CircleCI is hiring a Senior Platform Security Engineer, Threat Detection to join our Security Team. This role will investigate all types of threats in the CircleCI Cloud environment by conducting behavioral analysis during builds, assessing network traffic behavior, staying up to speed on malware trends, work proactively with third-party partners combating platform abuse, build metrics that establish benchmarks future work is measured against, and respond to incidents. Their primary duty is to identify users who are using CircleCI in ways that are against our Terms of Service and compliance requirements.

A typical day could include analyzing customer configuration code, consulting with legal, examining our system for evidence of new exploits, reverse engineering them and building tools to detect and protect us from them.

The Security team is a highly-distributed team that’s building a paved security path so our team of roughly 200 engineers can ensure our infrastructure provides value to legitimate customers. You'll write sustainable, resilient code as part of an engineering organization that values teamwork, trust, and learning.

Be part of a team at the heart of CircleCI’s business responsible for build environments used by thousands of development teams every day!

What You’ll Do:

  • Establish a refined culture of security observability and monitoring
  • Partner with Security Operations, Product, Legal and Platform Security Engineering
  • Write and maintain sustainable, high-quality, high-performance code for infrastructure and security automation
  • Reverse engineer malware
  • Build tooling to analyze new open source code that CircleCI is processing
  • Research and understand the landscape of cryptomining malware
  • Identify entry points malware utilize for our product’s free tier
  • Participate in the Security Team’s on-call incident rotation
  • Respond to bug emails submitted by security researchers and work on remediation

About You:

You value and know the importance of developing, documenting and educating others on best practices and processes for achieving goals. Learning something new every day is essential to your happiness. Mentoring is a primary reason why you love your profession. You are compassionate and genuinely like people. You love looking at obfuscated source code, solving difficult detection problems, thinking about how to make the game of malware not worth playing for your adversary, and discovering innovative abuses of everyday tools.

Does that sound like you? If so, here’s the experience we’re looking for:

  • Security mindset and strong analytical skills
  • Understanding of malware architecture, torrents, cryptomining, botnets, DDOS and other automated use against our terms of service
  • 5+ years experience researching malware and/or programmatic abuse of cloud environments
  • Excellent communication skills and ability to remain Calm under high-pressure situations
  • Experience working with Docker, Kubernetes, Terraform, Helm, AWS, and modern distributed SaaS infrastructure
  • A willingness to learn new languages. We use Clojure, Go and TypeScript and our customers use almost every language under the sun
  • Web, database, information and/or infrastructure security
  • A focus on delivering high-quality code through strong testing practices
  • Ability to manage customer demands and work with internal stakeholders to deliver on them
  • Demonstrated ability to lead multiple, complex projects simultaneously

About CircleCI

CircleCI is the world’s largest shared continuous integration and continuous delivery (CI/CD) platform, and the central hub where code moves from idea to delivery. As one of the most-used DevOps tools that processes more than 1 million builds a day, CircleCI has unique access to data on how engineering teams work, and how their code runs. Companies like Spotify, Coinbase, Stitch Fix, and BuzzFeed use us to improve engineering team productivity, release better products, and get to market faster.

CircleCI is proud to be an Equal Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law.


Level: Mid-Senior Level

Apply for this Job

* Required



At CircleCI we deeply understand the value of bringing together a team with different perspectives, backgrounds and experiences, and welcome all applicants regardless of race, color, religion, creed, age, national origin or ancestry, ethnicity, sex, sexual orientation, gender identity or expression, disability, military or veteran status.

While the disclosure of your personal information is optional, completely anonymous and not attached to your application, we ask you to consider sharing this information to help us understand who is interested in working here, and help us get better at providing a positive, fair and unbiased experience for all applicants.  We understand that many applicants, especially those of marginalized groups, are often fearful that disclosing this personal information might create a barrier of entry for them.  We want to assure you that your answers will remain absolutely anonymous, and that we will use this data only to help us get better at supporting all candidates as they move through our interview process.

We appreciate your help and for your trust in our efforts to make CircleCI a place of equal opportunity for everyone.

How do you identify your gender?

Are you a veteran?

What is your ability status?

Which races/ethnicities do you belong to?