About this role
Semaphore is a remote-first software company that helps engineering teams build, test, and deliver software with confidence. We support Semaphore Cloud and our self-hosted enterprise products to run critical development workflows securely and reliably. We maintain SOC 2 Type 2 and ISO 27001:2022 compliance and are hiring a Security Engineer to own the technical side of our security program.
A clear, hands-on security role focused on technical controls across our infrastructure and internal systems. You will collaborate with Engineering, Infrastructure, and our Compliance Manager to translate security and compliance requirements into practical, reliable controls. This is a technical, operations-oriented position where you will investigate vulnerabilities, operate security monitoring, improve infrastructure and access controls, automate recurring tasks, and lead technical remediation. The Compliance Manager owns the ISMS, policies, audit coordination, and regulatory interpretation; you will own the implementation, operation, and testing of the technical controls that support them. We value demonstrated ownership and sound judgment over specific years of experience or job titles.
Responsibilities
- Run the vulnerability-management lifecycle, including scanning, triage, prioritization, remediation, exceptions, and verification.
- Operate and improve security monitoring and SIEM tooling, including alert quality, dashboards, detection rules, and integrations.
- Investigate security alerts and lead the technical response to security incidents.
- Improve the security of Linux hosts, cloud infrastructure, networks, firewalls, containers, and internal services.
- Own technical controls for identity and access management, least privilege, just-in-time access, secrets, and certificates.
- Automate patching, evidence collection, recurring control checks, and other security operations.
- Coordinate penetration tests and drive technical findings through remediation and verification.
- Translate SOC 2 and ISO 27001 control requirements into effective technical implementations.
- Produce clear technical evidence for internal and external audits in partnership with the Compliance Manager.
- Maintain security runbooks, system documentation, risk-based priorities, and operational metrics.
- Help engineering teams make practical security decisions without adding unnecessary process.
Requirements
-
Proven ownership of technical security in a production SaaS, cloud, hosting, or infrastructure environment.
-
Strong Linux systems, networking, and cloud-security fundamentals.
-
Hands-on experience with vulnerability management, patching, hardening, and remediation at scale.
-
Experience operating SIEM or security-monitoring systems and investigating security events.
-
Practical understanding of IAM, privileged access, secrets management, certificates, and network controls.
-
Ability to automate operational work using Python, Bash, infrastructure-as-code, or similar tools.
-
Experience participating in incident response and communicating clearly during high-pressure situations.
-
Working knowledge of ISO 27001, SOC 2, or related security-control frameworks.
-
Strong written and spoken English, comfort working independently in a remote, asynchronous team.
-
Good risk judgment: distinguishing urgent security problems, acceptable exceptions, and low-value processes.
-
Nice to have
-
Experience with Wazuh or a comparable SIEM/security-monitoring platform.
-
Experience with Teleport, PAM, or just-in-time access systems.
-
Experience securing large Linux server fleets or hybrid cloud/on-premise environments.
-
Familiarity with CI/CD systems, build infrastructure, containers, and software supply-chain security.
-
Experience supporting SOC 2 or ISO 27001 audits from the technical-control side.
-
Relevant certifications such as Security+, CISSP, CISM, GIAC, or ISO 27001 (certification not required).
-
What success looks like
-
Within six months, technical security operations have a clear owner, documented priorities, and reliable response expectations; vulnerability findings are triaged and remediated or accepted based on risk; security monitoring is stable and actionable; recurring patching, access-control, and evidence-collection tasks are increasingly automated; engineering and infrastructure teams receive clear, practical guidance, and security issues reach closure; and audit evidence is reliable enough that compliance work does not rely on manual follow-up by senior engineers.
-
How you will work
-
You will collaborate closely with the Engineering and Infrastructure teams and partner with the Compliance Manager, who owns governance, policies, the ISMS, and audit coordination. You will design, implement, operate, test, and remediate technical security controls. This is an individual-contributor role with broad ownership and direct influence on how Semaphore protects its systems, customers, and company data.