Upwind Security logo

Security Engineer

Upwind Security
19 hours ago
Full-time
On-site
San Francisco, California, United States

Upwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management. Unlike traditional tools, Upwind uses runtime data proactively for risk prioritization and posture insights, ensuring teams focus on what truly matters. With industry-leading efficiency and eBPF-powered sensors, Upwind delivers comprehensive capabilities, including agentless cloud posture discovery, real-time threat protection, and integrated API security. From misconfigurations to malware defense, Upwind ensures end-to-end, cost-effective cloud infrastructure protection. At Upwind, you’ll have the opportunity to think creatively, explore new ideas, and use your skills to make a meaningful impact on our growth.

We are looking for a Security Engineer to join our MDR team as the founding U.S. member of the Security organization. In this role, you will be part of our security function, focusing on proactive reviews and providing advanced guidance to customers, while independently owning U.S.-hours coverage. This is an opportunity to bring deep cloud security expertise to a fast-growing team, working closely with analysts, researchers, and engineers — with a clear path toward technical or team leadership as the U.S. presence scales.

Responsibilities

  • Assist in fine-tuning Upwind's detection and response mechanisms.
  • Support proactive reviews of customer environments to identify risks, exposed attack surfaces, and recommend improvements.
  • Lead and conduct in-depth security investigations — including supply chain, API, malware, and runtime attack scenarios — documenting outcomes and developing playbooks to enhance future detection and response.
  • Collaborate with Security Analysts, Research, and Backend teams to enhance detection quality.
  • Own the handling of complex or critical incidents escalated from Tier 1/2, including live, high-pressure engagements with customers.
  • Participate in recurring customer meetings, helping translate security findings into clear, actionable recommendations — and maintain composure when conversations get tense.
  • Stay up to date with emerging threats, attack techniques, attack surfaces, and best practices in cloud security.
  • Contribute to the development and training of AI-driven detection models, leveraging machine learning to improve investigation accuracy and response efficiency.
  • Based in Boston, MA or San Francisco, CA. This is an on-site role; visa sponsorship is not available.
  • This role includes participating in a shared on-call rotation. While escalations are infrequent, team members are expected to be available for nights, weekends, or holidays during their rotation week.
  • Solid, hands-on experience in cybersecurity, ideally from a leading cloud or cloud security company, with real-world exposure to cloud environments.
  • Strong working knowledge of detection engineering, incident response, and threat analysis, with the ability to explain attack techniques (supply chain, API, malware, runtime) in depth.
  • Hands-on experience with at least one major cloud platform (AWS, GCP, or Azure) and container technologies (Docker/Kubernetes).
  • Comfortable and hands-on with Linux; Windows knowledge is a plus.
  • Familiarity with networking fundamentals and scripting (Python/Bash).
  • Strong communication and presentation skills, with proven ability to engage directly with customers — including staying composed under pressure or pushback.
  • Self-directed and comfortable operating independently in a fast-paced, high-ownership startup environment.
  • Curiosity, problem-solving mindset, and a genuine personal interest in security beyond the day job.
  • B.Sc. in Computer Science / Information Security — an advantage.