# Security Engineer
**Company:** [Posthog](https://scaleengineer.com/companies/posthog)
Security Engineer at PostHog - an expert generalist role overseeing all aspects of security operations for a high-growth, open-source product analytics platform. This position focuses on building security infrastructure from scratch, including detection pipelines, incident response capabilities, and threat hunting in AWS cloud-native environments. The ideal candidate combines deep cloud security expertise with strong engineering skills and a collaborative mindset to enable product teams while maintaining robust security posture.
**Role:** Security Engineer
**Seniority:** Senior
**Locations:** Remote (EMEA)
**Remote:** yes
**Salary:** 160000–220000 USD
[Apply](https://jobs.ashbyhq.com/posthog/36d5ce14-851c-450f-879a-45cbb896225e)
Canonical: https://scaleengineer.com/jobs/posthog/security-engineer
---
## Responsibilities

- Alert Triage and Tuning: Own and manage cloud security monitoring alerts through CSPM/CNAPP tools like Wiz, converting noise into actionable security findings. Establish alert fatigue reduction protocols to ensure the security team focuses only on genuine threats that require response and mitigation.
- Incident Detection and Response Leadership: Lead security incident response efforts from initial detection through post-mortem analysis. Coordinate cross-functional response to security events such as compromised dependencies or suspicious IAM patterns. Develop and maintain incident response runbooks that enable rapid, effective containment and remediation.
- Detection Pipeline Development: Design and build comprehensive detection pipelines using AWS CloudTrail, VPC Flow Logs, and network telemetry tools. Enable end-to-end traceability of network requests and suspicious activity back to specific code execution paths for deeper security context.
- Proactive Threat Hunting: Conduct regular threat hunts across the AWS environment to identify indicators of compromise and anomalous patterns. Define security baselines, establish telemetry collection for threat visibility, and move beyond reactive alert-based security to predictive threat identification.
- Vulnerability Disclosure Program Support: Manage and triage security research submissions through PostHog's Vulnerability Disclosure Program. Coordinate with researchers, validate findings, assign issues to product teams, and advance the program toward formal bug bounty operations with improved automation and workflows.
- Threat Modeling and Secure Design Reviews: Partner with product squads to conduct threat modeling sessions and architectural security reviews. Provide constructive guidance on secure implementation practices and design patterns, positioning security as an enabler rather than a constraint on product development.
- Security Culture Development: Foster a security-conscious engineering culture by building trust between security and product teams. Champion security best practices through mentoring, documentation, and collaborative problem-solving that demonstrates how to build features securely at PostHog's rapid pace.
- Internal Security Tooling: Participate in building internal security automation tools and agents, including automated alert triage systems, pull request security scanning, and vulnerability finding assignment workflows that reduce manual security operations overhead.

## Requirements

### education

- {"name":"Bachelor's Degree in Computer Science or Related Field","description":"Formal education in computer science, cybersecurity, information security, or closely related technical discipline. Equivalent professional experience and demonstrated expertise may substitute for formal degree."}
- {"name":"Security Certifications (Preferred)","description":"Industry-recognized credentials such as CISSP, CEH, OSCP, AWS Security Specialty, or similar certifications demonstrating commitment to security expertise and structured knowledge of security practices."}

### technical

- {"name":"AWS Cloud Security","description":"Expert-level proficiency with AWS security infrastructure including IAM policies, VPC architecture, VPC Flow Logs analysis, CloudTrail event monitoring, and S3 bucket security configurations. Demonstrated ability to design and audit cloud security architectures at scale."}
- {"name":"CSPM and CNAPP Tools","description":"Hands-on experience with Cloud Security Posture Management and Cloud-Native Application Protection Platform tools such as Wiz, Prisma Cloud, or similar solutions. Ability to configure detection rules, tune alerts, and integrate findings into security workflows."}
- {"name":"Security Code Analysis","description":"Experience with static application security testing and code scanning rule development. Proficiency with semantic analysis tools like Semgrep for writing custom vulnerability detection rules. Understanding of common vulnerability patterns and secure coding practices."}
- {"name":"Incident Response and Forensics","description":"Proven track record leading security incident response operations including threat containment, evidence preservation, and forensic analysis. Experience coordinating cross-functional incident response and communicating technical findings to both technical and non-technical stakeholders."}
- {"name":"Network Security and Observability","description":"Deep understanding of network security monitoring, VPC Flow Logs interpretation, DNS query analysis, and network-based threat detection. Experience building observability pipelines that correlate network activity with application-level security events."}
- {"name":"Software Engineering Fundamentals","description":"Strong engineering skills equivalent to product engineers on the team, including proficiency in at least one modern programming language. Ability to read, analyze, and understand application code to identify security vulnerabilities and trace exploitation techniques."}

