PostHog logo

PostHog

Security Engineer

Region Restricted

Remote work allowed only within certain countries or regions.

Europe

Employer listed it 9 days ago · Added 4 days ago

First listed 9 days ago and still open.

Salary

Not stated

Location

Europe

Work style

Async

Contract

Full-time

Experience

Mid

Category

Software

This employer didn't state pay. Jobs like this usually pay around $165k–$255k a year, a typical range taken from 594 mid-level software roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Region Restricted

Remote work is allowed, but only for candidates based in Europe.

What the employer says

  • Source listing states candidate location: "Remote (EMEA), Remote (UK), Remote"

What Nomaders makes of it

  • Applications outside the listed area are usually rejected
  • Timezone overlap with the listed area is often expected

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About PostHog

Product development used to mean manually writing code, running analysis, diagnosing bugs, and rolling out changes using dozens of tools.

PostHog makes products self-driving . It's the only platform that acts like a co-pilot for you (and your AI agents) to do it all – autonomously.

We started with open-source product analytics, launched out of Y Combinator's W20 cohort . We've since shipped more than a dozen products , including:

PostHog Desktop , the only AI devtool that understands your product, not just your codebase.

A built-in data warehouse , so users can query product and customer data together using custom SQL insights.

PostHog AI , an AI-powered analyst that answers product questions, helps users find useful session recordings, and writes custom SQL queries.

We are:

Product-led . More than 450,000 organizations have installed PostHog, mostly driven by word-of-mouth. We have intensely strong product-market fit.

Default alive . Revenue is growing incredibly quickly, and we're very efficient. We raise money to push ambition and grow faster, not to keep the lights on.

Well-funded. We've raised more than $180m from some of the world's top investors. We're set up for a long, ambitious journey.

We're focused on building an awesome product for end users, hiring exceptional teammates, shipping fast, and being as weird as possible .

Things we care about

Transparency: Everyone can read about our roadmap, how we pay (or even let go of) people, our strategy, and how we work, in our public company handbook . Internally, we share revenue, notes and slides from board meetings, and fundraising plans, so everyone has the context they need to make good decisions.

Autonomy: We don’t tell anyone what to do. Everyone chooses what to work on next based on what's going to have the biggest impact on our customers, and what they find interesting and motivating to work on. Engineers lead product teams and make product decisions . Teams are flexible and easy to change when needed.

Shipping fast: Why not now? We want to build a lot of products; we can't do that shipping at a normal pace. We've built the company around small teams – autonomous, highly-efficient groups of cracked engineers who can outship much larger companies because they own their products end-to-end.

Time for building: Nothing gets shipped in a meeting. We're a natively remote company. We default to async communication – PRs > Issues > Slack. Tuesdays and Thursdays are meeting-free days , and we prioritize heads down building time over perfect coordination. This will be the most productive job you've ever had.

Ambition: We want to solve big problems. We strongly believe that aiming for the best possible upside, and sometimes missing, is better than never trying. We're optimistic about what's possible and our ability to get there.

Being weird: Weird means redesigning an already world-class website for the 5th time. It means shipping literally every product that relates to customer data. It means building an objectively unnecessary developer toy with dubious shareholder value. Doing weird stuff is a competitive advantage. And it's fun.

Who we're looking for

We are looking for an expert security generalist (in EU/UK) to assist with all things security at PostHog. Someone equally adept (and interested!) in building secure libraries, writing semgrep rules, hardening cloud deployments, improving network observability, and leading incident response.

Someone to take the reins of our security operations, build out our detection pipelines, and ensure that when something goes bump in the night, we have the observability to know exactly what happened. We're a team that's building internal security products and agents - things like agents to automatically triage wiz alerts, automatically review pull requests, automatically assign vulnerability findings to the owning product team.

In this role you’ll:

Build from Scratch: You aren't maintaining someone else's legacy SIEM. You are shaping the security team, culture and tooling for a high-growth, open-source company.

Requirements

  • ·Cloud Native: You have 3-5+ years of experience in security engineering with a heavy focus on AWS. You know your way around IAM, VPC logs, and CloudTrail like the back of your hand.
  • ·Detection Specialist: You’ve used CSPM/CNAPP tools (like Wiz or Prisma) and, more importantly, you know how to build detection pipelines that engineers actually trust.
  • ·Battle-Tested: You’ve led incident response before. You’re calm under pressure and know how to coordinate across teams to contain a threat.
  • ·High Autonomy: We don’t have a security SOC. You’ll be building this function from scratch, so you need to be comfortable deciding what’s important and executing on it without a manual.
  • ·Engineering skills: You bring strong engineering experience and next to digging into code to understand an exploit or a vulnerability, you can write code with the same proficiency as our product engineers.

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, region restricted, matches where you plan to live and work.
  2. 2Tailor your CV to the role at PostHog, mentioning your remote working experience and working hours (Async).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $165k–$255k · You'll be taken to the employer's careers page.