> Markdown version of [/jobs/ext/2704040-security-engineers](https://www.wearedevelopers.com/jobs/ext/2704040-security-engineers). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineers - **Company:** Apollo - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $214,000.0 - $280,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Cloud Computing Security, Cloud Engineering, Cyber Security, Customer Data Management, Identity and Access Management, Intrusion Detection and Prevention, Zero Trust Network Access, Software Safety, Software Engineering, Software Security, Build Management, Casper Suite - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/security-engineer-apollo-research-9801741 ## About the Role * 5+ years in security roles in a hands-on technical capacity (not purely GRC/compliance). You'd need to be able to think structurally about threat modeling and failure modes. You need to be able to read code, understand infrastructure, and evaluate technical controls. * Engineering mindset. You treat security as an engineering problem. You are capable of, and willing to, build custom solutions when the task demands it, rather than relying on 'glueing' together off-the-shelf tools. You prioritize automation and systems-level thinking to scale security, and you are comfortable leveraging AI to accelerate development. * Direct experience with application security, cloud security, or product security. Ideally you've owned or significantly contributed to the security posture of an organisation that handles sensitive customer data. * Influence without authority. You have a track record of building buy-in for security practices and being trusted by non-security people. * Startup pace. You are excited about a fast-moving environment, comfortable with ambiguity and changing priorities, and willing to grind when it matters. Nice-to-haves * Software engineering experience * Experience implementing zero-trust architectures * Experience with sandboxing * Experience with detection engineering * Experience with GRC engineering * Experience with incident response * Hands-on experience with endpoint management (Kandji, Jamf, or similar) * Experience with identity/access management ## Description * Design, build, and operate Apollo's core security controls: identity and access management, infrastructure and cloud security, endpoint management, and incident response. * Build paved roads that make the secure path the default, easy path * Establish and advocate for security practices across Apollo, and build the organizational trust needed for people to adopt them, communicating security decisions and tradeoffs clearly along the way. * Evaluate vendors and tooling, make build-vs-buy calls on security infrastructure, and assess vendor security posture before adoption. * Lead major security projects end to end, from ideation through implementation and rollout. * Collaboratively define and shape the security roadmap and priorities., * Formal AI safety research background. We need security practitioners who can learn the AI safety context, not AI safety researchers who need to learn security. REPRESENTATIVE PROJECTS * Zero trust migration: Design and deliver an incremental path from Apollo's current cloud architecture toward zero trust, including hands-on implementation and deployment reducing the blast radius if any single credential, device, or agent is compromised. * Agentic SOC: Design and build an internal agentic SOC from scratch; automate triage and investigation of security alerts so detection coverage scales with Apollo's growing use of AI agents. * Sandbox hardening: Review Apollo's sandboxing infrastructure; propose and implement changes that improve security while minimizing impact on researcher productivity. * Third-party access review: Implement a lean, streamlined access review process for third-party software that people will actually use. * Incident response: Lead an incident response effort end to end: containment, root cause, and the post-mortem that turns it into a durable fix. * Pentesting tooling: Decide which agentic pentesting solution Apollo will use, and whether to build or buy., * Location: This is an in-person role working out of our London or San Francisco office. We offer flexible working hours and some wfh arrangements. * Visa sponsorship: We sponsor visas in both the UK and US. Sponsorship isn't guaranteed for every role or candidate, but if we make you an offer, we'll work with you to find the right visa route., The Infra and Security team is currently led by Rusheb Shah and consists of Glen Rodgers and Steven Lee. You will work closely with Security Researchers we're hiring for as well as technical staff from the Scheming Research and Product team. You can find our full team here. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Psychological Safety in Software Engineering - Jenny-Margrethe Vej & Alexandra Hou Aldershaab](https://www.wearedevelopers.com/videos/2142-psychological-safety-in-software-engineering-jenny-margrethe-vej-alexandra-hou-aldershaab) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Mutation Testing and Fuzzing in C#](https://www.wearedevelopers.com/videos/703-mutation-testing-and-fuzzing-in-c) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)