4 hours ago
Remote, United Kingdom or Remote, EMEAMid Level / Senior
Responsibilities
- Own and tune Wiz security alerts to reduce noise and produce actionable findings.
- Lead security incident detection and response, coordinate containment, and develop post-incident reviews and IR runbooks.
- Build security detection pipelines and improve network-based observability to trace suspicious activity to specific code paths.
- Conduct proactive threat hunting in the AWS environment and define telemetry for expected behavior.
- Support the Vulnerability Disclosure Program and help transition toward a formal bug bounty program.
- Assist product squads with threat modeling and secure design reviews.
- Build internal security products and agents for alert triage, pull-request review, and vulnerability assignment.
- Help strengthen PostHog’s security culture by enabling engineers to build securely.
Requirements
- 3–5+ years of security engineering experience with a heavy focus on AWS.
- Strong practical knowledge of IAM, VPC logs, and CloudTrail.
- Experience using CSPM/CNAPP tools such as Wiz or Prisma and building trusted detection pipelines.
- Previous leadership of incident response activities and cross-team threat coordination.
- Ability to build the security function and prioritize work autonomously without a security SOC or detailed manual.
- Strong software engineering skills, including the ability to inspect code to understand exploits and vulnerabilities and write code at product-engineering proficiency.
- A collaborative, enabling communication style focused on helping engineers implement security safely.
Benefits
- Natively remote work with async communication and meeting-free Tuesdays and Thursdays.
- High autonomy, direct impact, and the opportunity to build security operations and tooling from scratch.
- Open-source company culture with transparency into strategy, incidents, compensation practices, and ways of working.
- Dedicated heads-down building time and a small-team environment focused on shipping quickly.
About PostHog
PostHog builds an open‑source, all‑in‑one platform for product teams and engineers that combines product analytics, session recordings, feature flags, A/B testing, a built‑in data warehouse, and AI‑assisted analysis. The company offers self‑hosted and hosted plans (US/EU) with SOC 2, GDPR, and HIPAA compliance. Founded in 2020 in San Francisco after Y Combinator’s W20 cohort, PostHog monetizes through paid cloud and enterprise subscriptions.
