About the Role
You will own security at CipherData — the product's detection brain and the company's own security posture — reporting directly to the CEO, who is also our CISO. We are building our founding security team now, and this is the lead seat: there is no function to inherit, you set the standard, and you hire and lead the engineers who join you.
The center of gravity is the product. AIDR's multi-agent engine investigates and correlates security data — logs, events, alerts, and context from across a customer's stack — on a SIEM-less security lakehouse, and someone has to decide what a correct investigation looks like: which alerts matter, what evidence a conclusion must carry, and how to tell when an agent is confidently wrong. You define the detection content the agents reason over, the ground truth they are measured against, and the next generation of our security lakehouse and detection capabilities. You will work directly with the AI engineering team: they build the reasoning, you build what it reasons over and the bar it is held to.
Around that core you also carry what a CISO's first engineer carries at a company our size: our own infrastructure and product security, customer-facing incident response, and the compliance work (SOC 2, ISO 27001, and customer-specific requirements) that our enterprise customers require. These are real responsibilities, not footnotes — but they are sized for a startup. You will automate and delegate them, not staff a GRC team.
If you have wanted to own a security function end to end, encode what you know about triage once instead of repeating it every shift, and do it at a company small enough that your decisions ship the same week — this is that role.
What You'll Do
Product — detection, lakehouse, and ground truth (the majority of your time)
- Security lakehouse and detection platform: Drive the roadmap for our SIEM-less security lakehouse — schema and normalization across multi-vendor security data, retention and query strategy, and the detection and correlation layer that runs on it. Partner with product engineering on the data plane; own what "correct" means on top of it.
- Detection and correlation engineering: Build and maintain the detection logic and correlation rules that turn multi-vendor security data into signal our agents can reason over.
- Ground truth and evaluation: Curate and label real investigations into the benchmark datasets that tell us whether agent output is right — the standard the AI team builds against.
- Threat research into product: Track attacker tradecraft and convert it into agent capability, detection content, and test cases.
- Production SOC deployment: Deploy, tune, and validate AIDR in customer environments; own the loop that carries analyst feedback back into detection and evaluation.
Company — security function owner
- Customer incident response: Own the response to security incidents reported by customers or detected internally: analysis, root cause, remediation, customer communication, and post-incident review. Maintain the playbooks.
- Product and infrastructure security: Secure how we ingest, isolate, and handle customer security data — a privacy or tenancy failure is not something you recover from. Run assessments and pen tests on the product and our cloud footprint; integrate security into how we ship.
- Compliance and certifications: Own the technical side of SOC 2, ISO 27001, and customer security requirements, working with our Korea team and outside counsel. Automate evidence collection; don't build a paper program.
- Team: Build and grow the founding security team — hire, lead, and develop the security engineers who join you.
Our Core Values
Five principles guide every decision at CipherData. We hire against them and evaluate against them:
- Trustworthiness — be trustworthy to all people. Integrity, transparency, and dependability with colleagues, partners, and customers.
- Growth Mindset — learn from anything, anyone, anytime. Past experience is data, not dogma. Curiosity over ego; first principles over status quo.
- Proactive Ownership — do the right thing for the customer. Customer first, then company, then team, then self. Step beyond your role and hold yourself accountable.
- Disagree and Commit — debate when it matters, execute with unity. Challenge high-impact decisions with data and conviction, regardless of title. Once decided, commit fully.
- Impact-Driven Execution — ship, learn, iterate. Move fast, take calculated risks, and measure yourself by outcomes, not activity.
Minimum Qualifications
- 8+ years in security engineering, detection engineering, threat hunting, or incident response, including senior-level SOC or detection-engineering work where you were accountable for outcomes
- Demonstrated detection engineering in production: you have written, tuned, and retired detections and can explain the false-positive trade-offs you made
- Deep hands-on experience with SIEM and security data platforms, EDR/XDR, and cloud and identity telemetry — including data modeling and normalization, not just query authoring
- Strong Python and comfort in an engineering codebase: code review, tests, CI
- Incident response leadership on real intrusions, including customer- or executive-facing communication
- Ability to articulate what separates a good investigation from a bad one precisely enough that it can be written down and measured
- Evidence of 0-to-1 ownership: you have built a function, program, or system from nothing, scoped your own work, and shipped without a large support structure
Preferred Qualifications
- Experience designing or operating a security data lake or lakehouse at scale
- Detection-as-code practice — version control, testing, and CI for detection content
- Experience building labeled datasets, benchmarks, or evaluations for security tooling or ML systems
- Familiarity with LLM-based systems and their failure modes (hallucination, prompt injection, fabricated evidence)
- Multi-tenant or MSSP environments; cloud security depth across major cloud providers
- SOC 2 / ISO 27001 experience from the engineering side
- Purple team, adversary emulation, or offensive security background
- Prior experience as a first or early security hire
Details
- Position: Lead Security Engineer
- Experience: 8+ years
- Reports to: CEO & CISO
- Employment type: Full-time
- Location: Bellevue, WA
CipherData is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic.
CipherData · [email protected]