Skip to main content
Sourcegraph

Security Engineer [IC3]

RemoteUTC-8…UTC-2
Published
Role
Security
$144k+/yr
Check eligibility

Open to UTC-8…UTC-2 · Prefers EUROPE. Set where you work from to check your eligibility.

The listing prefers candidates in Europe.

No BS summary

IC3 security generalist focused on security operations for SaaS, application security, infrastructure security, compliance, incidents, and on-call. Must have Go, Elastic stack, GCP, SIEM alert review, and defensive security automation experience. Remote almost anywhere, with preferred Europe location and at least 10 hours/week overlap with EST.

Core skills

GoElastic stackGCP

Required skills

SIEM

Optional skills

TypeScriptTerraformKubernetes

What you'll do

  • Build security into Sourcegraph product offerings.
  • Work on security operations.
  • Maintain and improve the monitoring and alerting stack.
  • Participate in on-call rotations.
  • Respond to security incidents.
  • Perform application security testing.
  • Work on bug bounty programs.
  • Conduct security reviews for application and infrastructure security.
  • Proactively improve the security of Sourcegraph's codebase, product, cloud, and customers' on-premise deployments.
  • Get onboarded to the alerting and monitoring stack.
  • Discover, fix, and mitigate infrastructure vulnerabilities by updating libraries, base images, and analyzing containers.
  • Maintain internal systems such as automations that assist in alert triaging.
  • Work with other teams to triage, troubleshoot, and mitigate customer concerns and questions about Sourcegraph's security.
  • Enhance application security with audits, best practices, code fixes, and continuous education.
  • Perform reactive incident response if a security event occurs.
  • Work with your manager on a career plan with actionable goals.
  • Perform proactive research to detect new attack vectors.
  • Perform threat modeling for existing and future applications.
  • Assess and integrate new tools and technologies to improve operational efficiencies.
  • Help maintain compliance with SOC 2, ISO 27001, and GDPR standards.

What they require

  • Practical experience reviewing SIEM alerts and participating in on-call rotations.
  • Practical experience securing SaaS applications as a security generalist, including infrastructure security, application security, and/or compliance.
  • Experience with Go, including writing and maintaining internal tooling along with code reviews.
  • Experience with Elastic stack and GCP.
  • Experience using and automating a wide range of defensive security tools.
  • Experience working across engineering teams to secure projects across the organization.
  • High agency.
  • Effective written communication and documentation skills.
  • Preferred: Experience developing software as an engineer, writing code and contributing directly to applications.
  • Preferred: Experience working in a startup environment.
  • Preferred: Experience securing AI products.
  • Working hours must overlap with EST for at least 10 hours/week.

Benefits

  • Above-market salaries.
  • Open and transparent compensation philosophy and pay bands visible to every Sourcegraph teammate.
  • Competitive cash compensation.
  • Meaningful equity.
  • Generous perks and benefits.
  • Globally distributed team.
  • Welcome to request additional conversations with anyone you would like to meet during the interview process.

Sourcegraph brings clarity and control to complex codebases, giving engineering organizations visibility across their systems, context for AI agents, and the ability to execute coordinated code changes at scale. Its products include Code Search, Deep Search, MCP, and Agentic Batch Changes.

Software DevelopmentEnterprisesourcegraph.com

Details

Apply routeGreenhouse
$144k+/yr