### experience

- {"name":"Cloud Security Engineering","description":"3-5+ years of hands-on security engineering experience with strong focus on cloud-native infrastructure and AWS specifically. Background should include designing secure cloud architectures, implementing detection mechanisms, and managing security operations in production environments."}
- {"name":"Security Operations and SIEM Experience","description":"Experience building or operating security monitoring infrastructure and establishing detection capabilities. Familiarity with security event correlation, alert management, and threat intelligence integration. Should demonstrate comfort operating with incomplete information and building confidence in detections iteratively."}
- {"name":"Leadership of Security Initiatives","description":"Track record of taking ownership of security initiatives and executing independently with minimal guidance. Experience making security prioritization decisions, defining success metrics, and driving adoption of security practices across engineering teams."}

## Skills

### required

- {"name":"AWS IAM and Access Control","description":"Ability to design least-privilege IAM policies, audit role assumptions, and detect anomalous authentication patterns. Deep understanding of principal-based access control, cross-account access, and temporary credential management."}
- {"name":"Cloud Log Analysis","description":"Proficiency with AWS CloudTrail, VPC Flow Logs, CloudWatch Logs, and S3 access logging. Ability to write queries, build detection rules, and extract security signals from high-volume cloud audit logs."}
- {"name":"Incident Response Execution","description":"Experience executing incident response from detection through resolution, including threat containment, evidence preservation, impact assessment, and post-incident analysis. Ability to maintain composure and coordinate effectively under pressure."}
- {"name":"Security-First Communication","description":"Ability to translate complex technical security issues into clear guidance that enables engineering teams rather than blocks them. Comfortable working collaboratively with product teams and presenting security recommendations as opportunities rather than obstacles."}
- {"name":"Threat Hunting Methodology","description":"Experience defining security baselines, establishing hunt hypotheses, and proactively searching for indicators of compromise. Ability to build telemetry and detection logic based on threat intelligence and behavioral analytics."}
- {"name":"Python or Go Programming","description":"Proficiency with Python, Go, or similar languages for writing security tools, automation scripts, detection logic, and integrations. Should be capable of contributing production-quality code for security infrastructure."}

### preferred

- {"name":"Open Source Security Experience","description":"Background working with or maintaining open-source projects, particularly experience securing open-source software supply chains. Familiarity with open-source community dynamics and how to balance security with accessibility in open-source contexts."}
- {"name":"Kubernetes and Container Security","description":"Experience securing containerized workloads, implementing Pod Security Policies, managing image scanning, and securing Kubernetes runtime environments. Understanding of container-specific threat models and detection techniques."}
- {"name":"Semgrep or Similar SAST Tools","description":"Experience writing custom semantic analysis rules for vulnerability detection. Proficiency with Semgrep, Checkmarx, or similar static analysis tools for automating security code reviews across multiple repositories."}
- {"name":"Vulnerability Disclosure Program Management","description":"Experience managing vulnerability disclosure programs, triaging security research submissions, and coordinating with external security researchers. Background running bug bounty programs or similar responsible disclosure initiatives."}
- {"name":"Security Observability Platforms","description":"Hands-on experience with extended detection and response (XDR), managed detection and response (MDR), or security orchestration platforms. Familiarity with SOAR automation or security automation frameworks."}
- {"name":"Startup or High-Growth Environment Experience","description":"Background working in fast-paced startup environments where security infrastructure is built from scratch. Experience balancing security rigor with velocity and autonomy-driven culture."}

## Tech stack

### tools

- {"name":"Wiz","description":"Cloud Security Posture Management (CSPM) platform for comprehensive cloud security monitoring, vulnerability detection, and compliance tracking in cloud environments."}
- {"name":"AWS CloudTrail","description":"Comprehensive API logging and monitoring service providing complete visibility into AWS account activity for audit, compliance, and security investigation."}
- {"name":"Semgrep","description":"Static analysis tool for writing custom rules to detect security vulnerabilities and anti-patterns across codebases without false positives."}
- {"name":"Incident Response Tools","description":"Experience with security incident response platforms, playbook automation tools, and case management systems for coordinating complex security incidents."}

### others

- {"name":"AWS IAM","description":"Identity and Access Management service for implementing principle of least privilege, role-based access control, and securing authentication across cloud infrastructure."}
- {"name":"Network Observability","description":"Tools and techniques for capturing and analyzing network traffic patterns to identify anomalous behavior, lateral movement, and data exfiltration attempts."}
- {"name":"Cloud-Native Security","description":"Security practices specific to cloud environments including container security, serverless security, API security, and cloud-specific threat models and detection techniques."}
- {"name":"Threat Intelligence Integration","description":"Ability to incorporate threat intelligence feeds, indicators of compromise, and attacker tactics into detection logic and security operations workflows."}

