Senior Security Engineer - End-User, Infrastructure & AI Security
About the Role
We are looking for a hands-on Senior Security Engineer responsible for strengthening the security of our end-user environment and infrastructure across on-premises, data center, and cloud environments.
This role will focus primarily on endpoint security, infrastructure and network security, vulnerability management, incident response, Zero Trust, and security automation. The ideal candidate should also have practical experience applying AI technologies to improve security operations, threat detection, investigation, and automation.
What You'll Do:
- Own and continuously improve the security of end-user devices and enterprise infrastructure.
- Deploy, manage, and optimize endpoint security and EDR solutions such as CrowdStrike or equivalent.
- Manage endpoint protection, device hardening, security configurations, and endpoint vulnerability remediation.
- Manage and improve Data Loss Prevention (DLP), secure web/cloud proxy, and other end-user security controls.
- Implement and continuously improve Zero Trust security principles across users, endpoints, applications, and infrastructure.
- Work with Identity and Access Management (IAM) and Privileged Access Management (PAM) solutions to secure user and administrative access.
- Manage and improve network security controls, including firewalls, IDS/IPS, WAF, network segmentation, and secure remote access.
- Understand network architecture, protocols, and traffic flows and identify opportunities to strengthen network security.
- Secure Linux-based infrastructure and work with infrastructure teams on system hardening, secure configurations, and access controls.
- Identify security vulnerabilities, misconfigurations, and infrastructure security gaps and drive remediation with the appropriate engineering teams.
- Own and support vulnerability management across endpoints, servers, network devices, and infrastructure.
- Participate in vulnerability assessments, penetration testing, security scans, and remediation activities.
- Monitor and investigate security alerts using SIEM, EDR, network security, and other security platforms.
- Participate in security incident response, including investigation, containment, remediation, recovery, and root-cause analysis.
- Work closely with Infrastructure, Network, IT, SRE, Cloud, and Engineering teams to ensure security is incorporated into architecture and design.
- Perform security reviews of infrastructure changes, new technologies, and architecture designs.
- Support security across on-premises, data center, private-cloud, and public-cloud environments.
- Evaluate new security technologies and work with vendors on technical evaluations and proof-of-concept deployments.
- Develop and maintain security standards, technical procedures, hardening guidelines, and operational documentation.
- Mentor junior security engineers and help improve the team's overall technical capabilities.
- Stay current with emerging cybersecurity threats, technologies, and attack techniques.
AI & Security Automation Responsibilities
- Apply AI technologies and AI-assisted security tools to improve day-to-day security operations.
- Use AI/ML capabilities for anomaly detection, threat detection, vulnerability prioritization, incident investigation, and security monitoring.
- Leverage AI to improve security alert analysis, correlation, prioritization, and remediation.
- Identify opportunities to use AI to reduce repetitive manual security activities and improve operational efficiency.
- Use AI-assisted approaches to accelerate incident investigation, root-cause analysis, and remediation.
- Understand security risks introduced by AI and LLM-based applications and recommend appropriate security controls.
- Understand common AI/LLM security risks, including prompt injection, sensitive-data leakage, unauthorized access, excessive permissions, and misuse of AI systems.
- Integrate AI capabilities with security platforms, APIs, SIEM/SOAR, monitoring systems, or internal security workflows where appropriate.
- Develop security automation using Python, Bash, APIs, SOAR, or similar technologies.
- Participate in security assessments of new AI/LLM technologies being introduced into the organization.
- Evaluate AI-enabled cybersecurity products and conduct POCs to determine their effectiveness and operational value.
We'd Love for You to Have
Must have:
- 8+ years of hands-on experience in cybersecurity, infrastructure security, network security, or related areas.
- Strong hands-on experience with endpoint security and EDR solutions such as CrowdStrike or equivalent.
- Strong understanding of endpoint hardening and end-user security.
- Experience with DLP and secure web/cloud proxy technologies.
- Good understanding and practical experience implementing Zero Trust security principles.
- Experience with Identity and Access Management (IAM) and Privileged Access Management (PAM).
- Strong understanding of network security, firewalls, IDS/IPS, WAF, network segmentation, and networking concepts.
- Strong understanding of network protocols, architecture, and traffic flows.
- Experience securing Linux-based systems and infrastructure.
- Strong experience with vulnerability management and remediation.
- Experience with security incident investigation and incident response.
- Working knowledge of SIEM and security monitoring platforms.
- Experience securing on-premises and data center infrastructure.
- Working knowledge of at least one major public-cloud platform, preferably AWS.
- Ability to review infrastructure and network architecture from a security perspective.
- Practical experience using AI or AI-assisted technologies within cybersecurity or security operations.
- Understanding of AI/LLM security risks and how AI technologies can affect enterprise security.
- Experience applying AI to areas such as anomaly detection, security monitoring, incident investigation, vulnerability management, or security automation.
- Experience with scripting and automation using Python, Bash, APIs, or similar technologies.
- Strong troubleshooting, analytical, and problem-solving skills.
- Ability to work effectively with Infrastructure, Network, IT, SRE, Cloud, and Engineering teams.
- Experience working with global teams.
- Strong communication skills and ability to explain security risks and remediation requirements to technical teams and management.
Good to have:
- Experience with Darktrace or other Network Detection and Response (NDR) platforms.
- Experience with SOAR and security orchestration/automation.
- Kubernetes and container security experience.
- Experience across AWS, Azure, or GCP security.
- Experience with VAPT and Red Team/Blue Team exercises.
- Experience with security architecture and threat modeling.
- Experience performing AI/LLM security assessments and threat modeling.
- Experience securing enterprise GenAI/LLM applications, AI agents, RAG systems, or internally developed AI solutions.
- Familiarity with AI security frameworks and guidance such as MITRE ATLAS, NIST AI RMF, and OWASP guidance for LLM/GenAI applications.
- Experience supporting ISO 27001, SOC 2, or similar security and compliance programs.
- Experience evaluating new security products and working with vendors on security POCs.
- Relevant cybersecurity, network, cloud, or infrastructure certifications are a plus.
Qualifications:
- Bachelor's degree in computer science, Information Technology, Engineering, Cybersecurity, or an equivalent technical field.
- 6+ years of relevant cybersecurity or infrastructure security experience.
- Strong hands-on technical background with the ability to independently troubleshoot and resolve complex security issues.
- Ability to balance security requirements with infrastructure reliability, operational requirements, and business needs.
Additional Information:
Return to Office: PubMatic employees throughout the global have returned to our offices via a hybrid work schedule (3 days “in office” and 2 days “working remotely”) that is intended to maximize collaboration, innovation, and productivity among teams and across functions.
Benefits: Our benefits package includes the best of what leading organizations provide, such as paternity/maternity leave, healthcare insurance, broadband reimbursement. As well, when we’re back in the office, we all benefit from a kitchen loaded with healthy snacks and drinks and catered lunches and much more!
Diversity and Inclusion: PubMatic is proud to be an equal opportunity employer; we don’t just value diversity, we promote and celebrate it. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
About PubMatic
PubMatic is one of the world’s leading scaled digital advertising platforms, offering more transparent advertising solutions to publishers, media buyers, commerce companies and data owners, allowing them to harness the power and potential of the open internet to drive better business outcomes.
Founded in 2006 with the vision that data-driven decisioning would be the future of digital advertising, we enable content creators to run a more profitable advertising business, which in turn allows them to invest back into the multi-screen and multi-format content that consumers demand.