Information Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+13 more
Job description
- Design and automate controls, detection mechanisms, and tooling to improve the Information Security of Algolia’s infrastructure and products
- Research, evaluate, and recommend new Information Security technologies, techniques, and frameworks
- Design, implement, and maintain information security monitoring and remediation systems that move the needle in protecting Algolia’s customers’ data, and protecting Algolia’s systems and data
- Partner with engineering and product teams to integrate Information Security into new features, systems, and development pipelines
- Contribute to improving Information Security standards, processes, and best practices across the company
- Conduct Information Security risk assessments and threat models of core systems, services, and third-party vendors (this does not include answering customer third-party risk assessment questionnaires).
- Participate in and sometimes lead Information Security incident response activities and post-incident analysis
- Support ongoing and emerging Information Security and compliance initiatives (e.g., SOC 2, Type II, ISO 27001, C5, GDPR)
- Manage and enhance Algolia’s public bug bounty and vulnerability disclosure programs, We’ve recently seen an increase in recruitment scams targeting job seekers. To help protect yourself, please keep the following in mind:
- Our open positions may appear on third-party job boards, but the best way to apply safely is directly through our careers page.
- All genuine communication from Algolia will come from an @algolia.com email address. If you receive an email from someone claiming to work at Algolia who does not have an @algolia.com email address, please do not respond or share any personal information.
- We’ll never ask for payments, purchases, or financial details during the hiring process.
Requirements
- 3-6 years of experience in Information Security engineering, infrastructure protection, or related technical domains
- Proficiency in scripting or automation with at least one language (Python, Bash, Go, or similar) is required. Experience with Kubernetes is preferred.
- Strong understanding of Information Security principles for modern cloud environments (AWS, GCP, or Azure) as well as operations in datacenters.
- Strong understanding of, comfort with, and at least three years of experience in operating, configuring, and managing log management / SIEM, threat detection and posture management, endpoint detection and response, SAST, SOAR, CTI, and other table-stakes information security systems with strong preference to at least one year of experience with deep use of Crowdstrike or Obsidian (preferably both).
- Knowledge of common internet Information Security threats, attack vectors, and mitigation strategies
- Solid understanding of computer systems, networks, and low-level protocols from an Information Security perspective
- Experience in incident detection, response, and vulnerability management
- Excellent communication skills, with the ability to explain Information Security risks and concepts to both technical and non-technical audiences
- Clear ability to collaborate with VP of Information security to advise on next steps and to work independently to achieve business outcomes - rather than a ticket based approach.
- Full professional proficiency in English
Nice to Have
- Experience scaling Information Security programs in high-growth SaaS organizations (10,000+ customers, $50-200M ARR range)
- Cloud-specific Information Security certifications or equivalent training (e.g., AWS Security Specialty, GCP Professional Security Engineer)
- Experience with complex secrets management systems such as Hashicorp Vault
- Experience contributing to Information Security communities, such as bug bounty triage, open-source security tools, or Capture the Flag events
- Background in privacy engineering, threat modeling, or secure software design, * GRIT - Problem-solving and perseverance capability in an ever-changing and growing environment.
- TRUST - Willingness to trust our co-workers and to take ownership.
- CANDOR - Ability to receive and give constructive feedback.
Benefits & conditions
The annual base salary compensation range for this role reflects market pay data within this location. The exact compensation offered for this role may vary depending on specific location and job-related knowledge, technical skills, and experience; and is only one part of our Total Rewards philosophy to compensate and recognize employees for their work.
Base Salary Pay Range
£66,080 - £91,800 GBP
About the company
At Algolia, we’re proud to be a pioneer and market leader in AI Search, empowering 17,000+ businesses to deliver blazing-fast, predictive search and browse experiences at internet scale. Every week, we power over 30 billion search requests - four times more than Microsoft Bing, Yahoo, Baidu, Yandex, and DuckDuckGo combined.
In 2021, we raised $150 million in Series D funding, quadrupling our valuation to $2.25 billion. This strong foundation enables us to keep investing in our market-leading platform and serving incredible customers like Under Armour, PetSmart, Stripe, Gymshark, and Walgreens.
At Algolia, Information Security is built into everything we do. It is not an afterthought; it’s a core design and operational principle. Our Information Security team ensures that trust, privacy, and resilience are embedded throughout our infrastructure, products, and internal processes.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.adzuna.co.ukGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
The Overflow: 5 Security and Privacy Tools for Developers
Dev Digest 134 - Where pixels sing?
The 12 Best Jobs for Software Engineers