About The Position

We're looking for a Security Engineer to accelerate AegisAI's security program. Our customers trust us with their most sensitive data, and you'll build the systems that keep it protected: the scanning and vulnerability management that covers all of engineering, the posture and identity controls across our cloud estate, and the guardrails in our pipelines that stop problems before they ship. This is a building role, not a gatekeeping one. The best security engineering here looks like paved roads: predefined pipelines, logging and auth paths that make the secure way the fast way, so product teams move quicker because security already did the thinking. You'll work directly with our engineering and DevOps teams and with the head of security, and your fingerprints will be on how a security company secures itself. You'll own real surface from week one, and the scope grows as fast as you can take it.

Requirements

  • 4+ years in security engineering, or infrastructure engineering with real security ownership, at a cloud-native company.
  • You write code. Python, Go or similar, and you'd rather build a guardrail than write a runbook.
  • Deep in cloud IAM and Kubernetes security: you design for least privilege and short-lived credentials by default, and can walk engineers through the tradeoffs.
  • Fluent in CI/CD: you've hardened pipelines, not just run tools in them.
  • You work in the open with engineers: design reviews, pull requests and docs, not tickets thrown over a wall.
  • You prioritize by real-world risk, not scanner severity, and can explain the call to engineers and leadership alike.

Nice To Haves

  • You've secured systems that process email or other high-sensitivity customer data.
  • You've built a vulnerability management program and automated it end to end.
  • LLM application security: prompt injection, model pipelines, AI agent guardrails.
  • Supply chain security: artifact signing, provenance, SBOMs.
  • Detection engineering, or close partnership with a SOC.
  • You've worked at a security vendor and know what it means to be the product.

Responsibilities

  • Own scanning across code, dependencies, images, cloud config and our external surface; automate the triage, the routing to owners, and the remediation itself wherever it's safe; keep what's left inside our SLAs.
  • Own and expand the security gates in our build and deploy pipelines, so vulnerable dependencies and misconfigurations are blocked before they ship.
  • Define secure baselines for our cloud estate, detect drift from them, and automate remediation.
  • Drive least privilege and zero trust by default, across every system, credential and workload we operate.
  • Run design and code reviews and threat modeling for new features and products.
  • Partner with DevOps on reusable, secure-by-default paths for CI/CD, logging and auth, so every new service starts at our baseline and teams ship faster.
  • Be a technical lead when something needs investigating, and build the tooling that makes the next investigation faster.
  • Automate: If you do it twice by hand, you build it the third time.

Benefits

  • Flat, flexible, and fast.
  • You'll own your decisions.
  • You'll have clear KPIs for success — but how you get there is up to you.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service