a Security Engineer to strengthen defenses during the pre-IPO phase. You will cover six key areas, with responsibilities flexibly adjusted based on your experience and the team's growth.
Must-haves
- Experience in vulnerability assessment, secure coding support, or incident response.
- Experience in GRC engineering, transitioning manual evidence collection to code-based continuous acquisition.
- Experience expanding detection coverage to new products like ecforce AIdp.
- Experience strengthening security for the ecforce product family, including secure code reviews and vulnerability management.
- Ability to define issues, take responsibility for design decisions, and negotiate with development, SRE, and business teams.
- Ability to verify AI outputs and ensure correctness.
- Ability to create systems that are managed, tested, and deployable as code, avoiding reliance on individuals.
Nice-to-haves
- Experience with PCI DSS, ISMS, P-Mark, or SOC 2 compliance.
- Experience with corporate/zero trust infrastructure, including ID management, device management, and network security.
- Experience with AI security, including risk assessment and countermeasures for AI agents and LLM applications.
- Experience with team/project management, including security roadmap creation and budget/vendor management.
Tech stack
AWS (IAM, VPC, Lambda, Security Hub, GuardDuty)TerraformGitHubWizRuby on RailsSQLAthenaGlueGeminiClaudeClaude CodeNotion AINotebookLMCursorGitHub CopilotDevinSlackNotion
Work style
Remote possible