remote

Salary
$230,000–$250,000from the description
Posted
Jul 20, 2026
Location
Last confirmed open
Jul 22, 2026

What this job asks for AI summary

A senior individual contributor security engineering role with two primary ownership areas: AI and agentic security (including guardrails, LLM/ML workload security, and org-wide standards) and threat detection and incident response (owning the Panther SIEM platform, detection coverage, and HIPAA-aligned IR playbooks). The position also spans cloud and code security reviews and involves mentoring less experienced teammates on a small, broad-scope security team.

Senior level · 8+ years · Remote · Full-time

Must have (11)
AWSKubernetesTerraformLLMsPython, Go or TypeScriptPantherHIPAASOC 2incident responsethreat detectionMCP
Nice to have (10)
GuardDutyAWS ConfigWizSnykGitHub Advanced SecurityCrowdStrikeNightfallDrataHelmPostgres

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 140 people nationally plausibly meet what this posting asks for (information security analysts). range 60–220

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
MCP2%Terraform11%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
incident response62%Python51%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (5)

This role blends deep security engineering (AI security, threat detection, incident response) with a meaningful software development requirement (writing production code in Python, Go, or TypeScript). SOC 15-1212 was chosen as the primary because security ownership — detection platform, AI guardrails, IR readiness, cloud security reviews — is the dominant day-to-day scope; 15-1252 is a credible runner-up given the explicit production-code and security-tooling-building requirement.

Python, Go, and TypeScript are listed as interchangeable options for the production-code requirement ('Python, Go, or TypeScript'); Python is listed as the primary with Go and TypeScript as alternatives.

MCP (Model Context Protocol) is explicitly called out as a required depth area alongside LLM applications and agentic frameworks under 'What You Bring'.

The full security tooling stack (GuardDuty, AWS Config, Wiz, Snyk, GitHub Advanced Security, CrowdStrike, Nightfall, Drata, Postgres, Helm, Claude) appears under 'Our Tech Stack' — a stack/context section — and is marked preferred accordingly.

Panther is marked required because it is explicitly named as the detection platform the candidate will 'own', making it a hard gate despite also appearing in the tech stack list.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