EngineerJobs.io
← Back to all jobs

Job Description

Miradero Cybersecurity offers a 호 or open-ended landscape to shape a security platform from the ground up. This remote California role places you at the core of the engineering effort, with a salary range of USD 100,000 to 150,000 per year. As the first engineering hire, you will define architectural direction, own the telemetry pipeline, and lead the development of a private AI stack that differentiates us from legacy MSSPs. You will collaborate with a lean, high-trust team and have opportunities for technical leadership and equity-based growth in a well-funded startup environment.

Benefits

  • Dental insurance
  • Health insurance
  • Paid time off
  • Vision insurance

Why join Miradero Cybersecurity

  • Founding Influence: You are the first engineering hire. Your architectural decisions will shape the company’s technical trajectory.
  • The AI Moat: Lead the implementation of a private, local AI stack to create a technical edge over traditional MSSPs.
  • Equity & Growth: Employee equity options in a lean, well-funded startup with a clear path to technical leadership.
  • Operational Autonomy: A high trust, low micromanagement environment that enables independent ownership.

The right personality

  • Builder Mentality: Prefer creating durable tools that solve problems rather than repeating manual fixes.
  • Low Ego / High Output: Comfortable collaborating with a CTO and operating as a peer to the SOC Manager.
  • Precision-Driven: Value documentation and architectural clarity over quick, ad-hoc solutions.

Responsibilities

  • Platform Engineering: Architect and implement the multi-tenant telemetry pipeline and enable Detection-as-Code using GitHub or GitLab for version control and CI/CD deployment of detection logic.
  • Tooling Orchestration: Manage the configuration and integration of CrowdStrike Falcon (EDR) and ArmorPoint (XDR/SIEM), ensuring high-signal telemetry flows from endpoints to analysts.
  • Python Development: Write production-grade Python scripts to automate SOC tasks, build custom API integrations between security tools and PSA/Documentation systems, and develop internal tooling.
  • AI Implementation: Co-lead the development of the private AI layer, building Retrieval-Augmented Generation pipelines and LLM-based classifiers to automate triage and summarize findings.
  • Detection Authoring: Serve as the senior authority for detection content across CrowdStrike and ArmorPoint, tuning rules to minimize false positives.
  • Technical Pre-Sales: Act as the technical authority on standard client engagements, scoping pilot deployments and ensuring architectural sanity.
  • Escalation Engineering: Provide the final technical analysis for complex root-cause investigations that extend beyond the SOC's standard playbooks.

Requirements

  • 7+ years in Security Engineering, Detection Engineering, or Platform Architecture.
  • Strong Python skills are essential; ability to write clean, maintainable automation and API integration code.
  • DevOps Mindset: Fluent with GitHub and GitLab; experience with CI/CD and treating infrastructure and detections as code.
  • Deep tooling experience with CrowdStrike Falcon and ArmorPoint (or equivalent enterprise EDR/XDR platforms).
  • Solid understanding of cloud telemetry (AWS, Azure, GCP) and identity platforms (Entra ID, Okta).
  • Fluency with MITRE ATT&CK and translating tactics into practical detection logic.

Technologies

  • Python
  • GitHub
  • GitLab
  • CrowdStrike Falcon
  • ArmorPoint
  • AWS
  • Azure
  • GCP
  • Entra ID
  • Okta
  • MITRE ATT&CK
  • CQL
  • LogScale
  • RAG (Retrieval-Augmented Generation)
  • LLM

Similar Jobs