PostHog Logo

PostHog

AppSec Engineer

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in USA
Mid level
Remote
Hiring Remotely in USA
Mid level
The AppSec Engineer will own detection, response, and cloud security, build detection pipelines, lead incident responses, and support the engineering team with secure design reviews.
The summary above was generated by AI

About PostHog

We're shipping every product that companies need to run their business from their first day, to the day they IPO, and beyond. The operating system for folks who build software.

We started with open-source product analytics, launched out of Y Combinator's W20 cohort. We've since shipped more than a dozen products, including:

  • A built-in data warehouse, so users can query product and customer data together using custom SQL insights.

  • A customer data platform, so they can send their data wherever they need with ease.

  • PostHog AI, an AI-powered analyst that answers product questions, helps users find useful session recordings, and writes custom SQL queries.

Next on the roadmap are CRM, Workflow, revenue analytics, and support products. When we say every product that companies need to run their business, we really mean it!

We are:

  1. Product-led. More than 100,000 companies have installed PostHog, mostly driven by word-of-mouth. We have intensely strong product-market fit.

  2. Default alive. Revenue is growing 10% MoM on average, and we're very efficient. We raise money to push ambition and grow faster, not to keep the lights on.

  3. Well-funded. We've raised more than $100m from some of the world's top investors. We're set up for a long, ambitious journey.

We're focused on building an awesome product for end users, hiring exceptional teammates, shipping fast, and being as weird as possible.

Things we care about
  • Transparency: Everyone can read about our roadmap, how we pay (or even let go of) people, our strategy, and how we work, in our public company handbook. Internally, we share revenue, notes and slides from board meetings, and fundraising plans, so everyone has the context they need to make good decisions.

  • Autonomy: We don’t tell anyone what to do. Everyone chooses what to work on next based on what's going to have the biggest impact on our customers, and what they find interesting and motivating to work on. Engineers lead product teams and make product decisions. Teams are flexible and easy to change when needed.

  • Shipping fast: Why not now? We want to build a lot of products; we can't do that shipping at a normal pace. We've built the company around small teams – autonomous, highly-efficient groups of cracked engineers who can outship much larger companies because they own their products end-to-end.

  • Time for building: Nothing gets shipped in a meeting. We're a natively remote company. We default to async communication – PRs > Issues > Slack. Tuesdays and Thursdays are meeting-free days, and we prioritize heads down building time over perfect coordination. This will be the most productive job you've ever had.

  • Ambition: We want to solve big problems. We strongly believe that aiming for the best possible upside, and sometimes missing, is better than never trying. We're optimistic about what's possible and our ability to get there.

  • Being weird: Weird means redesigning an already world-class website for the 5th time. It means shipping literally every product that relates to customer data. It means building an objectively unnecessary developer toy with dubious shareholder value. Doing weird stuff is a competitive advantage. And it's fun.

Who we're looking for

We are looking for our first AppSec Engineer to own detection, response, and cloud security at PostHog.

PostHog is growing fast, and our attack surface is growing with it. We recently rolled out Wiz, and while it’s given us great visibility, it’s not enough.
Currently, we have one security specialist and our infra engineers are spending part of their time on supporting him with security triage rather than building infrastructure.

We need to fix that. We’re looking for someone to take the reins of our security operations, build out our detection pipelines, and ensure that when something goes bump in the night, we have the observability to know exactly what happened. This is a unique role as you’ll:

  • Build from Scratch: You aren't maintaining someone else's legacy SIEM. You are shaping the security team, culture and tooling for a high-growth, open-source company.

  • Zero Bureaucracy: We hate meetings. We don't have "Security Committees." You have the autonomy to make changes and move fast.

  • Transparency: We work in the open. You’ll be able to see (and contribute to) how we handled past incidents, like this NPM package compromise.

  • Direct Impact: Your work directly protects the data of thousands of customers. When you improve our security posture, the whole company (and our community) feels it.

What you'll be doing
  • Triage and Tune: You’ll own our Wiz alerts. You’ll be responsible for turning "noise" into "actionable findings" and ensuring we aren't just staring at a dashboard of 1,000 "Critical" issues that don't actually matter.

