Own the security operations layer for our customer-side deployments.
Lead CVE response across the fleet, ship supply-chain integrity controls (SBOM, signed images, provenance), co-page with InfoSec on security incidents, enforce secure-config baselines.
Requirements
Fluent in English.
5+ years in SRE, Production Engineering, or DevOps, with a record of shipping tooling.
Observability stack in production: Prometheus, Grafana, OpenTelemetry, Loki, Tempo, Signoz.
Infrastructure as code: Terraform, Ansible (or close equivalents).
Proficient in Python and/or Golang for tooling and automation.
Security mindset: you treat secure-SDLC, CVE response, and supply-chain integrity as reliability properties of the shipped artifact, not as someone else's job.
Strong written communication skills: runbooks, post-mortems, and customer-facing incident comms are core deliverables of this role.
Comfortable operating with high autonomy in an ambiguous, fast-paced environment — and disciplined enough to defend the team's scope when work tries to spill in.
Solid Linux internals, networking debug, and distributed-systems fundamentals.
Strong plus: cloud or application security background (AppSec, K8s security, supply chain — SBOM, cosign, SLSA). At least one of our early hires must bring this; if it's you, flag it.
Experience operating LLM / model-serving stacks in production.
Experience with multi-cloud or on-prem hybrid customer environments (AWS, GCP, Azure, sovereign clouds).
Open-source contributions, particularly in SRE, observability, or security tooling.