About the job
Join CodeRabbit as Our Lead Security Engineer
At CodeRabbit, we are at the forefront of innovation in research and development, dedicated to creating groundbreaking human-machine collaboration systems. Our vision is to revolutionize the future of software development through the integration of Gen AI-driven code reviewers, facilitating an unparalleled partnership between human creativity and advanced algorithms. By harnessing the power of language models and human intellect, we aim to redefine efficiency and quality in software development.
Position Summary:
We are seeking a seasoned Lead Security Engineer to join our mission of empowering developers with high-performance tools in a rapidly evolving threat landscape. In this pivotal role, you will be responsible for architecting, fortifying, and safeguarding our infrastructure and ecosystem.
As the Lead Security Engineer, you will infuse security into all aspects of our product and infrastructure, serving as the guardian of resilience, incident response, and proactive defense at scale.
Key Responsibilities:
Define the Security Roadmap: Develop and implement a strategic security engineering plan that aligns with CodeRabbit’s agile engineering processes.
Enhance Resilience: Advocate for defense-in-depth strategies, including threat modeling, secure design reviews, hardening, and CI/CD integration.
Lead Incident Response: Take charge of security incident response and recovery, ensuring effective triage, resolution, and root cause analysis to bolster system integrity.
Security Tools & Automation: Develop or integrate security tools (SAST, DAST, SIEM, EDR, monitoring) seamlessly into the developer workflow to maintain high delivery velocity.
Integrate Security Practices: Collaborate with engineering and product teams to ensure secure practices are incorporated early in project planning and daily operations.
Cultivate Talent & Culture: Contribute to hiring, coaching, and mentoring a resilient security engineering team while promoting security awareness throughout the organization.
Establish Compliance & Policy: Develop security standards, frameworks, and processes that evolve with our growth while remaining streamlined and developer-friendly.
Qualifications:
Proven Experience: 8+ years in security engineering, incident response, or related fields. Leadership experience during critical situations is a plus.
Technical Proficiency: In-depth knowledge of security best practices, threat modeling, and incident management.
Collaborative Mindset: Strong interpersonal skills and the ability to work effectively across multidisciplinary teams.
Adaptability: Eagerness to learn and adapt in a dynamic and fast-paced environment.

