安全工程师
Security Engineer
关于 POSTHOG
产品开发过去意味着手动编写代码、运行分析、诊断错误,并使用数十种工具推出更改。
PostHog 让产品实现自动驾驶 https://posthog.com/self-driving。它是唯一一个能作为你的副驾驶(以及你的 AI 代理)来完成所有工作的平台——自主完成。
我们从开源产品分析工具开始,从 Y Combinator 的 W20 班级孵化出来 https://posthog.com/handbook/story。此后我们推出了十多个产品 https://posthog.com/products,包括:
- PostHog Desktop https://posthog.com/desktop,唯一一个能理解你的产品而非仅代码库的 AI 开发工具。
- 内置的数据仓库 https://posthog.com/docs/data-warehouse,让用户可以使用自定义 SQL 洞察同时查询产品和客户数据。
- PostHog AI https://posthog.com/ai,一个由 AI 驱动的分析师,可以回答产品问题,帮助用户找到有用会话记录,并编写自定义 SQL 查询。
我们是:
1. 以产品为导向。超过 45 万个组织已安装 PostHog,主要由口碑驱动。我们有非常强的产品市场契合度。
2. 默认活跃 https://paulgraham.com/aord.html。收入增长非常迅速,我们效率很高。我们融资是为了推动雄心并更快增长,而不是为了维持运营。
3. 获得大量资金支持。我们从世界顶级投资者那里筹集了超过 1.8 亿美元资金。我们为长期、雄心勃勃的旅程做好了准备。
我们专注于为终端用户打造出色的产品,招聘优秀的团队成员,快速交付,并尽可能地保持独特 https://posthog.com/deskhog。
我们关注的事情
- 透明:任何人都可以在我们的公开公司手册 https://posthog.com/handbook 中阅读我们的路线图、如何支付(甚至解雇)员工、我们的战略以及我们的工作方式。内部,我们分享收入、董事会会议的笔记和幻灯片,以及融资计划,让每个人都能获得做出良好决策所需的信息。
- 自主性:我们不会告诉任何人该做什么。每个人根据对客户影响最大的事情,以及他们觉得有趣和有动力去做的事情来选择接下来要做什么。工程师领导产品团队 https://posthog.com/handbook/wide-company 并做出产品决策 https://posthog.com/handbook/which-products。当需要时,团队灵活且易于调整。
- 快速交付:为什么现在不?https://posthog.com/handbook/values#why-not-now 我们希望现在就做。
查看英文原文
ABOUT POSTHOG
Product development used to mean manually writing code, running analysis, diagnosing bugs, and rolling out changes using dozens of tools.
PostHog makes products self-driving https://posthog.com/self-driving. It's the only platform that acts like a co-pilot for you (and your AI agents) to do it all – autonomously.
We started with open-source product analytics, launched out of Y Combinator's W20 cohort https://posthog.com/handbook/story. We've since shipped more than a dozen products https://posthog.com/products, including:
- PostHog Desktop https://posthog.com/desktop, the only AI devtool that understands your product, not just your codebase.
- A built-in data warehouse https://posthog.com/docs/data-warehouse, so users can query product and customer data together using custom SQL insights.
- PostHog AI https://posthog.com/ai, an AI-powered analyst that answers product questions, helps users find useful session recordings, and writes custom SQL queries.
We are:
1. Product-led. More than 450,000 organizations have installed PostHog, mostly driven by word-of-mouth. We have intensely strong product-market fit.
2. Default alive https://paulgraham.com/aord.html. Revenue is growing incredibly quickly, and we're very efficient. We raise money to push ambition and grow faster, not to keep the lights on.
3. Well-funded. We've raised more than $180m from some of the world's top investors. We're set up for a long, ambitious journey.
We're focused on building an awesome product for end users, hiring exceptional teammates, shipping fast, and being as weird as possible https://posthog.com/deskhog.
THINGS WE CARE ABOUT
- Transparency: Everyone can read about our roadmap, how we pay (or even let go of) people, our strategy, and how we work, in our public company handbook https://posthog.com/handbook. Internally, we share revenue, notes and slides from board meetings, and fundraising plans, so everyone has the context they need to make good decisions.
- Autonomy: We don’t tell anyone what to do. Everyone chooses what to work on next based on what's going to have the biggest impact on our customers, and what they find interesting and motivating to work on. Engineers lead product teams https://posthog.com/handbook/wide-company and make product decisions https://posthog.com/handbook/which-products. Teams are flexible and easy to change when needed.
- Shipping fast: Why not now? https://posthog.com/handbook/values#why-not-now We want to build a lot of products; we can't do that shipping at a normal pace. We've built the company around small teams – autonomous, highly-efficient groups of cracked engineers https://posthog.com/founders/cracked-manifesto who can outship much larger companies because they own their products end-to-end.
