CareerPlanGet AI match score →
💼 Full-time🗓 2026-06-25

Core

Build and improve security controls, automate security workflows, and triage vulnerabilities to protect infrastructure, product, and user data.

Role type

hands-on security engineer (backend & infrastructure)

Builds

secure backend systems, automated security workflows, and security controls

Domain

SaaS / AI assistant for meetings / cloud security

Deliverable

production ML models | product features | infrastructure

Required skills

backend development (Node.js/TypeScript), authentication/authorization, cryptography, vulnerability assessment, penetration testing, cloud security (GCP/AWS), container security (Kubernetes/Docker), security tool configuration

Preferred skills

SaaS environment experience, bug bounty program management, compliance frameworks (SOC 2, HIPAA, GDPR), DevSecOps automation

Technologies

Node.js, TypeScript, Go, MongoDB, Kubernetes, Docker, GCP, Pub/Sub, HackerOne, Vanta, GitHub Advanced Security

Responsibilities

Build and improve security controls across product and infrastructure; Review code, architecture, and infrastructure for security risks; Run vulnerability assessments, penetration testing, and security audits; Debug and patch security issues in backend systems; Manage bug bounty triage and remediation workflows; Automate security checks, alerts, and vulnerability workflows; Partner with engineering teams to promote secure coding practices; Support incident response and security investigations; Configure and maintain security tools such as firewalls, IDS/IPS, scanners, and monitoring systems

Rewrite
## About the role Fireflies.ai is the #1 AI assistant for meetings, trusted by over 20 million people across more than 1 million organisations from fast-growing startups to Fortune 500 enterprises. Whether in sales, project management, marketing, operations, or product development, Fireflies is revolutionizing team collaboration by capturing knowledge, automating repetitive tasks, and enhancing productivity before, during, and after every meeting. Recognized as a category-defining platform, Fireflies has achieved unicorn status with a valuation exceeding $1 billion. Ramp data shows Fireflies is the 6th most purchased AI platform in the US. Chances are, you've already seen Fireflies in action, quietly powering one of your recent meetings. Fireflies.ai is looking for a hands-on Security Engineer to protect our infrastructure, product, and user data as we scale globally. This role is ideal for someone who can ship code, automate security workflows, triage vulnerabilities, and work closely with engineering teams to build secure systems. ## Responsibilities - Build and improve security controls across our product, backend, and infrastructure. - Review code, architecture, and infrastructure for security risks. - Run vulnerability assessments, penetration testing, and security audits. - Debug and patch security issues in backend systems. - Manage bug bounty triage and remediation workflows, including HackerOne. - Automate security checks, alerts, and vulnerability workflows. - Partner with engineering teams to promote secure coding practices. - Support incident response and security investigations. - Configure and maintain security tools such as firewalls, IDS/IPS, scanners, and monitoring systems. ## Requirements - 3+ years of experience in security engineering, backend security, or infrastructure security. - Strong backend development experience with Node.js/TypeScript. - Ability to ship code end-to-end. - Good understanding of authentication, authorization, cryptography, and common vulnerabilities. - Experience with security tools such as GitHub Advanced Security, Dependabot, CrowdStrike, Falco or similar. - Experience with cloud security, preferably GCP or AWS. - Familiarity with Kubernetes, Docker, and modern infrastructure security. - Strong problem-solving and communication skills. ## Nice to have - Experience with SaaS or high-growth startup environments. - Bug bounty program experience. - Experience with SOC 2, HIPAA, GDPR, Vanta, or similar. - Contributions to the security community, such as CVEs, talks, or open-source work. - Experience with DevSecOps or security automation. ## Tech Stack - Node.js, TypeScript - Go - MongoDB - Kubernetes, Docker - GCP - Pub/Sub architecture - HackerOne, Vanta, GitHub Advanced Security ## Values that are important to us - You should be a great communicator and culture maintainer - Take a look at our culture document - You're data-driven and customer-focused - You value fast & incremental engineering cycles - You maintain design excellence and minimize complexity - You measure your results & automate when
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Wellfound ↗