Description
We're looking for a Security Engineer to join the ElevenLabs Security team. In this role, you'll work at the intersection of security, software, and infrastructure engineering, building the platforms, controls, and tooling that let teams ship and operate cloud infrastructure securely at high velocity.
You will design and build security tools and guardrails that integrate directly into our infrastructure and products. You will partner with Engineering and Infrastructure teams to review application architectures, develop threat models, and build in secure by default patterns throughout the software development lifecycle.
You will identify, prioritise, and remediate security vulnerabilities, working directly with engineers and contributing to fixes where required, across the entire stack. You will ship new security features that directly improve the security posture of our products in production.
Design and implement supply chain security controls across build and deployment pipelines, including artefact signing, provenance, dynamic admission controls, and SBOM generation.
Strong engineering background, with experience building and shipping production systems. Proven track record of building and scaling security programs. Fluency in at least one programming language (Python, Typescript, Golang etc) with the ability to read, write, and maintain production quality code.
Hands-on experience in cloud-native environments (AWS or GCP), Kubernetes, and infrastructure-as-code (Terraform). Strong understanding of cloud security fundamentals: IAM, networking, PKI, Linux internals. Experience securing CI/CD pipelines to prevent supply chain attacks.
Bonus: Experience securing AI or Machine Learning systems, including training pipelines. Background in developer experience or platform engineering, especially building developer tooling. Contributions to open source security projects, published research, or talks at security conferences. Experience working in regulated environments (SOC 2, ISO27001, PCI, HIPAA or similar).
This role is remote and can be executed globally. However, to facilitate working with the Security Team, we prefer candidates based in GMT to GMT+3 or UK. If you prefer, you can work from our offices in Dublin, London, or Warsaw.