We are looking for forward-deployed security engineers who want to build the future of security operations with agents.
Tracecat helps AI-native security teams move at machine speed with agents they own and control. Our users automate security operations across detection and response, cloud, infrastructure, identity, vulnerability management, compliance, and internal workflows.
You’ll work directly with the founders and our customers, architect agents that automate real security work, and turn what you learn in the field into product capabilities that run in mission-critical environments. This is a high ownership role at an AI-native open core company winning deals against competitors 100x their size.
What you’ll do
You won’t just field customer requests. You’ll shape how security teams use agents to run security work.
Work directly with security teams to design and deploy agentic systems across their security stack
Build agents that investigate alerts, gather evidence, reason over context, recommend decisions, and trigger approved actions
Build Python integrations, agent skills, MCP tools, and data pipelines that give agents the context and tools they need
Design agents for detection and response, cloud findings, identity investigations, vulnerability response, case management, and recurring security operations
Evaluate agents for accuracy, approvals, auditability, failure modes, and analyst experience
Work with the founders and product team to turn repeated customer patterns into reusable agents and product capabilities
What you bring
Security judgment: you understand how teams investigate, prioritize, and respond to risk across cloud, infrastructure, identity, and production environments
Hands-on experience in security engineering, cloud security, infrastructure security, detection and response, incident response, product security, application security, or a related role
Strong full-stack development skills and experience building APIs, integrations, data pipelines, internal tools, or production automation
Product intuition: you can turn one-off customer problems into reusable product primitives
Customer empathy: you can work with analysts, responders, security engineers, security leaders, and founders without losing the technical thread
Comfort working in a small team where speed, ownership, and ambiguity are the norm
Technical craftsmanship: we’re an anti-slop AI-pilled company, and security automation should be auditable, testable, and boring when it matters
Slope over intercept: we value learning velocity, grit, and unapologetically unique personalities
Bonus
Prior experience building agents, copilots, MCP servers, tool-calling systems, evals, or sandboxed automation
Prior experience as a forward deployed engineer, founding engineer, security engineer, incident responder, detection engineer, cloud security engineer, infrastructure security engineer, or security consultant who still writes code
Experience with production security tooling across SIEM, EDR, cloud, identity, infrastructure, or vulnerability management
Familiarity with security frameworks, investigation languages, cloud audit logs, IAM, or infrastructure-as-code
Threat hunting, adversary emulation, red team, or offensive security experience
Experience deploying software into customer VPCs, on-prem environments, regulated environments, or high-assurance networks
Open source contributions or experience working in large production codebases
Company benefits:
Competitive compensation and meaningful equity
20 days paid time off every year
15 days of remote work flexibility per year
100% coverage for health, dental, vision
Wellness stipend to spend on gym, spa, or whatever keeps you at your best
Free lunch
Team offsites
About Tracecat
Tracecat helps AI-native security teams build agents and automate work.
Used by the most demanding security teams in mission-critical environments across defense, finance, federal and more. Open source and community driven at it's core: https://github.com/TracecatHQ/tracecat