Security Engineer
Senior · Full Time · Remote
Opens Posthog's application page
Role
What you'll do.
Security Engineer at PostHog - an expert generalist role overseeing all aspects of security operations for a high-growth, open-source product analytics platform. This position focuses on building security infrastructure from scratch, including detection pipelines, incident response capabilities, and threat hunting in AWS cloud-native environments. The ideal candidate combines deep cloud security expertise with strong engineering skills and a collaborative mindset to enable product teams while maintaining robust security posture.
Responsibilities
- Alert Triage and Tuning: Own and manage cloud security monitoring alerts through CSPM/CNAPP tools like Wiz, converting noise into actionable security findings. Establish alert fatigue reduction protocols to ensure the security team focuses only on genuine threats that require response and mitigation.
- Incident Detection and Response Leadership: Lead security incident response efforts from initial detection through post-mortem analysis. Coordinate cross-functional response to security events such as compromised dependencies or suspicious IAM patterns. Develop and maintain incident response runbooks that enable rapid, effective containment and remediation.
- Detection Pipeline Development: Design and build comprehensive detection pipelines using AWS CloudTrail, VPC Flow Logs, and network telemetry tools. Enable end-to-end traceability of network requests and suspicious activity back to specific code execution paths for deeper security context.
- Proactive Threat Hunting: Conduct regular threat hunts across the AWS environment to identify indicators of compromise and anomalous patterns. Define security baselines, establish telemetry collection for threat visibility, and move beyond reactive alert-based security to predictive threat identification.
- Vulnerability Disclosure Program Support: Manage and triage security research submissions through PostHog's Vulnerability Disclosure Program. Coordinate with researchers, validate findings, assign issues to product teams, and advance the program toward formal bug bounty operations with improved automation and workflows.
- Threat Modeling and Secure Design Reviews: Partner with product squads to conduct threat modeling sessions and architectural security reviews. Provide constructive guidance on secure implementation practices and design patterns, positioning security as an enabler rather than a constraint on product development.
- Security Culture Development: Foster a security-conscious engineering culture by building trust between security and product teams. Champion security best practices through mentoring, documentation, and collaborative problem-solving that demonstrates how to build features securely at PostHog's rapid pace.
- Internal Security Tooling: Participate in building internal security automation tools and agents, including automated alert triage systems, pull request security scanning, and vulnerability finding assignment workflows that reduce manual security operations overhead.
Qualifications
What we look for.
Technical
AWS Cloud Security
Expert-level proficiency with AWS security infrastructure including IAM policies, VPC architecture, VPC Flow Logs analysis, CloudTrail event monitoring, and S3 bucket security configurations. Demonstrated ability to design and audit cloud security architectures at scale.
CSPM and CNAPP Tools
Hands-on experience with Cloud Security Posture Management and Cloud-Native Application Protection Platform tools such as Wiz, Prisma Cloud, or similar solutions. Ability to configure detection rules, tune alerts, and integrate findings into security workflows.
Security Code Analysis
Experience with static application security testing and code scanning rule development. Proficiency with semantic analysis tools like Semgrep for writing custom vulnerability detection rules. Understanding of common vulnerability patterns and secure coding practices.
Incident Response and Forensics
Proven track record leading security incident response operations including threat containment, evidence preservation, and forensic analysis. Experience coordinating cross-functional incident response and communicating technical findings to both technical and non-technical stakeholders.
Network Security and Observability
Deep understanding of network security monitoring, VPC Flow Logs interpretation, DNS query analysis, and network-based threat detection. Experience building observability pipelines that correlate network activity with application-level security events.
Software Engineering Fundamentals
Strong engineering skills equivalent to product engineers on the team, including proficiency in at least one modern programming language. Ability to read, analyze, and understand application code to identify security vulnerabilities and trace exploitation techniques.
Education
Bachelor's Degree in Computer Science or Related Field
Formal education in computer science, cybersecurity, information security, or closely related technical discipline. Equivalent professional experience and demonstrated expertise may substitute for formal degree.
Security Certifications (Preferred)
Industry-recognized credentials such as CISSP, CEH, OSCP, AWS Security Specialty, or similar certifications demonstrating commitment to security expertise and structured knowledge of security practices.
Experience
Cloud Security Engineering
3-5+ years of hands-on security engineering experience with strong focus on cloud-native infrastructure and AWS specifically. Background should include designing secure cloud architectures, implementing detection mechanisms, and managing security operations in production environments.
Security Operations and SIEM Experience
Experience building or operating security monitoring infrastructure and establishing detection capabilities. Familiarity with security event correlation, alert management, and threat intelligence integration. Should demonstrate comfort operating with incomplete information and building confidence in detections iteratively.
