Security Engineer
Job Description
About Salt Security
Salt Security is the leader in agentic and API security, protecting the world's most innovative enterprises from AI agent and API attacks. Agentic security is the practice of discovering and governing the relationships between LLMs, MCP servers, and the APIs that let AI agents take action. The Salt Security Agentic Security Platform secures the full agentic ecosystem, discovering all agents, MCP connections, and APIs, stopping attacks in real time, and eliminating vulnerabilities before they reach production. Salt Security was founded in 2016 and is backed by Sequoia Capital, S Capital, Tenaya Capital, Salesforce Ventures, Advent International, and other leading investors. For more information, visit salt.security.
At Salt, we’re passionate about what we do. We work as a team and embrace new ideas, wherever they come from. We also enjoy all the benefits of a startup environment, including quickly seeing the results of your work, making an outsized impact on our company, and solving diverse challenges.
Want to make a big difference? We encourage you to apply!
About the Role:
We are looking for a Security Engineer with 1-2 years of experience to join our Internal Security team.
This role combines hands-on cloud and security operations with support for GRC and compliance activities.
You will be involved in securing our cloud, SaaS, and AI-driven systems, monitoring security events, and helping maintain our overall security posture. In parallel, you will support customer security questionnaires and compliance processes.
What You'll Do:
• Monitor, triage, and investigate security alerts and incidents across cloud and security tools (EDR, CASB, ZTNA, SaaS security platforms, and identity providers), and support response and remediation activities
• Assist in securing cloud environments (AWS/GCP/Azure), including IAM, access controls, network security, and CI/CD pipeline security
• Work closely with DevOps and IT teams to implement and enforce security best practices across infrastructure, endpoints, and SaaS systems
• Support vulnerability management processes, including scanning, prioritization, and remediation tracking
• Support risk management processes by identifying, assessing, and tracking risks, including vulnerability management, remediation efforts, and control gaps
• Support customer security questionnaires (RFPs/RFIs) with accurate technical responses
• Assist in maintaining compliance with frameworks such as SOC 2 and ISO 27001, including preparing audit evidence and documentation
Who You Are?
• 1-2 years of experience in cybersecurity, cloud security, and security operations
• Basic hands-on experience with cloud platforms (AWS, GCP, or Azure)
• Understanding of core security concepts: IAM, networking, least privilege, and secure configurations
• Experience or strong interest in collaborating with DevOps and IT teams, alongside a focus on AI security, data protection, and emerging technologies
• Familiarity with security tools such as EDR, vulnerability scanners, or SaaS security solutions
• Strong analytical and troubleshooting skills, with high attention to detail and the ability to manage multiple tasks
• Good communication skills and ability to work cross-functionally
• Willingness to learn and grow in both technical security and GRC domains
Nice to Have:
• Experience with cloud security best practices and securing CI/CD pipelines and infrastructure-as-code (Terraform, etc.)
• Familiarity with identity systems (Okta, Azure AD, etc.)
• Familiarity with compliance frameworks such as SOC 2, ISO 27001, or NIST
Requirements
Department: IT & Security