  • Incident detection, response: You’ll lead the charge on security incidents. Whether it’s a compromised NPM package or a suspicious IAM pattern, you’ll coordinate the response and lead the post-mortem. You’ll also help build our IR runbooks.

  • Build Observability: You’ll build detection pipelines, and close our network-based observability gaps. We want to be able to trace suspicious activity all the way back to specific code paths.

  • Threat Hunting: You’ll proactively hunt for threats in our AWS environment. You won't just wait for an alert; you'll define what "good" looks like and build the telemetry to prove it.

  • The VDP: You’ll support our Vulnerability Disclosure Program, triaging reports from researchers and eventually transitioning us toward a formal bug bounty program.

  • Enable the Team: You’ll support our product squads with threat modeling and secure design reviews. We don't do "Security says no", we do "Security says 'here is how to do this safely.'"

  • Help build our security culture: Our engineers trust the security team and view security as an enabler. You’ll be a crucial part of helping to continue this excellent (and uncommon) working relationship.

While this is not a Corporate security (MDM, endpoint, device trust) or Supply chain/CI-CD hardening role, in true PostHog style, there are opportunities to work on these as well

Requirements
  • Cloud Native: You have 3-5+ years of experience in security engineering with a heavy focus on AWS. You know your way around IAM, VPC logs, and CloudTrail like the back of your hand.

  • Engineering skills: You bring strong engineering experience and next to digging into code to understand an exploit or a vulnerability, you can write code with the same proficiency as our product engineers.

  • Detection Specialist: You’ve used CSPM/CNAPP tools (like Wiz or Prisma) and, more importantly, you know how to build detection pipelines that engineers actually trust.

  • Battle-Tested: You’ve led incident response before. You’re calm under pressure and know how to coordinate across teams to contain a threat.

  • High Autonomy: We don’t have a security SOC. You’ll be building this function from scratch, so you need to be comfortable deciding what’s important and executing on it without a manual.


  • Communication and attitude: As mentioned before we don't do "Security says no", we do "Security says 'here is how to do this safely.” This is crucial for us, we need people that want to enable engineers and work with them, not limit them.

If you have a disability, please let us know if there's any way we can make the interview process better for you - we're happy to accommodate!

#LI-DNI

Top Skills

AWS
Cloudtrail
Cnapp
Cspm
Iam
Vpc
Wiz

Similar Jobs

7 Days Ago
Remote
United States
170K-210K Annually
Senior level
170K-210K Annually
Senior level
Fintech
Design and enforce application security across AWS and Kubernetes environments: perform secure code reviews, threat modeling, automate AppSec workflows, embed security into CI/CD and IaC, build tooling, support compliance (PCI/CCPA/GLBA), and partner with product and detection teams to operationalize AppSec standards.
Top Skills: Python,Bash,Powershell,Node,Typescript,Nestjs,React Native,Aws,Iam,Kms,Vpc,Ec2,Rds,Eks,Kubernetes,Docker,Sast,Sca,Dast,Iac,Ci/Cd,Policy-As-Code,Pre-Commit,Siem,Mitre Att&Ck,Owasp Top 10,Cwe,Cvss
36 Minutes Ago
Remote or Hybrid
Pennsylvania, USA
101K-238K Annually
Senior level
101K-238K Annually
Senior level
Digital Media • News + Entertainment
The role involves managing and developing a team of analysts, creating measurement and attribution solutions, and collaborating with stakeholders to enhance Comcast's advertising platforms.
Top Skills: AWSAzureExcelGCPLookerPower BIPythonRSQLTableau
36 Minutes Ago
Remote or Hybrid
New York, NY, USA
78K-140K Annually
Mid level
78K-140K Annually
Mid level
Digital Media • News + Entertainment
The Sr. Analyst will develop data pipelines, collaborate across teams, design reporting solutions, conduct data analysis, and maintain data quality to drive business outcomes.
Top Skills: Bi ToolsLookerPythonSQL

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account