Leadership of Security Initiatives
Track record of taking ownership of security initiatives and executing independently with minimal guidance. Experience making security prioritization decisions, defining success metrics, and driving adoption of security practices across engineering teams.
Skills
Required
AWS IAM and Access Control
Ability to design least-privilege IAM policies, audit role assumptions, and detect anomalous authentication patterns. Deep understanding of principal-based access control, cross-account access, and temporary credential management.
Cloud Log Analysis
Proficiency with AWS CloudTrail, VPC Flow Logs, CloudWatch Logs, and S3 access logging. Ability to write queries, build detection rules, and extract security signals from high-volume cloud audit logs.
Incident Response Execution
Experience executing incident response from detection through resolution, including threat containment, evidence preservation, impact assessment, and post-incident analysis. Ability to maintain composure and coordinate effectively under pressure.
Security-First Communication
Ability to translate complex technical security issues into clear guidance that enables engineering teams rather than blocks them. Comfortable working collaboratively with product teams and presenting security recommendations as opportunities rather than obstacles.
Threat Hunting Methodology
Experience defining security baselines, establishing hunt hypotheses, and proactively searching for indicators of compromise. Ability to build telemetry and detection logic based on threat intelligence and behavioral analytics.
Python or Go Programming
Proficiency with Python, Go, or similar languages for writing security tools, automation scripts, detection logic, and integrations. Should be capable of contributing production-quality code for security infrastructure.
Preferred
Open Source Security Experience
Nice to haveBackground working with or maintaining open-source projects, particularly experience securing open-source software supply chains. Familiarity with open-source community dynamics and how to balance security with accessibility in open-source contexts.
Kubernetes and Container Security
Nice to haveExperience securing containerized workloads, implementing Pod Security Policies, managing image scanning, and securing Kubernetes runtime environments. Understanding of container-specific threat models and detection techniques.
Semgrep or Similar SAST Tools
Nice to haveExperience writing custom semantic analysis rules for vulnerability detection. Proficiency with Semgrep, Checkmarx, or similar static analysis tools for automating security code reviews across multiple repositories.
Vulnerability Disclosure Program Management
Nice to haveExperience managing vulnerability disclosure programs, triaging security research submissions, and coordinating with external security researchers. Background running bug bounty programs or similar responsible disclosure initiatives.
Security Observability Platforms
Nice to haveHands-on experience with extended detection and response (XDR), managed detection and response (MDR), or security orchestration platforms. Familiarity with SOAR automation or security automation frameworks.
Startup or High-Growth Environment Experience
Nice to haveBackground working in fast-paced startup environments where security infrastructure is built from scratch. Experience balancing security rigor with velocity and autonomy-driven culture.
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·USD 160,000 – 220,000
Equity·Stock options
Benefits
Fully Remote Work
Work from anywhere with a globally distributed team. PostHog is natively remote with async-first communication and flexible timezone accommodation for all employees.
Meeting-Free Building Days
Tuesdays and Thursdays designated as meeting-free days to protect deep work and engineering focus time. Prioritizes productivity and uninterrupted building time over constant meetings.
Equity Compensation
Significant equity stake in PostHog, aligning employee success with company growth. Competitive equity packages designed to share upside of the company's success.
Transparent Company Operations
Access to complete company transparency including roadmap visibility, board meeting notes, revenue figures, and strategic planning. All employees empowered with information needed to make impactful decisions.
Professional Development Budget
Annual budget for security certifications, training, conferences, and continuing education. Support for maintaining industry certifications and developing expertise in emerging security domains.
Health and Wellness Benefits
Comprehensive health insurance, mental health support, and wellness programs. Flexible time off policy with no fixed vacation allowance beyond company holidays.
Learning and Conference Support
Support for attending security conferences, training programs, and professional development opportunities. Access to resources for staying current with security threats and industry best practices.
Autonomous Work Environment
High degree of autonomy in decision-making and project prioritization. Ability to define and execute on what matters most without micromanagement or bureaucratic approval processes.
Full posting
Original listing.
About PostHog
We equip every developer to build successful products.
We started with open-source product analytics, launched out of Y Combinator's W20 cohort.
We've since shipped more than a dozen products, including a built-in data warehouse, a customer data platform, and Max AI, an AI-powered analyst that answers product questions, helps users find useful session recordings, and writes custom SQL queries.
Next on the roadmap are messaging, customer analytics, ai task creation and coding based on customer data, logs and support analytics.
Our values are not a poster on the wall full of aspiration. They’ve come from how we really work, day in day out.
PostHog is open source product led, and a default alive company that is well funded.
Things we care about
Transparency: Everyone can read about our roadmap, how we pay (or even let go of) people, our strategy, and how we work, in our public company handbook. Internally, we share revenue, notes and slides from board meetings, and fundraising plans, so everyone has the context they need to make good decisions.
