Logo for CircleCI

Security Operations Engineer

Role overview

Qualifications

  • 3+ years of security engineering or security operations experience, or equivalent demonstrated expertise.
  • Hands-on experience with cloud, application, and CI/CD security, ideally in AWS, GCP, or Azure environments.
  • Experience with security incident response and common security tooling, including EDR, CNAPP, SASE, vulnerability scanners, and log analysis.
  • Ability to build and maintain security automation and tooling, with experience in languages or technologies such as Go, Python, or Terraform.

Responsibilities

  • Monitor, investigate, and respond to security threats across CircleCI’s cloud and application environments, using security and AI-assisted tooling to improve detection and triage.
  • Participate in security risk assessments, incident response, post-incident reviews, and rotating on-call support, turning findings into stronger controls and processes.
  • Build and maintain security tooling, controls, and automation across cloud, application, and CI/CD environments, following established security patterns and best practices.
  • Partner with Engineering teams to understand security needs, provide practical guidance, and translate technical risks into clear, actionable recommendations.

Key facts

  • Remote from: Canada
  • Full time
  • Mid-level (2-5 years)
  • Security Operations Engineer
  • 160 - 160K yearly
  • English

Hard skills

Other skills

  • Problem Solving

About the company

CircleCI logo

CircleCI

Developer Tools & DevOps Platforms

Modern software builders need to reduce risk and confidently ship. In an ever-shifting tech landscape, that’s harder than ever. This is why we built CircleCI: the CI/CD platform that makes it easier for developers to win at software. At CircleCI, we know that velocity must go hand in hand with building securely. World-class engineering teams don’t sacrifice security for speed but rather choose CircleCI to deliver both. Our product philosophy for our customers has eight pillars: 1. Security for all: We believe that security features should be accessible to all customers, regardless of their plan level. 2. Unobtrusive security: We design security features to be intuitive and easy to use and believe most of all they must not interfere with the user experience. 3. Secure by default: We build secure defaults out of the box. 4.Traceability: We believe visibility can drive accountability. 5.Store of no value: We strive to minimize the amount of valuable or sensitive data stored. 6. Fail securely: When we fail, we fail securely. 7. Least privilege: We grant users and systems only the minimum level of access necessary to perform their intended functions. 8. Complete mediation: We ensure that all user actions are fully authorized and authenticated at all times. CircleCI enables developers to build faster, more secure, and more reliable pipelines, without needing to be a CI/CD expert. As a result, teams building on CircleCI regularly achieve elite software delivery benchmarks.

Company details

Company typeSME
IndustryDeveloper Tools & DevOps Platforms
Company size501 - 1000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Security Operations Engineer

About the Team

The Security Operations team plays a critical role in protecting CircleCI’s infrastructure, product, and customer data against an evolving threat landscape. From incident response to hardening our cloud and CI/CD environments, the team works closely with engineering to keep CircleCI secure, resilient, and ready for what’s next.

About the Role

As a Security Operations Engineer, you’ll play a key role in protecting CircleCI’s infrastructure, product, and customer data against an evolving threat landscape increasingly shaped by AI-driven attacks and AI-augmented defenses. This intermediate-level role offers the opportunity to take meaningful ownership of security challenges, work closely with Engineering as a trusted security partner, and expand your impact across the organization. You’ll contribute to our security roadmap while leveraging AI tooling to advance how we detect, respond to, and automate security threats across CircleCI.

What You’ll Do:

Threat Detection & Incident Response

  • Monitor, investigate, and respond to security threats across CircleCI’s cloud and application environments, using security and AI-assisted tooling to improve detection and triage.
  • Participate in security risk assessments, incident response, post-incident reviews, and rotating on-call support, turning findings into stronger controls and processes.

Security Engineering & Architecture

  • Build and maintain security tooling, controls, and automation across cloud, application, and CI/CD environments, following established security patterns and best practices.
  • Identify vulnerabilities and configuration risks, contribute to security runbooks and compliance requirements, and develop a growing understanding of CircleCI’s security architecture.

AI & Security

  • Incorporate AI-powered security tools into day-to-day workflows and help evaluate emerging technologies that can improve detection, response, and automation.
  • Stay current on AI-specific security threats and contribute to responsible approaches for using AI in security operations.

Cross-Team Partnership & Ownership

  • Partner with Engineering teams to understand security needs, provide practical guidance, and translate technical risks into clear, actionable recommendations.
  • Contribute to security roadmap planning, technology evaluations, and team documentation while building strong relationships across Security and Engineering.

What You’ll Bring:

  • 3+ years of security engineering or security operations experience, or equivalent demonstrated expertise.
  • Hands-on experience with cloud, application, and CI/CD security, ideally in AWS, GCP, or Azure environments.
  • Experience with security incident response and common security tooling, including EDR, CNAPP, SASE, vulnerability scanners, and log analysis.
  • Ability to build and maintain security automation and tooling, with experience in languages or technologies such as Go, Python, or Terraform.
  • Strong security judgment and problem-solving skills, with the ability to assess risk, make recommendations, and take action when information is incomplete.
  • Hands-on experience using AI/ML-powered security tools in a production environment, with an understanding of where AI can improve security workflows and where human judgment remains essential.

Bonus Skills (Nice to Have)

  • Familiarity with AI-specific threat categories (prompt injection, model supply chain risks, LLM abuse patterns).
  • Experience securing developer platforms, SaaS environments, or CI/CD infrastructure.
  • Relevant certifications: CEH, AWS Security Specialty, Security+, or equivalent.
  • Contributions to team process improvement, security runbook development, or internal knowledge sharing.
Canada Base Pay Range$127,500—$159,500 CAD

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

About CircleCI

CircleCI is the world’s largest continuous integration/continuous delivery (CI/CD) platform, and the hub where code moves from idea to delivery. As one of the most-used DevOps tools - processing more than 3 million jobs a day - CircleCI has unique access to data on how the most effective engineering teams work, and the tools to help software companies successfully leverage the power of AI into their commercial applications. Companies like Hinge, HuggingFace, and Samsung use us to improve engineering team productivity, release better products, and get to market faster.


Founded in 2011 and headquartered in downtown San Francisco with a global, remote workforce, CircleCI is venture-backed by Base10, Greenspring Associates, Eleven Prime, IVP, Sapphire Ventures, Top Tier Capital Partners, Baseline Ventures, Threshold
Ventures, Scale Venture Partners, Owl Rock Capital, Next Equity Partners, Heavybit, and Harrison Metal Capital. 

CircleCI is an Equal Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Operations Engineer Related jobs

Other jobs at CircleCI

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.