- Time for building: Nothing gets shipped in a meeting. We're a natively remote company. We default to async communication – PRs > Issues > Slack. Tuesdays and Thursdays are meeting-free days https://posthog.com/handbook/company/culture#were-on-the-makers-schedule, and we prioritize heads down building time over perfect coordination. This will be the most productive job you've ever had.
- Ambition: We want to solve big problems. We strongly believe that aiming for the best possible upside, and sometimes missing, is better than never trying. We're optimistic about what's possible and our ability to get there.
- Being weird: Weird means redesigning an already world-class website for the 5th time. It means shipping literally every product that relates to customer data. It means building an objectively unnecessary developer toy https://posthog.com/deskhog with dubious shareholder value. Doing weird stuff is a competitive advantage. And it's fun.
WHO WE'RE LOOKING FOR
We are looking for an expert security generalist (in EU/UK) to assist with all things security at PostHog. Someone equally adept (and interested!) in building secure libraries, writing semgrep rules, hardening cloud deployments, improving network observability, and leading incident response.
Someone to take the reins of our security operations, build out our detection pipelines, and ensure that when something goes bump in the night, we have the observability to know exactly what happened.
We're a team that's building internal security products and agents - things like agents to automatically triage wiz alerts, automatically review pull requests, automatically assign vulnerability findings to the owning product team.
In this role you’ll:
- Build from Scratch: You aren't maintaining someone else's legacy SIEM. You are shaping the security team, culture and tooling for a high-growth, open-source company.
- Zero Bureaucracy: We hate meetings. We don't have "Security Committees." You have the autonomy to make changes and move fast.
- Transparency: We work in the open. You’ll be able to see (and contribute to) how we handled past incidents, like this NPM package compromise https://www.google.com/search?q=https://github.com/PostHog/posthog/issues/example.
- Direct Impact: Your work directly protects the data of thousands of customers. When you improve our security posture, the whole company (and our community) feels it.
WHAT YOU'LL BE DOING
- Triage and Tune: You’ll own our Wiz alerts. You’ll be responsible for turning "noise" into "actionable findings" and ensuring we aren't just staring at a dashboard of issues that don't actually matter. We already get relatively few alerts, and we’d like to even further reduce that to just the ones that matter.
- Incident detection, response: You’ll lead the charge on security incidents. Whether it’s a compromised NPM package or a suspicious IAM pattern, you’ll help coordinate the response and lead the post-mortem. You’ll also help build our IR runbooks.
- Build Observability: You’ll build detection pipelines, and close our network-based observability gaps. We want to be able to trace network requests and suspicious activity all the way back to specific code paths.
- Threat Hunting: You’ll proactively hunt for threats in our AWS environment. You won't just wait for an alert; you'll define what "good" looks like and build the telemetry to prove it.
- The VDP: You’ll support our Vulnerability Disclosure Program, triaging reports from researchers and eventually transitioning us toward a formal bug bounty program.
- Enable the Team: You’ll support our product squads with threat modeling and secure design reviews. We don't do "Security says no"; we do "Security says 'here is how to do this safely.'"
- Help build our security culture: Our engineers trust the security team and view security as an enabler. You’ll be a crucial part of helping to continue this excellent (and uncommon) working relationship.
While this is not a Corporate security (MDM, endpoint, device trust) or Supply chain/CI-CD hardening role, in true PostHog style, there are opportunities to work on these as well.
REQUIREMENTS
- Cloud Native: You have 3-5+ years of experience in security engineering with a heavy focus on AWS. You know your way around IAM, VPC logs, and CloudTrail like the back of your hand.
- Detection Specialist: You’ve used CSPM/CNAPP tools (like Wiz or Prisma) and, more importantly, you know how to build detection pipelines that engineers actually trust.
- Battle-Tested: You’ve led incident response before. You’re calm under pressure and know how to coordinate across teams to contain a threat.
- High Autonomy: We don’t have a security SOC. You’ll be building this function from scratch, so you need to be comfortable deciding what’s important and executing on it without a manual.
- Engineering skills: You bring strong engineering experience and next to digging into code to understand an exploit or a vulnerability, you can write code with the same proficiency as our product engineers.
- Communication and attitude: As mentioned before we don't do "Security says no", we do "Security says 'here is how to do this safely.” This is crucial for us, we need people that want to enable engineers and work with them, not limit them.
NICE TO HAVE
- Incident management: Strong experience with incident response/incident detection
We are committed to ensuring a fair and accessible interview process. If you need any accommodations or adjustments, please let us know
#LI-DNI