Sobre este puesto de Security Engineer en Conduct
Why Conduct
The world's largest companies are slowed down by the software they run on. We're building the AI operating system that absorbs IT complexity and unlocks entirely new levels of speed, output, and ambition. We believe this is a generation-defining mission. Major enterprises already trust us with their most critical systems, we just closed a $60M+ Series A from top-tier funds, and we're still early enough that what you build here defines the company. We're a small, talent-dense team doing our life's work at Conduct - we value extreme ownership, high velocity, and low-ego collaboration. If you bring that same drive, we will make sure this is the place you do yours too.
Who we hire
We work with some of the largest enterprises in the world, and security is core to earning and keeping that trust. We're looking for someone who takes real ownership of our security posture and genuinely cares about getting it right. This is a builder's role as much as an operator's: you'll design and ship the security features our enterprise customers need, not just run controls and tooling.
You'll stand out if you:
Have shipped security features as a software engineer - things like BYOK per tenant, SSO/SCIM, or SIEM-compatible audit logging - not just configured or audited them
Have hands-on experience with enterprise security requirements - completing security questionnaires, navigating customer requirements around data handling and contractual agreements
Are confident acting as the technical point of contact for developers, CISOs, and clients during security due diligence conversations
Bring pragmatic judgement - you know how to balance security rigour against the speed a startup needs to move at
Are genuinely excited about InfoSec and motivated to keep growing; we're open to less experience if the drive and aptitude are clearly there
What you'll own
You'll own our security posture end to end: the day-to-day operational work of keeping us secure, the security capabilities our enterprise customers demand, and the bigger initiatives on our security roadmap as we build out the function. This is as much a software engineering role as a security ops one - expect to spend real time in our codebase building features, alongside hands-on investigation, remediation, and shaping how security scales as we grow from 20 to 40+ engineers.
Day to day, you'll:
Design and build security features that ship in our product - like BYOK per tenant, SIEM-compatible audit logs, and SSO/SCIM - working directly in the codebase alongside product engineers
Own enterprise security end to end - completing customer security questionnaires, working through requirements around data handling and contractual agreements, and acting as the technical point of contact for our clients’ CISOs and security teams
Monitor and harden our cloud environment - tracking security recommendations, driving remediation, and making pragmatic risk-acceptance calls where they're justified
Investigate and respond to security alerts across our endpoint, cloud, and application stack
Build out our detection and monitoring capabilities, evolving our SIEM with alerting that cuts through the noise
Own vulnerability management end to end - triaging, tracking, and driving issues through to resolution
Proactively hunt for threats, from unusual behaviour in our environment to emerging risks like package and supply chain compromises
Run and refine security scanning across our infrastructure, applications, and dependencies
Who we hire
3-7 years in a security engineering role
Background can come from any type of security engineering; what matters most is that you're comfortable reading and writing code - you'll be building product features and tooling, not just operating them
Experience working with enterprise customers is a plus, not a requirement