
Information Security Engineer
Posted Jul 14

Posted Jul 14
This is a fully remote position, open to applicants in United Kingdom.
• Create and automate controls, detection methods, and tools to enhance the Information Security of Algolia’s infrastructure and products.
• Investigate, assess, and propose new Information Security technologies, techniques, and frameworks.
• Develop, implement, and sustain information security monitoring and remediation systems that significantly enhance the protection of Algolia’s customers’ data, as well as Algolia’s own systems and data.
• Collaborate with engineering and product teams to embed Information Security into new features, systems, and development workflows.
• Play a role in enhancing Information Security standards, processes, and best practices throughout the organization.
• Conduct Information Security risk assessments and threat modeling for core systems, services, and third-party vendors (excluding the completion of customer third-party risk assessment questionnaires).
• Engage in and occasionally lead Information Security incident response activities and perform post-incident analyses.
• Assist with ongoing and emerging Information Security and compliance initiatives (e.g., SOC 2 Type II, ISO 27001, C5, GDPR).
• Oversee and improve Algolia’s public bug bounty and vulnerability disclosure programs.
• 3–6 years of experience in Information Security engineering, infrastructure protection, or related technical fields.
• Proficiency in scripting or automation with at least one programming language (Python, Bash, Go, or similar) is essential; experience with Kubernetes is preferred.
• Strong grasp of Information Security principles applicable to modern cloud environments (AWS, GCP, or Azure) and operations within data centers.
• Solid understanding of, comfort with, and a minimum of three years of experience in operating, configuring, and managing log management/SIEM, threat detection and posture management, endpoint detection and response, SAST, SOAR, CTI, and other fundamental information security systems, with a strong preference for at least one year of extensive use of Crowdstrike or Obsidian (ideally both).
• Familiarity with common internet Information Security threats, attack vectors, and mitigation strategies.
• Strong understanding of computer systems, networks, and low-level protocols from an Information Security viewpoint.
• Experience in incident detection, response, and vulnerability management.
• Exceptional communication skills, capable of conveying Information Security risks and concepts to both technical and non-technical audiences.
• Proven ability to work collaboratively with the VP of Information Security to provide strategic advice and to operate independently to meet business objectives rather than relying solely on a ticket-based approach.
• Full professional proficiency in English.
• A culture that prioritizes continuous learning, curiosity, and collaboration within Information Security.
• A global, remote-friendly team that views Information Security as a facilitator of innovation.
• Opportunities to make a tangible impact on the Information Security of systems utilized by millions of end users.
• Ongoing professional development and support as the Information Security landscape evolves.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.