Live opening · Posted 26 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
At Atlan, Security Engineers ship products. If your instinct when you see a recurring finding is to build the system that eliminates it permanently - not file another ticket - this role is for you. You'll own AppSec and cloud security automation across a platform used by 450+ enterprise customers in regulated industries, with AI as your primary force multiplier.
Responsibilities:
AI-Powered Security Agents: Build AI agents that handle vulnerability triage, automated security reviews of PRs, and initial incident forensics at scale. Hands-on production experience is required.
Application Security: Lead threat modelling, security reviews, and risk assessments across web applications, APIs, and services. Work with engineering to eliminate vulnerability classes end-to-end, writing or reviewing fixes, not just filing findings.
Cloud Security Automation: Build systems that automatically detect and remediate security gaps across AWS (primary), GCP, and Azure configuration drift, IAM misconfigurations, vulnerable dependencies, and exposed secrets. You own this end-to-end, not just the detection layer.
Developer Security (Shift-Left): Embed security into the developer workflow. Integrate SAST/SCA and secrets detection into CI/CD, making "Secure by Default" the path of least resistance for every engineer on the platform.
Requirements:
4-6 years of experience in a cloud-native SaaS environment, with demonstrated depth in at least two security domains. AppSec and cloud security are the preferred combination. Prior experience at a product startup or high-growth company is valued.
Hands-on AI development experience. You've integrated LLMs into production security workflows, triage pipelines, automated review agents, and detection systems.
Root-cause orientation: Identify the vulnerability class, build the guardrail, and eliminate the pattern permanently.
Deep AWS expertise across IAM, VPCs, and Kubernetes with practical knowledge of how these are attacked and defended in real environments. GCP and Azure familiarity is a plus.
End-to-end ownership: You identify the gap, build the fix, and close the loop without waiting for a separate execution team.
Experience
3-6 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.