Qualifications Required: 7 years of hands-on experience in security engineering, cloud security, or DevSecOps with production ownership of security controls and infrastructure Bachelor's degree in Computer Science or related field (or equivalent practical experience) Deep AWS security expertise—IAM, KMS, VPC/network security, GuardDuty, Security Hub, CloudTrail, Config, WAF—including hands-on experience across commercial and GovCloud environments Demonstrated experience in threat detection and threat hunting across cloud, application, and identity telemetry, including detection engineering / detection-as-code Experience operationalizing threat intelligence to drive proactive defense Strong background in logging, monitoring, and security reporting—centralized logging, SIEM design and administration, alerting, dashboards, and metrics Experience implementing and administering security infrastructure and tooling (CSPM, vulnerability management, secrets management, workload/endpoint protection) Application and pipeline security experience—securing CI/CD (GitHub Actions), SAST/DAST/SCA integration, secrets management, and securing containerized/Kubernetes workloads Infrastructure-as-code proficiency with Terraform and containerization tools such as Docker, applied to security guardrails and controls An innovative, adversarial mindset—you anticipate how systems break and automate the defense before it's needed Strong systems thinking and the ability to design scalable, secure, maintainable controls Excellent written and verbal communication skills Comfort operating in autonomous, fast-paced environments Nice to Have: Relevant certifications (AWS Security Specialty, CISSP, OSCP, GCIH/GCIA/GCFA, or similar) Experience with DuploCloud or similar tenant/cloud management platforms Knowledge of compliance frameworks such as SOC 2, FedRAMP, ITAR, or CMMC Experience building security for PLM, PDM, or hardware/manufacturing industry software Background supporting compliance-driven or regulated (GovCloud, on-premises) deployments Incident response, digital forensics, or purple-team experience Familiarity with observability tooling such as Datadog, PostHog, or Sentry, and event-driven systems (NATS, Redis, Kafka) PostgreSQL and Kubernetes operational familiarity sufficient to secure and reason about those workloads How We Build We don't just ship features. We value: Adversarial intuition — understanding how systems fail and how attackers think before building the defense Detection over hope — coverage you can measure, tune, and trust, expressed as code Precision in communication — clear control design produces reliable, auditable systems Pattern recognition — knowing when to abstract, automate, or simplify Operational discipline — building controls that are observable, resilient, and self-healing Intellectual curiosity — continuously improving how we secure and scale We optimize for engineers who can build security that fades into the background—enabling teams to deploy daily with confidence, not friction.