What are the responsibilities and job description for the Security Operations Engineer position at Rasa?
SUMMARY
Security is a crucial function for our organisation and we are looking for a Security Operations Engineer to help us continuously improve our security posture.
Security is everyone's job at Rasa, but the role of a Security Operations Engineer is to make sure the tools and processes are in place to help everyone succeed in that and make it easy for them to do so.
At Rasa, as our organisation grows, our Security Operations Engineers are instrumental in helping our security capabilities grow at the same pace, by ensuring we provide a secure foundation for other teams to work on. As a member of the security team, you will be a key contributor to securing our endpoints, services and cloud infrastructure.
As a Remote first company, we believe that the internet is where the work happens, an office is just somewhere you can connect to the internet. We believe that everyone can make a difference at Rasa no matter where they are based. If you would like to work in an office then we have an office in Berlin, Germany. But our focus is to continue to build our team remotely across the UK and Germany and North America.
ABOUT YOU
Security at Rasa is not only about technical controls. You'll have to approach security from the angle of enabling other team members to do their job securely, rather than simply dictating things they can and cannot do.
We run a significant amount of infrastructure in the cloud, and we need to secure that in a way that means other teams can do their jobs in a secure way. You'll appreciate that security is no use if it means other people cannot do their job.
You'll also enjoy keeping up to date with security topics, being aware of new vulnerabilities or attacks and understanding how they could affect Rasa.
We are looking for a Security Operations Engineer who combines technical, communication, and analytical capabilities and who will have the opportunity to lead the introduction and management of tooling and processes to support our mission and help teams work securely.
- You deeply care about security and can appreciate the people side as well as the technical side.
- You're comfortable being lean and you fix problems without waiting for someone to tell you to.
- You take pride in teaching and learning from teammates, and enjoy constructive peer review in a respectful environment.
- You can effectively communicate what you’re working on with team members outside the security team.
- You thrive in an inclusive and supportive environment, working with people from diverse backgrounds
- You value autonomy and transparency
Technical requirements
- Experience in deploying, configuring and monitoring security tooling (e.g. endpoint protection, cloud security posture management) across endpoint (MacOS/Linux) and cloud environments.
- Experience with securing large cloud environments (primarily GCP, but also AWS and Azure).
- Experience working with Python or another programming language.
- Ability to think ahead and anticipate technological challenges.
- Bonus: Experience in security incident response (whether at a process or forensic level).
Navigate our tech stack: Python 3, GitHub Actions, Kubernetes, GCP among other technologies and frameworks.
Please keep in mind that we are describing the background we imagine would best fit the role. Even if you don’t meet all the requirements, yet you are passionate about this role: we absolutely want to get to know you!
THINGS YOU WILL DO
We’re a startup, so you’ll have to be comfortable rolling up your sleeves and doing whatever is required to support our mission. However, you can definitely expect to:
- Configure, monitor and respond to alerts from security monitoring products such as cloud security posture management and endpoint protection.
- Work with the infrastructure team to ensure that our cloud environments are protected and monitored for security risks.
- Work with the operations team to ensure that new devices and services are adequately secured.
- Work as part of the wider security team to investigate and respond to security incidents.
- Help to educate the team on security best practices.
- Stay up to date with current vulnerabilities or attacks that may impact services used by Rasa or our infrastructure.
WHAT YOU CAN EXPECT FROM US
- Flexible hours and a dedicated remote budget
- 1000 Euro’s / £900 personal development fund & 6 paid education days to help you grow within your role
- 26 days paid holiday per year
- A Macbook, and other Tech to help you to do your job
- We have regular remote team events, as well as regular remote social events
- 2 team offsites every year, our last one was 3 days in beautiful Brandenburg
ABOUT US
Rasa supplies the standard infrastructure for conversational AI, providing the tools required to build better, more resilient contextual assistants. With more than 10 million downloads since launch, Rasa Open Source is loved by developers worldwide, with a friendly, fast-growing community learning from each other and working together to make better text- and voice-based AI assistants.
Rasa offers three key products in its suite of conversational AI offering. Rasa Open Source is the most popular open source software in conversational AI. Rasa X, released in 2019, is a free toolset that helps developers quickly improve and share an AI assistant built with Rasa Open Source. Rasa Enterprise is the company's commercial offering, providing an enterprise-grade platform for developing contextual assistants at scale. Rasa runs in production everywhere from startups to Fortune 500s, and provides the data privacy and security needed to enterprises of every size.
Rasa is privately held, with funding from Accel, Andreessen Horowitz, Basis Set Ventures, and others. The company was founded in 2016 and has offices in Berlin, Germany and Edinburgh, United Kingdom.Rasa is an equal opportunity employer. We are still a small team and are committed to growing in an inclusive manner. We want to augment our team with talented, compassionate people irrespective of race, color, religion, national origin, sex, physical or mental disability, or age.