A Security Engineer role focused on building and defending the next-generation data storage platform by designing advanced security patterns, operationalizing detection and response, and automating security measures in a cloud-native, AI, and distributed systems environment.
Key Responsibilities
Design and implement zero-trust network access models and secure service-to-service communication
Build high-fidelity behavioral detections for infrastructure and identity systems and integrate security telemetry into SIEM
Conduct threat modeling and security validation exercises on Kubernetes, cloud-native workloads, and AI pipelines
Automate security controls within infrastructure-as-code and CI/CD pipelines to reduce manual security tasks
Requirements
Experience in designing and implementing zero-trust network access models, securing service-to-service communication, or AI-specific guardrails to eliminate unauthorized data access and lateral movement.
Ability to build high-fidelity behavioral detections for infrastructure and identity systems, ensuring all security telemetry is integrated into SIEM for real-time visibility and rapid incident containment.
Experience conducting threat modeling and security validation exercises, including ransomware simulations, across Kubernetes, cloud-native workloads, and AI model pipelines.
Proficiency in automating security controls directly into infrastructure-as-code and CI/CD pipelines, including automating log analysis and network policy enforcement to reduce manual overhead.
Advanced knowledge of securing distributed systems, with deep technical proficiency in either network protocols TCP/IP, TLS/SSL, detection engineering methodologies, or AI/ML pipeline security protecting against prompt injection and data leakage.
Hands-on experience securing cloud-native environments such as AWS, Azure, or GCP, and containerized workloads using Kubernetes.
Experience with modern infrastructure-as-code automation tools.
Ability to distinguish legitimate operational activities from indicators of compromise through deep log analysis, packet inspection (e.g., Wireshark), or behavioral modeling in SIEM/XDR platforms.
Proven track record of working alongside DevOps, SOC, and Data teams to drive security outcomes without compromising engineering velocity.
Willingness and ability to work on-site at the Prague office in accordance with Everpure’s policies, unless on PTO, work travel, or other approved leave.
Benefits & Perks
Flexible time off
Wellness resources
Company-sponsored team events
Ready to Apply?
Join Pure Storage and make an impact in renewable energy