Monitor, investigate, and respond to security threats across CircleCI’s cloud and application environments
Use security and AI-assisted tooling to improve detection and triage
Participate in security risk assessments, incident response, post-incident reviews, and rotating on-call support
Turn findings into stronger security controls and processes
Build and maintain security tooling, controls, and automation across cloud, application, and CI/CD environments
Identify vulnerabilities and configuration risks
Contribute to security runbooks and compliance requirements
Incorporate AI-powered security tools into day-to-day workflows
Evaluate emerging technologies that can improve detection, response, and automation
Stay current on AI-specific security threats and contribute to responsible approaches for using AI in security operations
Partner with Engineering teams to understand security needs and provide practical guidance
Translate technical risks into clear, actionable recommendations
Contribute to security roadmap planning, technology evaluations, and team documentation
Build strong relationships across Security and Engineering
Requirements
3+ years of security engineering or security operations experience, or equivalent demonstrated expertise
Hands-on experience with cloud, application, and CI/CD security, ideally in AWS, GCP, or Azure environments
Experience with security incident response and common security tooling, including EDR, CNAPP, SASE, vulnerability scanners, and log analysis
Ability to build and maintain security automation and tooling, with experience in Go, Python, or Terraform
Strong security judgment and problem-solving skills, with the ability to assess risk, make recommendations, and take action when information is incomplete
Hands-on experience using AI/ML-powered security tools in a production environment
Understanding of where AI can improve security workflows and where human judgment remains essential
Familiarity with AI-specific threat categories such as prompt injection, model supply chain risks, and LLM abuse patterns
Experience securing developer platforms, SaaS environments, or CI/CD infrastructure
Relevant certifications such as CEH, AWS Security Specialty, Security+, or equivalent are nice to have
Contributions to team process improvement, security runbook development, or internal knowledge sharing are nice to have
Benefits
Reasonable accommodation for individuals with disabilities during the application or interview process and to perform essential job functions
Senior Security Operations Engineer monitoring incidents and leading forensics for Samsara’s IoT - connected operations platform. Building security automation and supporting insider - threat investigations.
Senior SOC analyst leading threat detection, investigations, and incident response for Financeit, a Canadian point - of - sale financing provider. Building its new SOC’s automation, AI - threat coverage, and operational standards.
Security Operations Engineer securing Tailscale’s software for safe device and network connections. Managing endpoints, identity access, platforms, automation, and data loss prevention.
Security Operations Engineer securing Tailscale’s networking platform through device, identity, access, and vulnerability management. Supporting distributed teams and automating security operations across core business systems.
Incident Response Security Engineer strengthening detection, automation, and incident management for ClickHouse’s real - time analytics cloud platform. Handling security events across products and services.
Lead cybersecurity strategy, governance, and operations at Alberta Innovates. Oversee risk management, incident response, and team leadership in a hybrid role based in Edmonton.