Security Engineer

PostHog
United Kingdom
Workplace: RemoteFull timeFunction: CybersecurityExperience: 3+ yearsSkills: ["Incident response coordination","Calm under pressure","Autonomy","Cross-team communication","Engineering enabling mindset"]

Own PostHog’s security operations for a natively remote, open-source product company. Triage and tune Wiz alerts, lead incident detection and response (including post-mortems and IR runbooks), and build detection pipelines and network observability so suspicious activity maps back to code paths. Proactively threat hunt in AWS, support the Vulnerability Disclosure Program, and enable product teams with threat modeling and secure design reviews.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
PostHog
PostHog
1 day ago

Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 44 minutes agoStatus: Live

Job Summary

Own PostHog’s security operations for a natively remote, open-source product company. Triage and tune Wiz alerts, lead incident detection and response (including post-mortems and IR runbooks), and build detection pipelines and network observability so suspicious activity maps back to code paths. Proactively threat hunt in AWS, support the Vulnerability Disclosure Program, and enable product teams with threat modeling and secure design reviews.
Location: United Kingdom
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Triage and tune Wiz alerts to turn noise into actionable findings and reduce irrelevant dashboard issues.
  • •Lead incident detection and response, coordinate response efforts, run post-mortems, and help build IR runbooks.
  • •Build detection pipelines and close network-based observability gaps to trace suspicious activity back to code paths.
  • •Proactively threat hunt in AWS by defining what “good” looks like and validating it through telemetry.
  • •Support the Vulnerability Disclosure Program and enable product squads with threat modeling and secure design reviews.

Key Requirements

  • •3-5+ years of security engineering experience with a heavy focus on AWS, including hands-on knowledge of IAM, VPC logs, and CloudTrail.
  • •Experience with CSPM/CNAPP tools (e.g., Wiz or Prisma) and ability to build detection pipelines engineers trust.
  • •Proven incident response leadership; calm under pressure and able to coordinate across teams to contain threats.
  • •Comfort building security operations from scratch with high autonomy (no existing security SOC).
  • •Strong engineering skills, including writing code to understand exploits or vulnerabilities.
Experience:3+ years
Skills:Incident response coordinationCalm under pressureAutonomyCross-team communicationEngineering enabling mindset
Tech Stack:AWSIAMVPC logsCloudTrailWizPrismaCSPMCNAPPSemgrepSIEMSlackNPMTelemetrySQL

Company Brief

PostHog
PostHog provides an open-source product analytics and developer platform that combines analytics, session replay, feature flags, A/B testing, and data warehousing to help engineering and product teams build and optimize products.
Industry: Developer Tools
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: San Francisco, United States
Founded: 2020
Glassdoor
Glassdoor: 4.3
WebsiteLinkedInGlassdoor