Jobs Companies CodeRabbit Lead Security Engineer

À propos de ce poste Lead Security Engineer chez CodeRabbit

CodeRabbit · Hybride · San Francisco

About CodeRabbit

CodeRabbit is an innovative research and development company focused on building extraordinarily productive human-machine collaboration systems. Our primary goal is to create the next generation of Gen AI-driven code reviewers: a symbiotic partnership between humans and advanced algorithms that significantly outperforms individual engineers. We combine language models with human ingenuity to push the boundaries of software development efficiency and quality.

Role Overview:

CodeRabbit is on a mission to empower developers with lean, high-performance tools—they move fast, and so do the threats. That's why we're looking for a battle-tested Lead Security Engineer who’s been in the trenches and can architect, harden, and defend our infrastructure, tooling, and ecosystem.

As our Lead Security Engineer, you’ll lead security engineering at CodeRabbit, infusing security into every layer of our product and infrastructure. You become the steward of resilience, incident response, and proactive defense at scale.

Responsibilities:

  • Own the security roadmap — craft and execute a strategic security engineering plan that aligns with CodeRabbit’s fast-paced engineering cadence.

  • Boost resilience — champion defense-in-depth tactics: threat modeling, secure design reviews, hardening, CI/CD integration.

  • Be Incident Commander — spearhead security incident response and recovery: triage, resolve, root cause, and turn those learnings into stronger systems.

  • Tools & automation — build or integrate security tooling (SAST, DAST, SIEM, EDR, monitoring) into the developer workflow without slowing delivery.

  • Embed security fluently — partner with engineering and product teams to bring secure practices early into planning and daily workflows.

  • Talent & culture — help to hire, coach, and mentor a scrappy, resilient security engineering team; elevate security awareness across the company.

  • Compliance & policy — establish security standards, frameworks, or processes that evolve as we scale—but remain lean and developer-friendly.

Qualifications:

  • Battle-tested experience: 8+ years in security engineering, incident response, or correlated fields—bonus if you've led through a major production breach or targeted attack.

  • Technical depth: Extensive experience with security across software and infrastructure—threat modeling, pen testing, secure CI/CD pipelines, cloud security, incident response.

  • Strategic mindset: Ability to translate risk into actionables, communicate trade‑offs with engineering/product leadership.

  • Praxis over theory: You’ve taken production systems down (intentionally or unintentionally) and built them back stronger.

  • Security in chaos: Experience in pressure situations—with clarity, direction, and calm.

  • Developer‑centric approach: You can speak fluent dev-tools, empathize with fast-moving teams, and secure them without slowing them down.

Bonus Points:

  • You’ve implemented DevSecOps tooling and orchestrated shift‑left security in developer pipelines.

  • You’ve recovered from (or prevented) a critical security event, and turned that into an engineering culture improvement.

  • Experience in a dev‑tools, SDK, or platform-heavy company.

  • Hacker mindset + operational discipline - pentests, disaster recovery, threat hunting, tooling, cloud environments.

  • Certifications like CISSP, CISM, CEH, or relevant cloud security certs.

Why Join Our Engineering Culture?

  • CodeRabbit is building the next generation of AI-native developer tooling — starting with code review. We combine large language models with deep software engineering context to help teams ship faster, catch more bugs, and make better architectural decisions at scale.

  • We are a high-ownership engineering culture. That means no passive execution, no waiting for perfect tickets, and no narrowly defined task boundaries. Engineers here find problems before they're assigned, use AI as a core part of how they build, ship with judgment, and own outcomes from proposal to production.

  • Our operating philosophy: bias toward action, ship the smallest necessary coherent slice, validate proportional to risk, watch what happens, and make the system better. AI drafts; humans decide. Speed matters, but so does understanding what you ship.

  • This opportunity will be energizing for people who want real ownership, pace, and high standards. It's uncomfortable for people who prefer slow consensus or heavily managed workflows.

  • If you want to build tools that are changing how software gets written, and be held to the standard that the best engineers thrive under; we'd love to talk.

Our Values

  • 🤝 Collaborative Humans: Prioritizing collective intelligence

  • 🚀 Fearless Innovators: Turning obstacles into growth opportunities

  • 💪 Persistent, Passionate Developers: Thriving on complex, long-term challenges

  • 🎯 Impact-Driven Creators: Crafting intuitive tools for developers

  • 🧠 Rapid Learners and Un-learners: Adapting quickly in our fast-paced technological world

Prêt à postuler chez CodeRabbit ?
Postuler chez CodeRabbit

Comment se compare ce salaire pour Security Engineer

Ce poste paie $250,000/yrdans la fourchette habituelle pour les postes Security Engineer.

$175,000 la médiane $235,000 $339,130

Fourchette typique $197,500–$265,000/yr, à partir de 216 annonces Security Engineer comparables sur JobsRadar (rémunération annualisée en USD). Voir les aperçus de salaire pour Security Engineer →

Emplois similaires

Higgsfield
Security Infrastructure Engineer
Higgsfield
⚡ Postuler tôt Almaty, Kazakhstan Hybride
● Nouveau 👁 Vu ✓ Postulé il y a 3 h
Fluidstack
Information Security Engineer, Bare Metal
Fluidstack
⚡ Postuler tôt New York, NY Sur site $269,000–$330,000
● Nouveau 👁 Vu ✓ Postulé il y a 3 h
Fluidstack
Security Engineer, Infrastructure
Fluidstack
⚡ Postuler tôt New York, NY Sur site $218,000–$252,000
● Nouveau 👁 Vu ✓ Postulé il y a 3 h
Braze
Senior Security Engineer, Enterprise Security
Braze
⚡ Postuler tôt San Francisco Sur site $128,900–$180,000
● Nouveau 👁 Vu ✓ Postulé il y a 6 h
MongoDB
Site Reliability Engineer (Senior or Staff), Infrastructure Security
MongoDB
⚡ Postuler tôt Austin; New York City; San Fra... Sur site $127,000–$249,000
● Nouveau 👁 Vu ✓ Postulé il y a 9 h
MongoDB
Security Software Engineer, Infrastructure Security (Staff or Senior)
MongoDB
⚡ Postuler tôt Austin; New York City; San Fra... Sur site $127,000–$249,000
● Nouveau 👁 Vu ✓ Postulé il y a 9 h
AN
Lead Security & IT Engineer
Anodize
⚡ Postuler tôt San Francisco or Los Altos, CA Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 18 h
VE
Security Engineer, Detection Response
Vercel
⚡ Postuler tôt Hybrid - San Francisco, New Yo... Hybride $208,000–$312,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 j
VE
Product Security Engineer
Vercel
⚡ Postuler tôt Hybrid - San Francisco, New Yo... Hybride $208,000–$312,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 j

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez CodeRabbit

Voir tous les emplois chez CodeRabbit →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit