Security Engineer (Internal)

Security Engineer (Internal)

Full-Time No working from home possible
Maze

At a Glance

  • Tasks: Secure our cloud and applications while building a robust security foundation.
  • Company: Join Maze, a cutting-edge startup at the intersection of AI and cybersecurity.
  • Benefits: Competitive salary, equity options, and the chance to shape security from the ground up.
  • Other info: Be part of a growing team with opportunities for career advancement.
  • Why this job: Make a real impact in cybersecurity while working with innovative technologies.
  • Qualifications: 5+ years in security engineering with AWS expertise and application security experience.

As Security Engineer (Internal) at Maze, you'll own how we secure ourselves — our cloud, our applications, and the way our engineers build. This is a unique opportunity to join a well‑funded Series A startup building at the intersection of generative AI and cybersecurity, establishing the internal security foundation that lets a three‑product company keep moving fast as it scales.

You'll take hands‑on ownership of cloud infrastructure security, application security, security tooling, and the compliance work that unlocks enterprise deals. We're deliberately looking for a strong generalist rather than a narrow specialist: someone who can harden our AWS environment and identity model, get into the weeds on application security, and run a pragmatic compliance program — and who knows when a control is worth the friction and when it isn’t.

Your success will be measured by the robustness of our security posture, our readiness for enterprise customer requirements, and your ability to make secure the default path for engineering rather than a blocker. This role is perfect for a pragmatic, broad security engineer who has built and run security at a startup, thrives with autonomy, and wants to own a domain end‑to‑end.

You'll be our founding internal security hire — but not a lone wolf for long: this is the first role in a function we expect to grow, and as we scale we'll add to the team and bring in dedicated security leadership. You'll set the foundations the rest of that team is built on, and have a clear runway to grow alongside it.

Your Contributions to Our Journey:

  • Harden Our Cloud Infrastructure: Secure our AWS environment by design — identity and access management, hardening, network and infrastructure‑as‑code controls (Terraform) — closing real risk rather than chasing checkboxes.
  • Own Application Security: Embed application security into how we build, from secure‑by‑default patterns and code review guidance to triaging and driving down vulnerabilities across our own products and services.
  • Build Security Tooling and Monitoring: Stand up the monitoring, logging, and alerting that gives us visibility across infrastructure and applications, and serve as our first line of defence.
  • Run Compliance Pragmatically: Lead readiness for SOC2, ISO27001, and similar frameworks — building the controls, documentation, and evidence that support enterprise sales without drowning the team in process.
  • Establish Security Policies That Enable: Create practical security policies and procedures that keep standards high while letting the team move quickly — no security theatre.
  • Automate Security Operations: Build security automation and tooling in code, using AI‑assisted workflows to ship faster while keeping quality high.
  • Manage Vendor and Supply‑Chain Security: Assess third‑party vendors and tools so our supply chain meets enterprise expectations.
  • Enable Incident Response: Develop incident response plans and runbooks, and establish clear processes for detecting, responding to, and recovering from security incidents.

What You Need to Be Successful:

  • Broad, Hands‑On Security Engineering: 5+ years building and running security, with genuine breadth across cloud security and application security rather than depth in only one — comfortable being the person who covers the whole surface area.
  • AWS Security Expertise: Deep, hands‑on knowledge of AWS security — IAM, hardening, and AWS‑native security tooling — with the judgement to prioritise what matters.
  • Application Security Capability: Real experience finding and fixing application‑layer vulnerabilities, and embedding secure development practices into engineering workflows.
  • Infrastructure as Code Proficiency: Strong experience managing security controls programmatically with Terraform, building secure, scalable infrastructure through code.
  • Coding and Scripting Skills: Proficiency in Python, Bash, or similar for security automation, custom tooling, and integrating security into development workflows.
  • Compliance and GRC Know‑How: Practical experience translating SOC2, ISO27001, or similar requirements into technical controls — without letting process become the product.
  • Pragmatic Security Mindset: A track record of balancing security rigour with business velocity, implementing controls that enable engineering rather than block it.
  • Startup Self‑Direction: Proven ability to operate autonomously as an early security hire, prioritise ruthlessly, and build without extensive oversight — and to thrive in the ambiguity of an early‑stage company.
  • Foundation‑Setter: Mindset to build security in a way others can build on as the team grows — clear documentation, repeatable processes, and standards a future team and security leadership inherit cleanly.

Nice to haves:

  • Experience building security programs at early‑stage startups (seed through Series B).
  • Background in DevOps or SRE that grew into security engineering.
  • Familiarity with container security (Docker, Kubernetes).
  • Experience at a cybersecurity product company.
  • A bias toward building vs buying security tooling under startup constraints.
  • AI‑assisted security workflow experience.

Why Join Us:

  • Ambitious Challenge: We’re building at the intersection of generative AI (LLMs and agents) and cybersecurity — and you’ll secure the company doing it, across cloud and application security.
  • Build Security from Zero: Own the internal security function from day one, establishing the architecture, tooling, and practices that scale Maze through hypergrowth — then help grow the team and function around you as we scale.
  • Expert Team: Work alongside a CTO and engineering team with deep experience in AI and cybersecurity — hands‑on leaders who have been part of multiple acquisitions and an IPO — giving you strong technical partnership while you own security.
  • Impactful Work: Cybersecurity is a force for good. Your work directly enables AI‑powered security solutions that protect organisations worldwide — making security an enabler of innovation, not a blocker.
  • Build an AI‑native Company: Join early enough to design everything from the ground up, with significant equity upside and a clear path to grow as our security organisation matures.

Security Engineer (Internal) employer: Maze

At Maze, we pride ourselves on being an exceptional employer that empowers our employees to take ownership and drive impactful change. As a founding internal security hire, you'll have the unique opportunity to shape our security landscape while working alongside a talented team in a dynamic startup environment. With a strong focus on autonomy, professional growth, and the chance to build security from the ground up, you'll be part of a mission that not only protects but also enables innovation in the exciting field of generative AI and cybersecurity.

Maze

Contact Details:

Maze Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineer (Internal)

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Maze, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Maze

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Maze. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Engineer (Internal)

AWS Security Expertise
Application Security Capability
Infrastructure as Code Proficiency
Coding and Scripting Skills
Compliance and GRC Know-How
Pragmatic Security Mindset
Startup Self-Direction

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Maze insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Maze that you’re committed to staying ahead in the game.

How to prepare for a job interview at Maze

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Maze to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Maze.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.