> Markdown version of [/jobs/ext/2722658-security-engineer](https://www.wearedevelopers.com/jobs/ext/2722658-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Lambda Inc. - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Training Data, Artificial Intelligence, Code Review, Cyber Security, Customer Data Management, Data Centers, Linux, Digital Assets, Hyper-V, Intrusion Detection Systems, Python (Programming Language), Kernel-Based Virtual Machine, PCI Data Security Standards, Security Information and Event Management, Software Vulnerability Management, Xen Servers, Large Language Models, Machine Learning Operations, Security Orchestration, Automation & Response - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/security-engineer-lambda-3-8057582 ## About the Role * 5+ years of demonstrated security engineering experience, either directly as a security engineer or as an engineer driving security outcomes. We also welcome equivalent backgrounds: significant formal security training paired with strong engineering experience. * A track record of working across security domains; for example, shipping detection work in one role and architecture, platform, or vulnerability management work in another. We don't expect mastery of every domain; we do expect demonstrated breadth and eagerness to learn. * Thrives in high-speed, high-ambiguity startup environments where priorities shift regularly and structure must be built while executing. * Strong hands-on Linux experience that showcases your ability to protect both our applications and the cloud we build underneath them. * Comfortable solving problems in Python, Go, or a similar language, with the discipline to ship production-grade tooling rather than only one-off scripts. * Excellent collaboration with technical teams both with and without authority (we're all on the same team!). Nice to Have * You've led or developed a meaningful component of a security program (detection & response, security architecture, platform/tooling, vulnerability management, GRC operations, etc.). * Experience driving or providing significant evidence for compliance audits such as SOC 2, ISO 27001, PCI-DSS, HIPAA/HITECH, or FedRAMP. * Significant experience operating large-scale production services (e.g., SRE across thousands of hosts) or with virtualization at scale (KVM, Hyper-V, Xen). * You've built or deployed critical security infrastructure such as SIEM, SOAR, EDR, IDS/IPS, or canary/honeypot systems. * Experience with AI/ML infrastructure security, model security, or protecting high-value computational workloads. * Enthusiasm about leveraging direct access to state-of-the-art LLMs to push security operations beyond the status quo, including through automated triage, intelligent alert correlation, AI-assisted code review. ## Description *Note: This position requires presence in our San Francisco/San Jose/Bellevue office location 4 days per week; Lambda's designated work from home day is currently Tuesday., Lambda Security protects some of the world's most valuable digital assets: training data, model weights representing immense computational investments, and the sensitive inputs required to leverage best-of-breed AI models. We're responsible for securing every byte that powers breakthrough artificial intelligence., * Build and Tune Detections: Develop and refine detection content across our SIEM and EDR to catch threats targeting customer data, model weights, and infrastructure. * Respond to Incidents: Participate in on-call, lead investigations end-to-end, and turn each incident into automation, playbooks, or controls that prevent the next one. * Harden Systems Directly: Remediate vulnerabilities and security findings in production, partnering with engineering teams when fixes cross team boundaries. * Review Architectures and Code: Provide actionable security feedback on high-level designs and individual changes, and turn recurring review patterns into reusable standards. * Build Security Tooling: Ship Python or Go services that automate evidence collection, vulnerability triage, and other toil, using Lambda's hosted LLMs where they meaningfully accelerate the work. * Partner Across Engineering: Work with Product Engineering, Data Center Operations and Engineering, IT, and Legal to land security improvements at the moments they're cheapest to adopt. * Balance Strategic and Tactical: Recognize when to invest in a long-term fix versus when "good enough" is exactly that, and bias toward measurable forward progress. ## Related Videos - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)