About this role.
Synthesia is hiring a staff-level SecOps Security Engineer to strengthen security operations across its cloud-first SaaS platform. The role owns hands-on security improvements in AWS/GCP, Kubernetes, CI/CD, endpoint security, and internal automation. Core work includes building detection and response capabilities, investigating incidents end-to-end, and shipping production infrastructure changes. This is a senior individual-contributor role reporting to the Head of Security in a fast-growing, remote US organization.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
5/5Pace & Pressure
5/5Autonomy Level
5/5Communication Load
4/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would begin by defining the threat or control gap, reviewing the affected architecture and telemetry, and proposing a low-risk implementation with measurable success criteria. I would implement and test the change through infrastructure-as-code and staged deployment, validate it with monitoring and attack-path testing, then document ownership and operational procedures.
I would first ensure high-quality audit, identity, workload, and network telemetry is centralized in the SIEM. I would create prioritized detections mapped to relevant attack techniques, enrich alerts with asset and identity context, automate safe containment actions where appropriate, and maintain tested playbooks for triage, eradication, recovery, and post-incident improvements.
I would prioritize least-privilege RBAC, workload identity, admission and policy controls, network segmentation, image provenance and scanning, secrets protection, runtime detection, and audit logging. I would implement these controls progressively through platform guardrails so secure defaults are easier for developers to adopt than exceptions.
I focus on protecting source access, enforcing least privilege for pipeline identities, securing secrets, pinning and verifying dependencies, scanning code and artifacts, and producing verifiable build provenance. I also establish protected deployment paths and monitor for anomalous pipeline activity or unauthorized configuration changes.
I would use predefined severity criteria and playbooks to determine when immediate containment is justified, such as revoking compromised credentials or isolating an affected workload. Before making destructive changes where feasible, I would preserve logs and relevant forensic data, coordinate with service owners, document decisions, and follow recovery steps that minimize customer impact.
Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and teams across Europe and the US.
As AI continues to shape the way we live and work, Synthesia develops products to enhance visual communication and enterprise skill development, helping people work better and stay at the center of successful organizations.
Following our recent Series E funding round, where we raised $200 million, our valuation stands at $4 billion. Our total funding exceeds $530 million from premier investors including Accel, NVentures (Nvidia’s VC arm), Kleiner Perkins, GV, and Evantic Capital, alongside the founders and operators of Stripe, Datadog, Miro, and Webflow.
Location: Remote (US East Coast/Central)
As our team and customer base grow, we need to make sure our security efforts scale accordingly. For that, we are looking to expand the Synthesia Infosec team by onboarding an additional Security Engineer (L6)! You will report to the Head of Security and work within the Security Operations team.
Key Responsibilities:
Build and own deeply technical security improvements across our Cloud Infrastructure(s) and associated territory (AWS/GCP, Kubernetes, CI/CD), including shipping production changes yourself when needed.
Design, implement, and iterate on detection and response capabilities (SIEM, EDR/MDR, cloud-native detections, CNAPP) with an engineer’s bias for automation, reliability, and measurable outcomes.
Hunt, investigate, and respond to security alerts and suspicious activity end-to-end (triage → containment → eradication → recovery → learnings), including writing tooling and detection logic to prevent recurrence.
Build internal security tooling and automations (IaC, scripts, integrations) that reduce toil and raise the security bar by default.
Experience & Qualifications:
You’re a deeply technical security engineer with a builder/hacker mindset, able to go from idea → prototype → production and comfortable making changes directly in Cloud Infra / DevOps systems.
You have 5+ years of hands-on security engineering experience, ideally in a cloud-first SaaS environment.
Have worked in a fast-growing startup, scale-up and/or SaaS company
We would expect you to have experience in:
Cloud security engineering in AWS and/or GCP, with the ability to implement improvements hands-on (IAM, networking, compute, storage, logging).
Kubernetes security (cluster hardening, workload isolation, runtime security, policy controls) and container ecosystems.
DevOps fundamentals: CI/CD security, secrets management, artifact integrity, and secure-by-default platform patterns.
Incident response and investigation, including creating repeatable playbooks and automating response where appropriate.
Strong programming/scripting ability (Python or similar) plus comfort with infrastructure-as-code (e.g., Terraform) and automation.
Serious agent coding – ideally you’re on the bleeding edge in the space.
Endpoint security tooling, such as CrowdStrike
Bonus points for:
Hands on experience with any/all of: Hunters, Wiz, Falcon, Tracebit, Torii, Okta, Google Workspace, StrongDM, Github, StepSecurity, Dope Security
Any relevant Information Security certification, e.g AWS Certified Security, GIAC GWEB, OSCP, or CSSLP.
The good stuff..
In addition to being a part of a great team, working in a fun and innovative environment, we offer:
A competitive salary + stock options in our fast-growing Series E startup
Remote-friendly environment
100% Medical, Dental & Vision
401k Plan
Paid parental leave
25 days of annual leave + Public holidays + paid sick leave
Fun culture with regular socials
A generous referral scheme
A brand new computer + monitor
Budget and support for conference travel, community events, and content production
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.







