Synthesia
SecOps Security Engineer (Staff-level, L6)
- Location
- US Remote, US
- Arrangement
- Remote
- Employment type
- Full-time
- Posted
- 25 August 2026 (about a month ago)
Checked about a month agoApplications go to the employer, never to RoleSprint
About this role
Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and teams across Europe and the US.
As AI continues to shape the way we live and work, Synthesia develops products to enhance visual communication and enterprise skill development, helping people work better and stay at the center of successful organizations.
Following our recent Series E funding round, where we raised $200 million, our valuation stands at $4 billion. Our total funding exceeds $530 million from premier investors including Accel, NVentures (Nvidia's VC arm), Kleiner Perkins, GV, and Evantic Capital, alongside the founders and operators of Stripe, Datadog, Miro, and Webflow.
Location: Remote (US East Coast/Central)
As our team and customer base grow, we need to make sure our security efforts scale accordingly. For that, we are looking to expand the Synthesia Infosec team by onboarding an additional Security Engineer (L6)! You will report to the Head of Security and work within the Security Operations team.
KEY RESPONSIBILITIES:
- Build and own deeply technical security improvements across our Cloud Infrastructure(s) and associated territory (AWS/GCP, Kubernetes, CI/CD), including shipping production changes yourself when needed.
- Design, implement, and iterate on detection and response capabilities (SIEM, EDR/MDR, cloud-native detections, CNAPP) with an engineer’s bias for automation, reliability, and measurable outcomes.
- Hunt, investigate, and respond to security alerts and suspicious activity end-to-end (triage → containment → eradication → recovery → learnings), including writing tooling and detection logic to prevent recurrence.
- Build internal security tooling and automations (IaC, scripts, integrations) that reduce toil and raise the security bar by default.
EXPERIENCE & QUALIFICATIONS:
- You’re a deeply technical security engineer with a builder/hacker mindset, able to go from idea → prototype → production and comfortable making changes directly in Cloud Infra / DevOps systems.
- You have 5+ years of hands-on security engineering experience, ideally in a cloud-first SaaS environment.
- Have worked in a fast-growing startup, scale-up and/or SaaS company
WE WOULD EXPECT YOU TO HAVE EXPERIENCE IN:
- Cloud security engineering in AWS and/or GCP, with the ability to implement improvements hands-on (IAM, networking, compute, storage, logging).
- Kubernetes security (cluster hardening, workload isolation, runtime security, policy controls) and container ecosystems.
- DevOps fundamentals: CI/CD security, secrets management, artifact integrity, and secure-by-default platform patterns.
- Incident response and investigation, including creating repeatable playbooks and automating response where appropriate.
- Strong programming/scripting ability (Python or similar) plus comfort with infrastructure-as-code (e.g., Terraform) and automation.
- Serious agent coding - ideally you’re on the bleeding edge in the space.
- Endpoint security tooling, such as CrowdStrike
Bonus points for:
- Hands on experience with any/all of: Hunters, Wiz, Falcon, Tracebit, Torii, Okta, Google Workspace, StrongDM, Github, StepSecurity, Dope Security
- Any relevant Information Security certification, e.g AWS Certified Security, GIAC GWEB, OSCP, or CSSLP.
THE GOOD STUFF..
In addition to being a part of a great team, working in a fun and innovative environment, we offer:
- A competitive salary + stock options in our fast-growing Series E startup
- Remote-friendly environment
- 100% Medical, Dental & Vision
- 401k Plan
- Paid parental leave
- 25 days of annual leave + Public holidays + paid sick leave
- Fun culture with regular socials
- A generous referral scheme
- A brand new computer + monitor
- Budget and support for conference travel, community events, and content production
Eligible remote locations
- US
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Advertised by Synthesia and published on Ashby, the applicant tracking system they use.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 25 August 2026, last checked about a month ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.