AI summary: Security engineer who builds and maintains security infrastructure and practices for PostHog's product analytics and data platform.
We equip every developer to build successful products.
We started with open-source product analytics, launched out of Y Combinatorâs W20 cohort.
Weâve since shipped more than a dozen products, including a built-in data warehouse, a customer data platform, and Max AI, an AI-powered analyst that answers product questions, helps users find useful session recordings, and writes custom SQL queries.
Next on the roadmap are messaging, customer analytics, ai task creation and coding based on customer data, logs and support analytics.
Our values are not a poster on the wall full of aspiration. Theyâve come from how we really work, day in day out.
PostHog is open source product led, and a default alive company that is well funded.
Transparency: Everyone can read about our roadmap, how we pay (or even let go of) people, our strategy, and how we work, in our public company handbook. Internally, we share revenue, notes and slides from board meetings, and fundraising plans, so everyone has the context they need to make good decisions.
Autonomy: We donât tell anyone what to do. Everyone chooses what to work on next based on whatâs going to have the biggest impact on our customers, and what they find interesting and motivating to work on. Engineers lead product teams and make product decisions. Teams are flexible and easy to change when needed.
Shipping fast: Why not now? We want to build a lot of products; we canât do that shipping at a normal pace. Weâve built the company around small teams â autonomous, highly-efficient groups of cracked engineers who can outship much larger companies because they own their products end-to-end.
Time for building: Nothing gets shipped in a meeting. Weâre a natively remote company. We default to async communication â PRs > Issues > Slack. Tuesdays and Thursdays are meeting-free days, and we prioritize heads down building time over perfect coordination. This will be the most productive job youâve ever had.
Ambition: We want to solve big problems. We strongly believe that aiming for the best possible upside, and sometimes missing, is better than never trying. Weâre optimistic about whatâs possible and our ability to get there.
Being weird: Weird means redesigning an already world-class website for the 5th time. It means shipping literally every product that relates to customer data. It means building an objectively unnecessary developer toy with dubious shareholder value. Doing weird stuff is a competitive advantage. And itâs fun.
We are looking for an expert security generalist to assist with all things security at PostHog. Someone equally adept (and interested!) in building secure libraries, writing semgrep rules, hardening cloud deployments, improving network observability, and leading incident response.
Someone to take the reins of our security operations, build out our detection pipelines, and ensure that when something goes bump in the night, we have the observability to know exactly what happened.
Weâre a team thatâs building internal security products and agents - things like agents to automatically triage wiz alerts, automatically review pull requests, automatically assign vulnerability findings to the owning product team.
In this role youâll:
Build from Scratch: You arenât maintaining someone elseâs legacy SIEM. You are shaping the security team, culture and tooling for a high-growth, open-source company.
Zero Bureaucracy: We hate meetings. We donât have âSecurity Committees.â You have the autonomy to make changes and move fast.
Transparency: We work in the open. Youâll be able to see (and contribute to) how we handled past incidents, like this NPM package compromise.
Direct Impact: Your work directly protects the data of thousands of customers. When you improve our security posture, the whole company (and our community) feels it.
Triage and Tune: Youâll own our Wiz alerts. Youâll be responsible for turning ânoiseâ into âactionable findingsâ and ensuring we arenât just staring at a dashboard of issues that donât actually matter. We already get relatively few alerts, and weâd like to even further reduce that to just the ones that matter.
Incident detection, response: Youâll lead the charge on security incidents. Whether itâs a compromised NPM package or a suspicious IAM pattern, youâll help coordinate the response and lead the post-mortem. Youâll also help build our IR runbooks.
Build Observability: Youâll build detection pipelines, and close our network-based observability gaps. We want to be able to trace network requests and suspicious activity all the way back to specific code paths.
Threat Hunting: Youâll proactively hunt for threats in our AWS environment. You wonât just wait for an alert; youâll define what âgoodâ looks like and build the telemetry to prove it.
The VDP: Youâll support our Vulnerability Disclosure Program, triaging reports from researchers and eventually transitioning us toward a formal bug bounty program.
Enable the Team: Youâll support our product squads with threat modeling and secure design reviews. We donât do âSecurity says noâ, we do âSecurity says âhere is how to do this safely.ââ
Help build our security culture: Our engineers trust the security team and view security as an enabler. Youâll be a crucial part of helping to continue this excellent (and uncommon) working relationship.
While this is not a Corporate security (MDM, endpoint, device trust) or Supply chain/CI-CD hardening role, in true PostHog style, there are opportunities to work on these as well
Cloud Native: You have 3-5+ years of experience in security engineering with a heavy focus on AWS. You know your way around IAM, VPC logs, and CloudTrail like the back of your hand.
Detection Specialist: Youâve used CSPM/CNAPP tools (like Wiz or Prisma) and, more importantly, you know how to build detection pipelines that engineers actually trust.
Battle-Tested: Youâve led incident response before. Youâre calm under pressure and know how to coordinate across teams to contain a threat.
High Autonomy: We donât have a security SOC. Youâll be building this function from scratch, so you need to be comfortable deciding whatâs important and executing on it without a manual.
Engineering skills: You bring strong engineering experience and next to digging into code to understand an exploit or a vulnerability, you can write code with the same proficiency as our product engineers.
Communication and attitude: As mentioned before we donât do âSecurity says noâ, we do âSecurity says âhere is how to do this safely.â This is crucial for us, we need people that want to enable engineers and work with them, not limit them.
We are committed to ensuring a fair and accessible interview process. If you need any accommodations or adjustments, please let us know.