Cyber Security Engineer
Job Description
Key Responsibilities:
• Design and build detection pipelines for synthetic video and audio, including integration of AI/ML models for deepfake identification
• Research and implement techniques for conversation arc analysis: detecting manipulation patterns such as authority spoofing, urgency injection, and social isolation across multi-turn interactions
• Build identity verification layers that work in real-time video and audio contexts
• Develop adversarial testing frameworks to stress-test our detection models against evolving attack techniques (voice cloning, face-swapping, real-time deepfakes)
• Contribute to the architecture of our desktop-native detection agent, ensuring low-latency analysis without compromising accuracy
• Stay current on the threat landscape: new generative AI capabilities, emerging social engineering vectors, and novel attack surfaces
Internal Security & Infrastructure
• Design and implement endpoint security controls across company devices (macOS/Linux), including disk encryption, device management, and access policies
• Build and maintain DLP policies to protect sensitive data (customer data, model weights, proprietary detection logic)
• Configure and manage cloud security controls across our infrastructure (AWS/GCP), including IAM, network segmentation, logging, and secrets management
• Implement monitoring and alerting for security-relevant events across infrastructure and application layers
• Develop and maintain security baselines, hardening guides, and compliance documentation as we pursue enterprise customer requirements
Automation & Operations
• Automate security workflows: deployment hardening, configuration audits, vulnerability scanning, and agent health checks using Python, Bash, or infrastructure-as-code tools
• Maintain documentation including architecture diagrams, deployment procedures, and incident response playbooks
• Support security reviews for new features and integrations
Requirements:
• Strong understanding of how social engineering attacks work in practice, from phishing and vishing to deepfake-enabled impersonation
• Hands-on experience with at least some of: audio/video processing pipelines, ML model deployment, or real-time streaming analysis
• Solid knowledge of endpoint and cloud security fundamentals: encryption, access control, network segmentation, logging
• Experience securing cloud infrastructure (AWS or GCP preferred)
• Proficiency in Python; Bash and familiarity with CI/CD pipelines a plus
• Understanding of adversarial ML concepts: how generative models can be attacked, evaded, or poisoned
• Comfort working in a fast-moving startup where you'll wear multiple hats
Nice-to-Have:
• Experience with deepfake detection, synthetic media analysis, or computer vision / audio ML models
• Familiarity with EDR/NDR platforms (CrowdStrike, Defender, Corelight, etc.)
• Background in red teaming or penetration testing, particularly social engineering assessments
• Cloud security certifications (AWS Security Specialty, GCP Professional Cloud Security Engineer) or general certs (CISSP, OSCP, Security+)
• Experience building security tooling or detection systems from scratch rather than just configuring vendor products
