Lead offensive and defensive security engineering for a threat-hunting product: emulate attackers, perform threat research, design workflows, validate detection accuracy, run penetration tests and simulations, collaborate with data science, and guide product teams on security best practices.
About Us
System Two Security is driving SOC transformation with its unique application of AI computing with an initial focus on generative AI powered proactive threat research, threat analysis and iterative threat hunting. The product’s purpose-built language agents respond to new threat actors and attack patterns within minutes with its agentic workflows delivering end-to-end threat detection and containment from integrated feeds of raw cyber threat advisories. Early users of the product include prominent MSSPs, and enterprise SOCs across retail, healthcare, SaaS and technology verticals. It is based in Palo Alto, CA and is venture funded by The Hive.
Job Description
System Two Security is looking to hire a Principal Security Engineer with a wide expertise in both offensive and defensive measures in enterprise cybersecurity. The Principal Security Engineer is essential in enhancing development efforts for our flagship threat hunting product, working closely with Data Science and Data teams. This role puts you in a central role as the in-house expert focused on providing solution direction and validation for the System Two Security’s backend systems supporting the product. A key outcome is improving system accuracy.
Responsibilities
- Narrative Building: Integrate defensive tactics and controls with the threats and vulnerabilities into a single narrative.
- Emulation: Emulate the tools and techniques of attackers in the most realistic way possible.
- Threat Intelligence Research: Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations. Engage with peers and industry groups that share threat intelligence analytics. Conducting research to identify potential security threats
- Workflow Design: Develop efficient workflows for the threat hunting system.
- Accuracy Analysis: Assess and improve the accuracy of the S2S backend systems.
- Collaboration: Partner with the data science team to align efforts.
- Reporting: Communicate findings and insights effectively.
- Continuous Improvement: Seek ways to enhance cybersecurity practices within the product.
- Guidance: Provide guidance on industry standards and best practices to product managers and application developers.
- Design and execute testing and simulations: Penetration tests, technical controls assessments, cyber exercises, or resiliency simulations, and contribute to the development and refinement of assessment methodologies, tools, and frameworks
Required Skills
- Bachelor's degree in computer science, information technology, or a related field.
- 5+ years of work experience.
- Extensive experience in the field of cybersecurity.
- Experience in one or more technical roles in the areas of Security Operations, Threat Intelligence, Penetration Testing, Red Teaming, Purple Teaming, Threat Hunting or Incident Response.
- Experience with Threat Research and detection engineering.
- Experience in validation systems to reduce False Positives.
- Experience querying log sources within large centralized logging platforms, e.g. Splunk, Elastic, Cloudera, SQL.
- Functional understanding of how threat actors gain access, move laterally, privilege escalate, set persistence, and evade defenses to achieve objectives.
- Ability to critically examine an organization’s systems through the perspective of a threat actor and articulate risk in a clear and precise manner.
- Excellent communication and teamwork skills.
- Ability to stay up-to-date with the latest security trends and technologies.
- Ability to manage and balance business and technical requirements.
- Highly organized with an ability to manage competing priorities.
- Hold relevant industry certifications showcasing advanced expertise in cybersecurity and offensive testing methodologies or resiliency such as:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Offensive Security Certified Professional (OSCP)
- SANS Purple Team Certified
Preferred Skills
- Master's degree in cybersecurity or a related field.
- Experience developing AI.
- Strong leadership and project management skills.
- Experience building security technology roadmaps and transitioning in new technologies.
- Understand system and network telemetry generated by SOC tools.
- Experience in other technical areas: Security Products and Services, Security, Data and IP Services, Network Operations, and Cloud and Data Center Outsourcing.
- Experience with large scale data analysis.
- Working knowledge of MITRE ATT&CK framework.
Similar Jobs
Artificial Intelligence • Hardware • Information Technology • Machine Learning
Maintain, troubleshoot, calibrate, and monitor semiconductor manufacturing equipment. The technician performs preventive maintenance, documents equipment issues, analyzes performance data, communicates machine trends to engineering and production teams, supports failure analysis and continuous improvement projects, and follows safety procedures. The role also includes responding to customer needs, implementing action plans, and using approved AI tools to improve troubleshooting, documentation, and data analysis.
Top Skills:
Ai-Enabled ToolsCalibration EquipmentEquipment Tracking SystemsTest Equipment
Cloud • Information Technology • Security • Software
Develop and maintain distributed systems, microservices, and APIs primarily with Golang. Deploy applications using Kubernetes, Docker, and cloud infrastructure; build CI/CD pipelines; and integrate with native operating-system frameworks. Collaborate on UI components, apply AI throughout development and testing, and support device-management capabilities such as Apple, Android, and Windows enrollment. The role is remote within India and includes on-call participation.
Top Skills:
AdeAndroid EnterpriseApple MdmAWSAzureCC++DdmDockerGCPGithub ActionsGoGrpcJavaKubernetesNode.jsObjective-CPythonRestSwiftTypescriptVueWindows Mdm
Cloud • Information Technology • Security • Software
Develop cross-platform device management software for Windows, macOS, and Linux using Go and Node.js. Build endpoint management engines, system agents, MDM telemetry, enrollment pipelines, and highly available cloud APIs. Work with operating system internals, authentication and security protocols, automated testing, CI/CD, cloud platforms, containers, and Kubernetes. Collaborate across engineering and product teams in a Scrum environment, contribute to planning, mentor junior engineers, and participate in on-call rotations.
Top Skills:
AndroidAWSAzureC#C++Ci/CdDdmGCPGithub ActionsGoiOSJavaKubernetesLinuxmacOSMdmMtlsNode.jsOauthOidcPythonSwiftWindows
What you need to know about the Pune Tech Scene
Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

.jpeg)
