Why This Job is Featured on The SaaS Jobs
Trust is a core product attribute in SaaS, and this Information Security Engineer role sits directly on that boundary between platform reliability and customer confidence. The remit spans infrastructure and product security, indicating a company operating a cloud service where security controls, monitoring, and secure delivery pipelines are part of day to day engineering rather than a separate audit function.
For a SaaS career, the role offers broad exposure to the mechanics of running secure multi tenant systems at scale: building automated controls, improving detection and remediation, and partnering with product and engineering as features ship. Work across incident response, threat modeling, vendor risk, and programs like SOC 2 and ISO 27001 builds a portfolio that transfers well across B2B SaaS, where security posture increasingly influences enterprise sales cycles and renewal decisions.
This position tends to suit security engineers who prefer pragmatic engineering over checkbox compliance, and who are comfortable operating across tooling, cloud environments, and cross functional communication. It also fits someone who wants ownership in shaping standards and processes, with enough technical depth to automate and integrate security into existing development workflows in a distributed SaaS environment.
The section above is editorial commentary from The SaaS Jobs, provided to help SaaS professionals understand the role in a broader industry context.
Job Description
At Algolia, Information Security is built into everything we do. It is not an afterthought; it’s a core design and operational principle. Our Information Security team ensures that trust, privacy, and resilience are embedded throughout our infrastructure, products, and internal processes.
As Algolia continues to expand globally, we are growing our Information Security team to match that scale. We are seeking a North-American based, pragmatic, technically strong, and collaborative information security engineer to strengthen our Information Security posture and enable the company to innovate securely and confidently.
What You’ll Do
- Design and automate controls, detection mechanisms, and tooling to improve the Information Security of Algolia’s infrastructure and products
- Research, evaluate, and recommend new Information Security technologies, techniques, and frameworks
- Design, implement, and maintain information security monitoring and remediation systems that move the needle in protecting Algolia’s customers’ data, and protecting Algolia’s systems and data
- Partner with engineering and product teams to integrate Information Security into new features, systems, and development pipelines
- Contribute to improving Information Security standards, processes, and best practices across the company
- Conduct Information Security risk assessments and threat models of core systems, services, and third-party vendors (this does not include answering customer third-party risk assessment questionnaires).
- Participate in and sometimes lead Information Security incident response activities and post-incident analysis
- Support ongoing and emerging Information Security and compliance initiatives (e.g., SOC 2, Type II, ISO 27001, C5, GDPR)
- Manage and enhance Algolia’s public bug bounty and vulnerability disclosure programs
What We’re Looking For
- 3–6 years of experience in Information Security engineering, infrastructure protection, or related technical domains
- Proficiency in scripting or automation with at least one language (Python, Bash, Go, or similar) is required. Experience with Kubernetes is preferred.
- Strong understanding of Information Security principles for modern cloud environments (AWS, GCP, or Azure) as well as operations in datacenters.
- Strong understanding of, comfort with, and at least three years of experience in operating, configuring, and managing log management / SIEM, threat detection and posture management, endpoint detection and response, SAST, SOAR, CTI, and other table-stakes information security systems with strong preference to at least one year of experience with deep use of Crowdstrike or Obsidian (preferably both).
- Knowledge of common internet Information Security threats, attack vectors, and mitigation strategies
- Solid understanding of computer systems, networks, and low-level protocols from an Information Security perspective
- Experience in incident detection, response, and vulnerability management
- Excellent communication skills, with the ability to explain Information Security risks and concepts to both technical and non-technical audiences
- Clear ability to collaborate with VP of Information security to advise on next steps and to work independently to achieve business outcomes - rather than a ticket based approach.
- Full professional proficiency in English
Nice to Have
- Experience scaling Information Security programs in high-growth SaaS organizations (10,000+ customers, $50–200M ARR range)
- Cloud-specific Information Security certifications or equivalent training (e.g., AWS Security Specialty, GCP Professional Security Engineer)
- Experience with complex secrets management systems such as Hashicorp Vault
- Experience contributing to Information Security communities, such as bug bounty triage, open-source security tools, or Capture the Flag events
- Background in privacy engineering, threat modeling, or secure software design
Why You’ll Love Working Here
- A culture that values continuous learning, curiosity, and collaboration in Information Security
- A global, remote-friendly team that treats Information Security as an enabler of innovation
- Opportunities to make a measurable impact on the Information Security of systems used by millions of end users
- Ongoing professional development and support as the Information Security landscape evolves
Location: Remote or hybrid (depending on region) within the Eastern or Central timezones In the US