SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer

Censys - Remote - Remote - posted 2026-09-22

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Censys maps the internet and delivers real-time Internet intelligence to governments, Fortune 500 companies, and threat intelligence providers. This is a senior, high-ownership security engineering role on a small team with significant autonomy and impact. You will own the identity program end-to-end, including standing access reduction, manual provisioning automation, and non-human identity management. You'll harden and continuously improve the cloud-native environment (GCP-first), focusing on organization policy, IAM least privilege, service account and workload identity hygiene, network segmentation, secrets management, and posture monitoring. You'll partner with SRE on infrastructure-as-code guardrails to enforce security at build time. Vulnerability management is yours to own as a program: asset coverage, risk-based prioritization that weighs real exploitability and exposure, defensible SLAs, hands-on partnership with engineering on remediation, and actionable reporting for leadership. You'll use Censys to maintain an outside-in view of the company's own attack surface. You'll build detection coverage for identity, cloud, and SaaS systems, share in the security escalation rotation, lead or co-lead high-severity incidents, run blameless post-incident reviews, and turn findings into durable fixes. You'll maintain runbooks and exercise tabletops regularly. A significant part of this role involves AI and agentic security: securing the company's AI footprint (non-human and agent identity, MCP server and tool-permission scoping, secrets handling for autonomous workflows, data-flow review, untrusted-input and prompt-injection boundaries) and building agentic security workflows (alert triage and enrichment, evidence collection, access review orchestration, phishing response, posture drift detection) that measurably reduce manual toil. You'll drive security automation and Slack-native operations, meeting people where they already work with ChatOps-driven requests and approvals, self-service paths that are easier than insecure alternatives, and automation over documentation. Note: Application and product security are owned by the SRE team. You'll partner closely on cloud and infrastructure guardrails and contribute security expertise, but you are not expected to own the SDLC or product security roadmap. REQUIREMENTS: - 5+ years in security engineering with real depth in at least two of: identity and access management, cloud security, vulnerability management, detection and response - Hands-on identity operations experience: SSO/SAML/OIDC, MFA and conditional access, device trust, lifecycle automation. Direct Duo and Google Workspace experience is a significant advantage - Experience securing cloud-first or cloud-native environments. GCP preferred; strong AWS or Azure background with genuine interest in going deep on GCP works - Scripting and automation ability (Python, Go, or similar) sufficient to build tooling and API integrations, not only to configure vendor products - Incident response experience as a primary responder or lead on high-severity incidents, including post-incident analysis - Genuine enthusiasm for AI and hands-on experience building with LLMs or agent frameworks (professional, open source, or personal projects all count) - Working familiarity with a prescriptive control framework (ISO 27XXX, CMMC, FedRAMP) and the judgment to implement controls as engineering rather than paperwork - Comfort operating with ambiguity on a lean team: can prioritize independently, say no with a reason, and finish things - Strong written communication for an async, Slack-heavy environment BONUS: - Deep GCP expertise: organization policies, VPC Service Controls, workload identity federation, custom org constraints - Experience securing or building agentic systems, MCP servers, or AI-enabled products - Detection engineering and SIEM or data-pipeline experience - Prior experience on a security team at a security product company - Direct experience taking an organization through CMMC assessment or FedRAMP authorization - SOC 2, ISO 27001, ISO 42001, or GDPR experience and how it intersects with engineering practice - Defining and reporting security metrics to executive stakeholders - Open source contributions, published research, tooling, advisories, or conference talks - Relevant certifications: GCP Professional Cloud Security Engineer, GIAC (GCFA, GCDA, GCSA), or OSCP

Similar roles