About the job
We are seeking a dedicated Internal Security Engineer to join our team at MazeHQ. As a pivotal member of our internal security department, you will have the unique opportunity to construct our security infrastructure, develop essential tools, and implement a comprehensive compliance program from the ground up. This is an exciting chance to be among the founding team members of a well-funded startup at the forefront of generative AI and cybersecurity, where you will lay the groundwork for our security framework that supports our rapid growth.
Your responsibilities will include managing security tools and monitoring systems, reinforcing cloud infrastructure security, preparing for compliance, and formulating scalable security policies. Your effectiveness will be gauged by the strength of our security measures, our preparedness for enterprise customer demands, and your capacity to facilitate the engineering team’s agility without sacrificing security. This role is ideal for a proactive security engineer who has experience developing security programs within startups, possesses a pragmatic approach to balancing security with speed, and is eager to design security infrastructure using advanced tools and AI-assisted workflows.
Your Key Responsibilities:
- Develop Security Tools and Monitoring: Create and execute extensive security monitoring, logging, and alerting systems to enhance visibility across our infrastructure and applications, serving as our primary defense.
- Enhance Cloud Infrastructure Security: Strengthen our AWS infrastructure by applying best practices, implement infrastructure-as-code security controls using Terraform, and ensure a secured cloud environment by design.
- Lead Compliance Initiatives: Spearhead preparation for SOC2, ISO27001, and other compliance frameworks, crafting documentation and controls that support enterprise sales.
- Formulate Security Policies: Establish practical security policies and procedures that empower the team to operate efficiently while maintaining robust security standards, avoiding unnecessary complexities.
- Automate Security Operations: Create security automation and tools using coding and scripting, harnessing AI-assisted development to expedite implementation while upholding high quality.
- Oversee Vendor Security: Perform security evaluations of third-party vendors and tools to ensure our supply chain security meets enterprise standards.
- Facilitate Incident Response: Develop incident response strategies and documentation to ensure swift and effective reactions to security incidents.
