Mount Thor is hiring a security engineer to build and operate the systems that protect our infrastructure, customer workloads, and data.
The RoleYou will own security engineering and the CI/CD systems that build, test, and deploy Mount Thor's software. Your responsibilities span software delivery, infrastructure automation, customer data protection, and the engineering controls behind enterprise compliance.
You will write code, implement controls, and work directly with engineers to secure the systems we build and operate. You will also own the technical work behind our SOC 2 Type 2 program and enterprise customer security requirements, from implementing controls to producing evidence that they work.
You will work closely with Platform, Fleet, Network Infrastructure, and Operations, and represent our security architecture in conversations with customers and auditors.
In this role you will- Build security into our infrastructure and products. Review designs, threat model systems, and implement protections across APIs, cloud environments, containers, host systems, and customer workload isolation.
- Own CI/CD and DevOps engineering. Build and operate our build, test, and deployment pipelines, runners, artifact repositories, and infrastructure automation. Own environment provisioning, release workflows, deployment verification, and rollback. Improve delivery speed, reliability, and developer experience. Integrate security scanning, secrets management, artifact provenance, and access controls throughout these systems.
- Own identity, access, and secrets management. Implement least privilege, service identity, privileged access, credential rotation, and access reviews across production and internal systems. Build access controls for both people and software agents.
- Protect customer data throughout its lifecycle. Build controls for data collection, access, encryption, retention, deletion, and logging. Work with engineering and legal partners to translate privacy requirements and customer commitments into enforceable system behavior.
- Build and operate our SOC 2 Type 2 controls. Translate requirements into engineering work, automate evidence collection and control checks, coordinate technical walkthroughs with auditors, and drive findings through remediation. Keep evidence connected to how production systems actually operate.
- Own the engineering response to enterprise security requirements. Lead technical security reviews with customers, explain our architecture and controls, evaluate requirements, and deliver the changes needed to support customer adoption. Keep security documentation and customer commitments accurate.
- Build detection and response capabilities. Establish useful security telemetry, investigate threats, lead security incidents, and turn findings into lasting improvements. Own vulnerability management and coordinate penetration testing and remediation.
- Use agentic engineering throughout the work. Use coding agents to investigate, implement, and validate changes. Build tools that let agents inspect security posture, gather evidence, and perform bounded actions with appropriate authorization and auditability.
What you bring- Strong software engineering skills in Go, Python, Rust, or a similar language, with experience shipping and operating production software.
- Hands-on experience securing cloud infrastructure, APIs, containers, and distributed systems.
- Experience owning production CI/CD systems and infrastructure as code, including diagnosing failed builds and deployments, managing environments, and improving release reliability.
- Experience securing CI/CD pipelines, build infrastructure, deployment workflows, and software dependencies.
- Depth in identity and authorization, secrets management, encryption, network security, and tenant isolation.
- Experience implementing and operating controls for SOC 2 Type 2 or a comparable security assurance program.
- Practical knowledge of privacy and data protection, including access controls, data minimization, retention, and deletion.
- Experience investigating security incidents, prioritizing vulnerabilities, and delivering remediation.
- The ability to explain technical systems clearly to engineers, customers, auditors, and leadership.
- A record of taking broad, ambiguous security work from design through implementation and production operation.
Bonus Skills- Built a security engineering function at an early-stage infrastructure or enterprise software company.
- Secured multi-tenant compute platforms, bare-metal fleets, or customer-managed workloads.
- Worked with macOS, Apple Silicon, host security, secure boot, or hardware-backed credentials.
- Built compliance automation, policy-as-code, or continuous control monitoring.
- Implemented workload identity, artifact signing, build provenance, or isolated build environments.
- Supported enterprise requirements for data residency, customer-managed encryption, or dedicated environments.
- Built security controls for coding agents, computer-use systems, or execution of untrusted code.