> Markdown version of [/jobs/ext/1349765-security-engineer](https://www.wearedevelopers.com/jobs/ext/1349765-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Neuralink Corp. - **Location:** South San Francisco, CA, United States - **Salary:** $99,000.0 - $185,000.0 - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Amazon Web Services, Apple Mac Systems, Software System Penetration Testing, Code Review, Cyber Security, Linux, Firmware, Hardware Security Module, Identity and Access Management, Intrusion Detection and Prevention, Cloud Services, Secure Coding, Security Information and Event Management, Software Vulnerability Management, Base Calling Interface, Cloud Platform System, Application Specific Integrated Circuits, Software Security, Safety Critical Systems, Kubernetes, Security Orchestration, Automation & Response - **Published:** July 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=dc9617141619eb6a ## About the Role * Hands-on experience in security engineering, security operations, or product/application security - or evidence of exceptional ability in lieu of traditional experience or qualifications. * Strong technical fundamentals: operating system internals (Linux, macOS, Windows), networking, and authentication/authorization. * Experience detecting, investigating, and responding to security incidents. * An attacker's mindset paired with a builder's bias: you find problems and then fix them, independently and end-to-end. * Clear communication with both technical and non-technical stakeholders, and sound judgment under pressure., * Product security depth: threat modeling, secure code review at scale, or penetration testing of web, mobile, or embedded targets. * Experience securing cloud environments (AWS or similar), Kubernetes/containers, and infrastructure-as-code. * Embedded, firmware, or hardware security experience - especially for medical devices or other safety-critical systems. * Familiarity with security in regulated environments (FDA premarket cybersecurity guidance, HIPAA, SOC 2). * Detection engineering or security automation experience across a modern SecOps stack. * CTF, bug bounty, or public security research track record, or relevant certifications (e.g., OSCP). * Experience mentoring engineers or independently owning security processes end-to-end. ## Description As a Security Engineer on this team, you will defend our fleet, networks, and cloud by building detections, responding to incidents, and hardening systems. You will threat model, review, and test the software we ship, from firmware and mobile apps to cloud services. You will work as an individual contributor embedded with the Software team, close to the engineers who build these systems, with wide latitude to find the highest-impact security problems and fix them., * Run and improve security operations: triage and investigate alerts across endpoint, identity, network, email, and cloud, and lead incident response from detection through root cause and remediation. * Build and tune detections and response automation (SIEM, EDR, SOAR), and write tooling that eliminates manual security work and scales coverage as the company grows. * Partner with IT to harden corporate security infrastructure: SSO/MFA and identity lifecycle, endpoint management, email security, and vulnerability management. * Perform threat modeling and secure design and code reviews for Neuralink products - implant firmware, surgical robotics, BCI, infrastructure, ASIC, clinical and consumer-facing applications, and cloud backends. * Find vulnerabilities before attackers do: run internal security assessments and penetration tests, triage external vulnerability reports, and drive remediation with owning teams. * Establish and improve security standards, incident response runbooks, and secure development practices, partnering cross-functionally with software, infrastructure, IT, and compliance teams. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Your Kubernetes Node Is Not a Server: Rethinking the OS Layer](https://www.wearedevelopers.com/videos/100315-your-kubernetes-node-is-not-a-server-rethinking-the-os-layer) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)