Remote
Security Engineer
About this role
Company Background Censys’ mission is to be the one place to understand everything on the internet. Frustrated by the lack of trustworthy Internet intelligence, we set out to create the industry’s most comprehensive, accurate, and up-to-date map of the Internet. Today, Censys delivers real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide.
Censys maps the internet. Our customers rely on us for the exposure and threat intelligence that shapes their security programs — which means the bar for our own security is not theoretical. You'll help set it. This is a senior, high-ownership role on a small team. You will own the identity program, cloud security posture, and vulnerability management end to end, serve as a core incident responder, and build the automation — increasingly agentic — that enables our team to operate at the scale of a much larger one.
You'll also be one of our most direct users of our own product: monitoring Censys's external attack surface with Censys is part of the job. We're looking for someone well-rounded rather than narrowly specialized, who is energized by AI and wants to build with it, and who is comfortable deciding what matters most when everything looks urgent. What You’ll Do: Identity & Access Management Own identity as a program, not a ticket queue.
Drive down standing access and manual provisioning over time for joiner-mover-leaver changes and non-human identity management. Cloud Security (GCP-first) Harden and continuously improve our cloud-native environment: organization policy, IAM least privilege, service account and workload identity hygiene, network segmentation, secrets management, and posture monitoring. Partner with SRE on infrastructure-as-code guardrails so security is enforced at build time, not discovered later.
Vulnerability Management Own the program: asset coverage, risk-based prioritization that weighs real exploitability and exposure rather than raw CVSS, defensible SLAs, hands-on partnership with engineering on remediation, and reporting leadership can act on. Use Censys to keep an outside-in view of our own attack surface. Detection & Incident Response Build detection coverage for identity, cloud, and SaaS. Share in the security escalation rotation, lead or co-lead high-severity incidents, run blameless post-incident reviews, and turn findings into durable fixes.