### databases

- {"name":"Amazon CloudTrail","description":"AWS service for logging API calls and account activity. Central source of truth for audit events and security investigations in AWS environments."}
- {"name":"VPC Flow Logs","description":"Network traffic logging service providing visibility into VPC-level network communication patterns. Essential for threat detection and network-based forensics."}
- {"name":"Amazon Athena","description":"SQL query engine for analyzing large datasets in S3, commonly used to query CloudTrail and VPC Flow Logs for security investigation and threat hunting."}

### languages

- {"name":"Python","description":"Primary language for security automation, detection pipeline development, and tooling. Widely used for writing monitoring scripts, incident response automation, and integration with security platforms."}
- {"name":"Go","description":"High-performance language used for building security infrastructure, particularly for resource-efficient detection agents and cloud-native security tooling that requires concurrency."}

### frameworks

- {"name":"Falcon Logic Engine","description":"Detection rule framework used by CSPM/CNAPP tools like Wiz and Prisma for writing cloud-native detection rules. Understanding of how to build effective detection logic and alert rules."}
- {"name":"Semgrep Rules Framework","description":"Rule definition language for semantic pattern matching and static analysis. Used for writing custom vulnerability detection rules across codebases to identify security anti-patterns."}

## Benefits

### benefits

- {"name":"Fully Remote Work","description":"Work from anywhere with a globally distributed team. PostHog is natively remote with async-first communication and flexible timezone accommodation for all employees."}
- {"name":"Meeting-Free Building Days","description":"Tuesdays and Thursdays designated as meeting-free days to protect deep work and engineering focus time. Prioritizes productivity and uninterrupted building time over constant meetings."}
- {"name":"Equity Compensation","description":"Significant equity stake in PostHog, aligning employee success with company growth. Competitive equity packages designed to share upside of the company's success."}
- {"name":"Transparent Company Operations","description":"Access to complete company transparency including roadmap visibility, board meeting notes, revenue figures, and strategic planning. All employees empowered with information needed to make impactful decisions."}
- {"name":"Professional Development Budget","description":"Annual budget for security certifications, training, conferences, and continuing education. Support for maintaining industry certifications and developing expertise in emerging security domains."}
- {"name":"Health and Wellness Benefits","description":"Comprehensive health insurance, mental health support, and wellness programs. Flexible time off policy with no fixed vacation allowance beyond company holidays."}
- {"name":"Learning and Conference Support","description":"Support for attending security conferences, training programs, and professional development opportunities. Access to resources for staying current with security threats and industry best practices."}
- {"name":"Autonomous Work Environment","description":"High degree of autonomy in decision-making and project prioritization. Ability to define and execute on what matters most without micromanagement or bureaucratic approval processes."}

## Compensation

- **max:** 220000
- **min:** 160000
- **currency:** USD
- **stockOptions:** true

## Interview process

### steps

## Full description
## About PostHog

We [equip every developer to build successful products](https://posthog.com/handbook/why-does-posthog-exist).

We started with open-source product analytics, [launched out of Y Combinator's W20 cohort](https://posthog.com/handbook/story).

We've since shipped [more than a dozen products](https://posthog.com/products), including [a built-in data warehouse](https://posthog.com/docs/data-warehouse), [a customer data platform](https://posthog.com/docs/cdp), and [Max AI](https://posthog.com/max), an AI-powered analyst that answers product questions, helps users find useful session recordings, and writes custom SQL queries.

Next on the roadmap are messaging, customer analytics, ai task creation and coding based on customer data, logs and support analytics.

Our [values](https://posthog.com/handbook/values) are not a poster on the wall full of aspiration. They’ve come from how we really work, day in day out.

PostHog is [open source](https://posthog.com/docs/self-host) product led, and a [default alive](https://paulgraham.com/aord.html) company that is well funded.

