Resumo da vaga

Lead Security Engineer

Requisitos e responsabilidades

Conteúdo da vaga extraído em seções para revisão mais rápida.

Responsibilities:

  • Own the security roadmap — craft and execute a strategic security engineering plan that aligns with CodeRabbit’s fast-paced engineering cadence.
  • Boost resilience — champion defense-in-depth tactics: threat modeling, secure design reviews, hardening, CI/CD integration.
  • Be Incident Commander — spearhead security incident response and recovery: triage, resolve, root cause, and turn those learnings into stronger systems.
  • Tools & automation — build or integrate security tooling (SAST, DAST, SIEM, EDR, monitoring) into the developer workflow without slowing delivery.
  • Embed security fluently — partner with engineering and product teams to bring secure practices early into planning and daily workflows.
  • Talent & culture — help to hire, coach, and mentor a scrappy, resilient security engineering team; elevate security awareness across the company.
  • Compliance & policy — establish security standards, frameworks, or processes that evolve as we scale—but remain lean and developer-friendly.

Qualifications:

  • Battle-tested experience: 8+ years in security engineering, incident response, or correlated fields—bonus if you've led through a major production breach or targeted attack.
  • Technical depth: Extensive experience with security across software and infrastructure—threat modeling, pen testing, secure CI/CD pipelines, cloud security, incident response.
  • Strategic mindset: Ability to translate risk into actionables, communicate trade‑offs with engineering/product leadership.
  • Praxis over theory: You’ve taken production systems down (intentionally or unintentionally) and built them back stronger.
  • Security in chaos: Experience in pressure situations—with clarity, direction, and calm.
  • Developer‑centric approach: You can speak fluent dev-tools, empathize with fast-moving teams, and secure them without slowing them down.

Bonus Points:

  • You’ve implemented DevSecOps tooling and orchestrated shift‑left security in developer pipelines.
  • You’ve recovered from (or prevented) a critical security event, and turned that into an engineering culture improvement.
  • Experience in a dev‑tools, SDK, or platform-heavy company.
  • Hacker mindset + operational discipline - pentests, disaster recovery, threat hunting, tooling, cloud environments.
  • Certifications like CISSP, CISM, CEH, or relevant cloud security certs.

Why Join Our Engineering Culture?

  • CodeRabbit is building the next generation of AI-native developer tooling — starting with code review. We combine large language models with deep software engineering context to help teams ship faster, catch more bugs, and make better architectural decisions at scale.
  • We are a high-ownership engineering culture. That means no passive execution, no waiting for perfect tickets, and no narrowly defined task boundaries. Engineers here find problems before they're assigned, use AI as a core part of how they build, ship with judgment, and own outcomes from proposal to production.
  • Our operating philosophy: bias toward action, ship the smallest necessary coherent slice, validate proportional to risk, watch what happens, and make the system better. AI drafts; humans decide. Speed matters, but so does understanding what you ship.
  • This opportunity will be energizing for people who want real ownership, pace, and high standards. It's uncomfortable for people who prefer slow consensus or heavily managed workflows.
  • If you want to build tools that are changing how software gets written, and be held to the standard that the best engineers thrive under; we'd love to talk.

Our Values

  • 🤝 Collaborative Humans: Prioritizing collective intelligence
  • 🚀 Fearless Innovators: Turning obstacles into growth opportunities
  • 💪 Persistent, Passionate Developers: Thriving on complex, long-term challenges
  • 🎯 Impact-Driven Creators: Crafting intuitive tools for developers
  • 🧠 Rapid Learners and Un-learners: Adapting quickly in our fast-paced technological world
Vagas similares

Mantenha uma lista reserva.

Ver stack
FocoEngineeringÁrea da vaga
Sinal de senioridadeLeadNível do candidato
StackCI/CDSkills principais
Localização2 países aceitosElegibilidade

Stack

Use estas tags para comparar vagas remotas similares.

Elegibilidade de localização

Candidatos devem aplicar apenas quando o país do perfil estiver listado aqui.

Seu perfilPaís não definidoEntre para comparar seu país com esta vaga.

Fluxo de contratação

O WithMira mostra a vaga e depois envia candidatos para a aplicação da empresa.

1Confira fit da vaga, stack e elegibilidade de localização no WithMira.
2Abra a página de aplicação da empresa pelo link rastreado.
3Salve a vaga ou assine oportunidades similares antes de sair.