Information Security Engineer

Hark•San Jose, CA
•$150,000 - $300,000

About The Position

We're hiring a Member of Technical Staff (Information Security Engineer) to secure the infrastructure and systems Hark runs on. You'll harden our AWS environments, own identity and access across the company, build detection and response, and lead incident response when things go wrong. We run model training, agent sandboxes, and hardware manufacturing pipelines, so the environment is broader and more interesting than a typical SaaS stack. This role is hands-on; you'll be building and operating, not managing or auditing.

Requirements

  • 4–8 years of hands-on security engineering experience in cloud and infrastructure security.
  • Deep fluency in AWS security (IAM, Organizations/SCPs, CloudTrail, EKS), network hardening, and cloud posture tooling like Wiz (or equivalent).
  • Experience with detection engineering and incident response using tools like GuardDuty and CrowdStrike (or equivalent); you've triaged real alerts and contained real incidents.
  • Ability to read and review infrastructure-as-code (Pulumi, Terraform, or similar) for security issues.
  • Comfort writing code and automation (Python, Go, or similar) to eliminate manual security work.
  • Experience administering identity and endpoint platforms like Google Workspace as IdP, Kandji, and CrowdStrike (or equivalent IdP, MDM, and EDR tools).

Nice To Haves

  • Experience at a cloud security company (Wiz, Orca, Datadog, Snyk) or a security-forward startup (Stripe, Figma, Ramp, Netflix).
  • Familiarity with zero-trust networking and secrets tooling (Tailscale, Cloudflare, HashiCorp Vault).
  • Experience securing ML infrastructure, GPU clusters, or hardware/manufacturing supply chains.
  • Hands-on experience building out a SOC 2 program at an early-stage company.

Responsibilities

  • Harden cloud infrastructure across multiple AWS accounts (IAM, EKS, VPC and network access paths, KMS) and review IaC for misconfigurations.
  • Own identity and access: SSO, least-privilege IAM, just-in-time access, secrets management, and access reviews.
  • Build and maintain detection and alerting pipelines; lead triage, containment, and post-incident review.
  • Secure the corporate environment: endpoint management, SaaS security posture, and zero-trust network access.
  • Evaluate third-party vendors and integrations for security and privacy risk.
  • Build the technical controls and evidence behind our compliance programs (SOC 2, GDPR) as automation, not spreadsheets.

Benefits

  • The US base salary range for this full-time position is between $150,000 - $300,000 annually.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service