Security Generalist
Location: Remote (Global)
At PostHog, we're on a mission to equip every developer to build successful products. Launched from Y Combinator's W20 cohort, we've rapidly evolved beyond open-source product analytics, shipping over a dozen innovative products like a built-in data warehouse, a customer data platform, and the AI-powered analyst, Max AI. Our ambitious roadmap includes messaging, customer analytics, and AI-driven task creation based on customer data, logs, and support analytics.
We're an open-source, product-led company, well-funded and default alive, with a culture built on genuine values:
Transparency: Our public company handbook reveals everything from our roadmap to how we pay. Internally, you'll have full context with shared revenue, board meeting notes, and fundraising plans.
Autonomy: We don't micromanage. Engineers lead product teams, make product decisions, and choose what to work on next based on impact and personal motivation.
Shipping Fast: We operate on a "why not now?" philosophy, with small, autonomous teams of "cracked engineers" out-shipping much larger companies.
Time for Building: As a natively remote company, we prioritize async communication and have meeting-free Tuesdays and Thursdays, ensuring ample heads-down building time.
Ambition: We aim to solve big problems, believing that striving for the best, even if we sometimes miss, is better than never trying.
Being Weird: We embrace unconventional approaches, from redesigning our website repeatedly to building objectively unnecessary developer toys. It's our competitive advantage and it's fun.
The Opportunity: Expert Security Generalist
We're seeking a passionate and expert Security Generalist to own and elevate all things security at PostHog. This is a unique chance to build from the ground up, shaping our security team, culture, and tooling in a high-growth, open-source environment. You'll be equally adept and interested in building secure libraries, crafting Semgrep rules, hardening cloud deployments, enhancing network observability, and leading incident response.
You'll take the reins of our security operations, building out sophisticated detection pipelines and ensuring that when something goes bump in the night, we have the observability to understand exactly what happened. Our team is actively building internal security products and agents to automate tasks like triaging Wiz alerts, reviewing pull requests, and assigning vulnerability findings to owning product teams.
In this role, you will:
Build from Scratch: Forget legacy SIEMs. You'll architect our security framework, tools, and processes for a rapidly evolving, open-source product landscape.
Operate with Zero Bureaucracy: We loathe meetings and committees. You'll have the autonomy to make impactful changes and move at the speed of a startup.
Work with Radical Transparency: Our work is open. You'll contribute to and learn from how we handle incidents, like our past NPM package compromise.
Deliver Direct Impact: Your efforts will directly safeguard the data of thousands of customers, with your improvements to our security posture felt across the entire company and community.
What You'll Be Doing
Master Triage & Tuning: Own our Wiz alerts, transforming noise into actionable findings and continuously refining our alerts to focus only on what truly matters.
Lead Incident Detection & Response: Spearhead security incidents, from compromised NPM packages to suspicious IAM patterns, coordinating responses and leading thorough post-mortems. You'll also build our critical IR runbooks.
Engineer Observability: Build advanced detection pipelines and close network-based observability gaps, enabling us to trace suspicious activity all the way back to specific code paths.
Proactive Threat Hunting: Go beyond alerts by proactively hunting for threats in our AWS environment, defining "good" and building the telemetry to prove it.
Own the VDP: Support and scale our Vulnerability Disclosure Program, triaging researcher reports and transitioning us towards a formal bug bounty program.
Empower the Team: Provide threat modeling and secure design reviews to our product squads, embodying our philosophy of "Security says, 'here is how to do this safely.'"
Cultivate Security Culture: Play a crucial role in fostering our exceptional security culture, where engineers trust the security team as an enabler, not a gatekeeper.
While this role isn't focused on Corporate Security (MDM, endpoint, device trust) or Supply Chain/CI-CD hardening, our PostHog style means there are always opportunities to dive into these areas too!
What You'll Bring
Cloud Native Expertise: 3-5+ years of security engineering experience with a heavy focus on AWS. You're intimately familiar with IAM, VPC logs, and CloudTrail.
Detection Specialist: Proven expertise with CSPM/CNAPP tools (e.g., Wiz, Prisma) and, crucially, the ability to build detection pipelines that engineers trust and value.
Battle-Tested Incident Leader: You've led incident response efforts, demonstrating calmness under pressure and the ability to coordinate effectively across teams to contain threats.
High Autonomy & Drive: You thrive in an environment where you're building a function from scratch, comfortable defining priorities and executing without a prescriptive manual.
Exceptional Engineering Skills: Beyond digging into code to understand exploits or vulnerabilities, you write code with the same proficiency and quality as our product engineers.
Collaborative Communication & Attitude: You embody our "Security says, 'here is how to do this safely'" ethos, enabling engineers and fostering a collaborative working relationship.
We are committed to ensuring a fair and accessible interview process. If you need any accommodations or adjustments, please let us know.