Base Salary
$180k - $240k/yr
Responsibilities
- Own the detection lifecycle by translating threat models, incidents, and attacker behavior into telemetry requirements and detections-as-code.
- Design and operate security telemetry pipelines across GCP/AWS, Kubernetes, and the LangSmith/LangGraph control plane.
- Build investigation and threat-hunting tools for proactive hunting, evidence collection, incident scoping, and containment.
- Develop internal AI agents and automation for alert triage, finding enrichment, evidence gathering, and routine security operations with human-in-the-loop controls.
- Lead security incident response, participate in the incident on-call rotation, and drive postmortems and remediation.
- Partner with Product Security to convert threat models and vulnerability findings into production monitoring and secure-design improvements.
Requirements
- 5+ years of security engineering experience with meaningful detection engineering, security operations, or incident response experience.
- Strong production software engineering skills in Python or Go; TypeScript experience is a plus.
- Experience with GCP or AWS logging, Kubernetes audit and runtime telemetry, workload identity, and actionable detection development.
- Ability to model attacker behavior, perform threat hunting, test detection coverage, and distinguish useful signals from noise.
- Hands-on incident response experience, including on-call participation, incident leadership, and postmortems.
- Experience building reliable automation or developer-facing systems with APIs, workflows, instrumentation, quality evaluation, and production operation.
- Ability to identify users and requirements, prioritize high-leverage problems, define success, and ship iteratively.
- Experience building or operating AI agents for security workflows is preferred.
- Experience using AI tooling for security investigations and engineering, understanding AI threats and adversarial testing, or securing LLM and agent workloads is preferred.
- Exposure to SOC 2 or ISO 27001 monitoring and evidence automation is preferred.
- Experience with infrastructure as code such as Terraform or Helm is preferred.
- Experience securing SaaS and self-hosted or air-gapped deployments is preferred.
Benefits
- Medical, dental, and vision coverage.
- Flexible vacation.
- 401(k) plan.
- Meals on in-office days in the US.
- Role is located in San Francisco or NYC and includes participation in an incident on-call rotation.
Categories
About LangChain
At LangChain, our mission is to make intelligent agents ubiquitous. We build the foundation for agent engineering in the real world, helping developers move from prototypes to production-ready AI agents that teams can rely on. What began as widely adopted open-source tools has grown into a platform for building, evaluating, deploying, and operating agents at scale. LangChain provides the agent engineering platform and open source frameworks developers need to ship reliable agents fast. LangSmith offers observability, evaluation, and deployment for rapid iteration. Our open source frameworks, LangGraph, LangChain, and Deep Agents, help developers build agents with speed and granular control. LangSmith is trusted by leading AI teams at Zip, Vanta, Klarna, Workday, Linkedin, Cloudflare, and more.
