Security Operations EngineerAbout the TeamThe Security Operations team plays a critical role in protecting CircleCI's infrastructure, product, and customer data against an evolving threat landscape. From incident response to hardening our cloud and CI/CD environments, the team works closely with engineering to keep CircleCI secure, resilient, and ready for what's next.
About the RoleAs a Security Operations Engineer, you'll play a key role in protecting CircleCI's infrastructure, product, and customer data against an evolving threat landscape increasingly shaped by AI-driven attacks and AI-augmented defenses. This intermediate-level role offers the opportunity to take meaningful ownership of security challenges, work closely with Engineering as a trusted security partner, and expand your impact across the organization. You'll contribute to our security roadmap while leveraging AI tooling to advance how we detect, respond to, and automate security threats across CircleCI.
What You'll Do:Threat Detection & Incident Response- Monitor, investigate, and respond to security threats across CircleCI's cloud and application environments, using security and AI-assisted tooling to improve detection and triage.
- Participate in security risk assessments, incident response, post-incident reviews, and rotating on-call support, turning findings into stronger controls and processes.
Security Engineering & Architecture- Build and maintain security tooling, controls, and automation across cloud, application, and CI/CD environments, following established security patterns and best practices.
- Identify vulnerabilities and configuration risks, contribute to security runbooks and compliance requirements, and develop a growing understanding of CircleCI's security architecture.
AI & Security- Incorporate AI-powered security tools into day-to-day workflows and help evaluate emerging technologies that can improve detection, response, and automation.
- Stay current on AI-specific security threats and contribute to responsible approaches for using AI in security operations.
Cross-Team Partnership & Ownership- Partner with Engineering teams to understand security needs, provide practical guidance, and translate technical risks into clear, actionable recommendations.
- Contribute to security roadmap planning, technology evaluations, and team documentation while building strong relationships across Security and Engineering.
What You'll Bring:- 3+ years of security engineering or security operations experience, or equivalent demonstrated expertise.
- Hands-on experience with cloud, application, and CI/CD security, ideally in AWS, GCP, or Azure environments.
- Experience with security incident response and common security tooling, including EDR, CNAPP, SASE, vulnerability scanners, and log analysis.
- Ability to build and maintain security automation and tooling, with experience in languages or technologies such as Go, Python, or Terraform.
- Strong security judgment and problem-solving skills, with the ability to assess risk, make recommendations, and take action when information is incomplete.
- Hands-on experience using AI/ML-powered security tools in a production environment, with an understanding of where AI can improve security workflows and where human judgment remains essential.
Bonus Skills (Nice to Have)- Familiarity with AI-specific threat categories (prompt injection, model supply chain risks, LLM abuse patterns).
- Experience securing developer platforms, SaaS environments, or CI/CD infrastructure.
- Relevant certifications: CEH, AWS Security Specialty, Security+, or equivalent.
- Contributions to team process improvement, security runbook development, or internal knowledge sharing.
Canada Base Pay Range
$127,500-$159,500 CAD