Autonomy: We don’t tell anyone what to do. Everyone chooses what to work on next based on what's going to have the biggest impact on our customers, and what they find interesting and motivating to work on. Engineers lead product teams and make product decisions. Teams are flexible and easy to change when needed.
Shipping fast: Why not now? We want to build a lot of products; we can't do that shipping at a normal pace. We've built the company around small teams – autonomous, highly-efficient groups of cracked engineers who can outship much larger companies because they own their products end-to-end.
Time for building: Nothing gets shipped in a meeting. We're a natively remote company. We default to async communication – PRs > Issues > Slack. Tuesdays and Thursdays are meeting-free days, and we prioritize heads down building time over perfect coordination. This will be the most productive job you've ever had.
Ambition: We want to solve big problems. We strongly believe that aiming for the best possible upside, and sometimes missing, is better than never trying. We're optimistic about what's possible and our ability to get there.
Being weird: Weird means redesigning an already world-class website for the 5th time. It means shipping literally every product that relates to customer data. It means building an objectively unnecessary developer toy with dubious shareholder value. Doing weird stuff is a competitive advantage. And it's fun.
Who we're looking for
We are looking for an expert security generalist to assist with all things security at PostHog. Someone equally adept (and interested!) in building secure libraries, writing semgrep rules, hardening cloud deployments, improving network observability, and leading incident response.
Someone to take the reins of our security operations, build out our detection pipelines, and ensure that when something goes bump in the night, we have the observability to know exactly what happened.
We're a team that's building internal security products and agents - things like agents to automatically triage wiz alerts, automatically review pull requests, automatically assign vulnerability findings to the owning product team.
In this role you’ll:
Build from Scratch: You aren't maintaining someone else's legacy SIEM. You are shaping the security team, culture and tooling for a high-growth, open-source company.
Zero Bureaucracy: We hate meetings. We don't have "Security Committees." You have the autonomy to make changes and move fast.
Transparency: We work in the open. You’ll be able to see (and contribute to) how we handled past incidents, like this NPM package compromise.
Direct Impact: Your work directly protects the data of thousands of customers. When you improve our security posture, the whole company (and our community) feels it.
What you'll be doing
Triage and Tune: You’ll own our Wiz alerts. You’ll be responsible for turning "noise" into "actionable findings" and ensuring we aren't just staring at a dashboard of issues that don't actually matter. We already get relatively few alerts, and we’d like to even further reduce that to just the ones that matter.
Incident detection, response: You’ll lead the charge on security incidents. Whether it’s a compromised NPM package or a suspicious IAM pattern, you’ll help coordinate the response and lead the post-mortem. You’ll also help build our IR runbooks.
Build Observability: You’ll build detection pipelines, and close our network-based observability gaps. We want to be able to trace network requests and suspicious activity all the way back to specific code paths.
Threat Hunting: You’ll proactively hunt for threats in our AWS environment. You won't just wait for an alert; you'll define what "good" looks like and build the telemetry to prove it.
The VDP: You’ll support our Vulnerability Disclosure Program, triaging reports from researchers and eventually transitioning us toward a formal bug bounty program.
Enable the Team: You’ll support our product squads with threat modeling and secure design reviews. We don't do "Security says no", we do "Security says 'here is how to do this safely.'"
Help build our security culture: Our engineers trust the security team and view security as an enabler. You’ll be a crucial part of helping to continue this excellent (and uncommon) working relationship.
While this is not a Corporate security (MDM, endpoint, device trust) or Supply chain/CI-CD hardening role, in true PostHog style, there are opportunities to work on these as well
Requirements
Cloud Native: You have 3-5+ years of experience in security engineering with a heavy focus on AWS. You know your way around IAM, VPC logs, and CloudTrail like the back of your hand.
Detection Specialist: You’ve used CSPM/CNAPP tools (like Wiz or Prisma) and, more importantly, you know how to build detection pipelines that engineers actually trust.
Battle-Tested: You’ve led incident response before. You’re calm under pressure and know how to coordinate across teams to contain a threat.
High Autonomy: We don’t have a security SOC. You’ll be building this function from scratch, so you need to be comfortable deciding what’s important and executing on it without a manual.
Engineering skills: You bring strong engineering experience and next to digging into code to understand an exploit or a vulnerability, you can write code with the same proficiency as our product engineers.
Communication and attitude: As mentioned before we don't do "Security says no", we do "Security says 'here is how to do this safely.” This is crucial for us, we need people that want to enable engineers and work with them, not limit them.
We are committed to ensuring a fair and accessible interview process. If you need any accommodations or adjustments, please let us know.
Redirects to Posthog's application page.