Atlan
About this role
Atlan builds the metadata and context layer enterprises put underneath their data and AI systems, and its posting says the platform serves more than 450 enterprise customers, naming General Motors, Nasdaq, Workday and Elastic. This security role is written for engineers rather than reviewers: the posting opens by saying that at Atlan security engineers ship products, and that if your instinct on seeing a recurring finding is to build the system that eliminates it permanently rather than file another ticket, this is the job. The work is AppSec and cloud security automation across AWS as primary plus GCP and Azure, building AI agents that triage vulnerabilities and review pull requests, and pushing SAST, SCA and secrets detection into CI and CD. It is listed remote in India, which makes it one of the few remote roles anywhere on today's board.
Who this is for
Required by the posting: 4 to 6 years of experience in a cloud native SaaS environment with demonstrated depth in at least two security domains, and the posting names AppSec plus cloud security as the preferred combination. Prior experience at a product startup or high growth company is valued. Hands on production experience building AI agents is stated as required, not optional, for the AI portion of the role.
The three areas of work the posting sets out. First, AI powered security agents: build agents that handle vulnerability triage, automated security review of pull requests, and initial incident forensics at scale. Second, cloud security automation: build systems that automatically detect and remediate configuration drift, IAM misconfigurations, vulnerable dependencies and exposed secrets across AWS as primary, plus GCP and Azure, owning it end to end rather than only the detection layer. Third, developer security or shift left: integrate SAST, SCA and secrets detection into CI and CD so secure by default is the path of least resistance for every engineer.
Location: the posting lists India and Atlan's own board metadata marks it remote, employment type full time.
Who should apply: security engineers four to six years in who write real code and would rather build the fix than raise the finding. If you are further along, Atlan's Senior Security Engineer for Corporate Security at 5 or more years is also on today's list and is a broader ownership role.
The three areas of work the posting sets out. First, AI powered security agents: build agents that handle vulnerability triage, automated security review of pull requests, and initial incident forensics at scale. Second, cloud security automation: build systems that automatically detect and remediate configuration drift, IAM misconfigurations, vulnerable dependencies and exposed secrets across AWS as primary, plus GCP and Azure, owning it end to end rather than only the detection layer. Third, developer security or shift left: integrate SAST, SCA and secrets detection into CI and CD so secure by default is the path of least resistance for every engineer.
Location: the posting lists India and Atlan's own board metadata marks it remote, employment type full time.
Who should apply: security engineers four to six years in who write real code and would rather build the fix than raise the finding. If you are further along, Atlan's Senior Security Engineer for Corporate Security at 5 or more years is also on today's list and is a broader ownership role.
Apply on company site
Opens jobs.ashbyhq.com, the employer's own application page. Applying is always free.