## **Things we care about**

* **Transparency:** Everyone can read about our roadmap, how we pay (or even let go of) people, our strategy, and how we work, in our[ public company handbook](https://posthog.com/handbook). Internally, we share revenue, notes and slides from board meetings, and fundraising plans, so everyone has the context they need to make good decisions.
* **Autonomy:** We don’t tell anyone what to do. Everyone chooses what to work on next based on what's going to have the biggest impact on our customers, and what they find interesting and motivating to work on.[ Engineers lead product teams](https://posthog.com/handbook/wide-company) and[ make product decisions](https://posthog.com/handbook/which-products). Teams are flexible and easy to change when needed.
* **Shipping fast:**[ Why not now?](https://posthog.com/handbook/values#why-not-now) We want to build a lot of products; we can't do that shipping at a normal pace. We've built the company around small teams – autonomous, highly-efficient groups of[ cracked engineers](https://posthog.com/founders/cracked-manifesto) who can outship much larger companies because they own their products end-to-end.
* **Time for building:** Nothing gets shipped in a meeting. We're a natively remote company. We default to async communication – PRs > Issues > Slack. Tuesdays and Thursdays are[ meeting-free days](https://posthog.com/handbook/company/culture#were-on-the-makers-schedule), and we prioritize heads down building time over perfect coordination. This will be the most productive job you've ever had.
* **Ambition:** We want to solve big problems. We strongly believe that aiming for the best possible upside, and sometimes missing, is better than never trying. We're optimistic about what's possible and our ability to get there.
* **Being weird:** Weird means redesigning an already world-class website for the 5th time. It means shipping _literally_ every product that relates to customer data. It means building an[ objectively unnecessary developer toy](https://posthog.com/deskhog) with dubious shareholder value. Doing weird stuff is a competitive advantage. And it's fun.

## **Who we're looking for**

We are looking for an expert security generalist to assist with all things security at PostHog. Someone equally adept (and interested!) in building secure libraries, writing semgrep rules, hardening cloud deployments, improving network observability, and leading incident response.

Someone to take the reins of our security operations, build out our detection pipelines, and ensure that when something goes bump in the night, we have the observability to know exactly what happened.   
  
We're a team that's building internal security products and agents - things like agents to automatically triage wiz alerts, automatically review pull requests, automatically assign vulnerability findings to the owning product team.

In this role you’ll:

* **Build from Scratch:** You aren't maintaining someone else's legacy SIEM. You are shaping the security team, culture and tooling for a high-growth, open-source company.
* **Zero Bureaucracy:** We hate meetings. We don't have "Security Committees." You have the autonomy to make changes and move fast.
* **Transparency:** We work in the open. You’ll be able to see (and contribute to) how we handled past incidents, like this[ NPM package compromise](https://www.google.com/search?q=https://github.com/PostHog/posthog/issues/example).
* **Direct Impact:** Your work directly protects the data of thousands of customers. When you improve our security posture, the whole company (and our community) feels it.

## **What you'll be doing**

* **Triage and Tune:** You’ll own our Wiz alerts. You’ll be responsible for turning "noise" into "actionable findings" and ensuring we aren't just staring at a dashboard of issues that don't actually matter. We already get relatively few alerts, and we’d like to even further reduce that to just the ones that matter.
* **Incident detection, response:** You’ll lead the charge on security incidents. Whether it’s a compromised NPM package or a suspicious IAM pattern, you’ll help coordinate the response and lead the post-mortem. You’ll also help build our IR runbooks.
* **Build Observability:** You’ll build detection pipelines, and close our network-based observability gaps. We want to be able to trace network requests and suspicious activity all the way back to specific code paths.
* **Threat Hunting:** You’ll proactively hunt for threats in our AWS environment. You won't just wait for an alert; you'll define what "good" looks like and build the telemetry to prove it.
* **The VDP:** You’ll support our Vulnerability Disclosure Program, triaging reports from researchers and eventually transitioning us toward a formal bug bounty program.
* **Enable the Team:** You’ll support our product squads with threat modeling and secure design reviews. We don't do "Security says no", we do "Security says 'here is how to do this safely.'"
* **Help build our security culture:** Our engineers trust the security team and view security as an enabler. You’ll be a crucial part of helping to continue this excellent (and uncommon) working relationship.

While this is not a Corporate security (MDM, endpoint, device trust) or Supply chain/CI-CD hardening role, in true PostHog style, there are opportunities to work on these as well

## Requirements

* **Cloud Native:** You have 3-5+ years of experience in security engineering with a heavy focus on AWS. You know your way around IAM, VPC logs, and CloudTrail like the back of your hand.
* **Detection Specialist:** You’ve used CSPM/CNAPP tools (like Wiz or Prisma) and, more importantly, you know how to build detection pipelines that engineers actually trust.
* **Battle-Tested:** You’ve led incident response before. You’re calm under pressure and know how to coordinate across teams to contain a threat.
* **High Autonomy:** We don’t have a security SOC. You’ll be building this function from scratch, so you need to be comfortable deciding what’s important and executing on it without a manual.
* **Engineering skills:** You bring strong engineering experience and next to digging into code to understand an exploit or a vulnerability, you can write code with the same proficiency as our product engineers.
* **Communication and attitude:** As mentioned before we don't do "Security says no", we do "Security says 'here is how to do this safely.” This is crucial for us, we need people that want to enable engineers and work with them, not limit them.

We are committed to ensuring a fair and accessible interview process. If you need any accommodations or adjustments, please let us know.

##
