At Sysdig, we believe cloud security isn't a compromise - it's a promise. From the start, our mission has been clear: to help organizations secure innovation in the cloud, the right way.
We created Falco, the open standard for cloud threat detection, and continue to lead the cloud security market with runtime insights, open innovation, and agentic Al. Creators of technology trusted by over 60% of the Fortune 500, Sysdig gives teams the real-time clarity to move fast and defend what matters most.
Culture matters here. We believe diversity fuels stronger ideas, and open dialogue drives sharper decisions. Recognized as a Best Place to Work and one of Deloitte's fastest-growing companies for the past 5 years, we're here to raise the standard for what cloud security and workplace culture should be.
If you have the passion to dig deeper, the desire to challenge convention, and the curiosity to build something better, Sysdig is the right place for you.
You'll own security engineering across four pillars — product security, production security, offensive security, and assurance engineering — and you'll build two programs from nothing: agentic continuous pentesting integrated with specialized human testing, and a security champions program covering both classical and AI security.
This role is Sysdig's customer zero, and we mean that operationally rather than rhetorically. You'll run our security program on our own technology, starting with the headless expression of Sysdig Secure and the products we're building to protect AI workloads. You'll sit with the product team on roadmap direction, with as much influence as you're willing to take.
The Office of the CISO operates transparently, and we want our security team publishing and speaking, so the work you do here becomes work the industry can use — with a real production environment to cite and a product you helped design as the evidence.
Own security engineering end-to-end. Set the roadmap, standards, and budget for the function. Act as final decision-maker on tooling and practice.
Build and grow the team. Hire senior and staff security engineers, set their technical direction, and stay close enough to the code to be credible with the engineers you're asking to change how they work.
Own product and platform security. Threat model the cloud defense platform and our AI workload protection products. Build secure-by-default primitives engineers build on rather than around. Drive vulnerability management measured by closure, not ticket volume.
Harden production as code. Secrets and workload identity, Kubernetes and multi-cloud hardening delivered through Terraform and CI/CD rather than documentation. Run detection and response in our own environment, on our own telemetry.
Build agentic continuous pentesting with humans in the loop where humans are better — agent-driven adversarial validation integrated with specialized human pentesting through our partner network. You define where agents are trusted, where they aren't, and how findings feed detection coverage.
Own attack enumeration, detection coverage, and validation as measured disciplines rather than as an annual engagement ending in a PDF.
Rebuild how compliance works here. We maintain ISO 27001, ISO 27701, and SOC 2 Type II, and we're moving entirely off point-in-time assessments. Build continuous assurance: controls that report their own state, evidence generated as a pipeline output, validation running continuously against production.
Make AI-assisted development safe at our scale. Define what coding agents can touch, what they can commit, and how you'd know if one were subverted by an insider, an external actor, or another agent.
Use agents to scale the security function itself — triage, control validation, evidence generation, detection authoring. If a security task is repeatable, it should run without the team.
Build the security champions program across both classical security, and AI security, As a means of scaling and increasing velocity of security across the engineering organization.
Shape the product roadmap as customer zero. Use new capabilities in production before customers do, then work directly with product on what to build, shape, or stop.
Represent security externally. Engage major customers on matters of significance, and publish and speak on the work — encouraged, resourced, and supported.
Have 8+ years in security or software engineering, including 4+ years leading and developing engineers, with real ownership of a team's roadmap, outcomes, and budget
Have genuine depth in at least two of the four pillars, with working knowledge of all four — we'd rather have real expertise in product and offensive security than a survey of everything
Have shipped security as code: Terraform or OpenTofu, controls enforced in pipelines, cloud and Kubernetes security at the architectural level rather than the dashboard level
Have run detection and response for real, as the person on the escalation path rather than above it
Are already building with agentic tooling and have opinions about where it fails
Would rather make the secure path the easiest path than enforce it through policy — most of the impact here comes through partnership with Engineering and Product, not mandate
Are credible with a customer's CISO and with your own engineers, without changing register much between them
Are energized rather than unsettled by problems where established principles don't fully apply
Built a security function that didn't exist before, at a company where much of it was theirs to define
Experience with capable adversaries — APT actors or other sophisticated cyberoffensive groups
Built or run agent-driven offensive tooling, or automated vulnerability discovery and remediation at scale
Worked on AI governance frameworks — ISO 42001, the EU AI Act, NIST AI RMF — as an engineering problem rather than a documentation exercise
A track record of conference speaking, published research, or open-source contribution
Extra days off to prioritize your well-being
401(k) Retirement Savings Plan with a 3% company match
Maternity and Parental Leave
Mental health support for you and your family through the Modern Health app
Full health benefits package for you and your family
The U.S. annual salary range for this full-time position is between 186,000 and 256,000 USD/year. Actual offers may be higher or lower than this range based on a variety of factors, including your work location, job-related experience and education.
We would love for you to join us! Please reach out even if your experience doesn't perfectly match the job description. We can always explore other options after starting the conversation. Your background and passion will set you apart, especially if your career path is different.
Sysdig values a diverse workplace and encourages women, people of color, LGBTQIA+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply. Sysdig is an equal-opportunity employer. Sysdig does not discriminate on the basis of race, color, religion, sex, national origin, age, disability, genetic information, sexual orientation, gender identity, or any other legally protected status.
#LI-FP1
#LI-Remote