Position

Senior Security Engineer

Employment TypeFull-time
LocationRemote, United States (East Coast)

The Role

We're looking for a US East Coast-based Senior Security Engineer to join Bird's security team: a small group of engineers and experienced security experts who own security (and IT) across the entire company. This is a hands-on builder role with a scope most security jobs can't offer. In the same week you might pentest a new product feature before release, ship the fix for a vulnerability you found, tune a detection in our SIEM, harden our Okta configuration, and pair with product engineering on a customer-facing feature like SSO or SCIM.

If you've been doing excellent work in a narrower role at a strong tech company, whether that's pentesting, incident response, detection, or security engineering, and you want far more scope, responsibility, and freedom than a ticket queue allows, this role is built for you.

We're a small team based in the Netherlands and Belgium, and we work in a way that suits people who like ownership: we do what needs to be done, we do it fast, and we don't let blockers sit. Much of what we tackle has no mature process yet, so you work out a sound path forward and take it. In return you get genuine autonomy, impact you can see across the company every day, and teammates who geek out about security. We also build with AI aggressively, from agentic vulnerability triage to AI-assisted alert handling, and we expect you to treat AI as a daily multiplier rather than a novelty.

What You'll Do

Offensive Security & Vulnerability Management

  • Hack our platforms and products: pentest new features and products before they ship
  • Help run our vulnerability management program end-to-end, triaging findings from bug bounty, scanners, and pentests, and often fixing them yourself rather than handing them off

Cloud & Attack Surface

  • Raise the security posture of our AWS organisations with preventative guardrails and detective controls, such as SCPs, IMDSv2 enforcement, and GuardDuty
  • Keep our internet-facing attack surface continuously mapped, scanned, and shrinking

Detection & Incident Response

  • Build and tune detections, handle alerts, and act as a technical incident handler when something real happens
  • Detect and prevent abuse and fraud on our platforms

Corporate & Endpoint Security

  • Secure our corporate environment: SaaS application security, identity and access management, Okta, and Google Workspace hardening
  • Contribute to endpoint and device security (MDM, device lifecycle, endpoint hardening), since the security team owns IT at Bird and everyone shares in it

Customer-Facing Security Features

  • Build security features alongside our engineering teams: SSO, MFA improvements, SCIM, audit logging, and session controls for our enterprise customers

Automation & Shared Load

  • Build security automations, increasingly with AI and LLMs. We'd rather automate a task than staff it
  • Take a rotating turn as the team's operational point of contact for access requests, security questions, and IT support. Everyone shares the operational load, and we keep automating it down

What You'll Bring

  • 3+ years of hands-on experience in technical security roles: penetration tester, incident responder, security engineer, or similar. We care about demonstrated capability, not years served
  • The ability to script and automate in at least one major language, and comfort reading code you didn't write
  • Deep technical curiosity: you take things apart to understand them, and you're drawn to problems beyond whatever your current role says you own
  • Comfort operating without a playbook: when you hit an unfamiliar problem, you work out a sound path forward instead of waiting for a defined process, and when something is material enough to escalate, you bring a recommendation rather than an open question
  • A bias to done: thorough and organised, but you'd rather ship a good fix today than a perfect one next sprint. Blockers are things you clear, not things you report
  • You already use AI tooling as a serious force multiplier in your day-to-day work and want to push it further
  • Clear communication with engineers, leadership, and customers. You can explain the same vulnerability to the engineer fixing it and to an enterprise customer's security team

Nice to Have

  • You've shipped production code. The feature-development side of this role goes deeper if you have
  • Cloud security depth in AWS (IAM, organisation-level controls, GuardDuty) or Kubernetes security
  • Hands-on experience with Okta, MDM platforms such as Jamf, or SIEM and detection engineering
  • A public security track record: bug bounty findings, CVEs, CTF placements, open-source tooling, or published research
  • Experience building with LLMs: agents, security automation, or internal tooling

Ready to join us?

Send your resume to hr@bird.com with the role title in the subject line.

Your next idea.
Ready to connect.