Tulip Interfaces is a security-focused team building cloud protections that directly shape product and culture. This hybrid role in Boston, MA offers company equity and a benefits package designed to support your health, family, and long-term growth, including health, dental, and vision coverage, flexible spending, parental leave, a 401(K), flexible work scheduling, and an unlimited vacation policy. You will help strengthen security engineering across cloud security, detection and alerting, vulnerability management, and compliance support, with hands-on work primarily in AWS.
What you’ll do
- Design, build, and maintain security controls as code across cloud environments, including posture hardening and account-level guardrails.
- Own vulnerability management end-to-end: triage findings across environments, prioritize to reduce noise, and drive remediation through to closure.
- Run the recurring alert-review workflow, tuning detections, reducing false positives, and improving coverage over time.
- Build and maintain log ingestion and SIEM pipelines, and participate in incident response work.
- Partner with engineering and product teams on architecture, authentication, and application security reviews, including code review and automated testing.
- Support FedRAMP and other compliance efforts through documentation upkeep, alert monitoring, evidence collection, training exercises, and customer security questionnaires.
What you bring
- 5+ years of security engineering experience with hands-on ownership of cloud security work.
- Deep, hands-on experience securing AWS and/or Azure environments, including containerized and Kubernetes workloads (EKS/AKS).
- Ability to build and manage security controls as code using Terraform and Python (or similar).
- Experience authoring and tuning detections and SIEM rules, and running vulnerability and container-image scanning in CI.
- Working knowledge of compliance frameworks such as FedRAMP, ISO 27001, or SOC 2, including evidence practices.
- Nice to have: incident response or forensics experience, threat modeling of new services, or running internal security exercises.
- Education: Bachelor's degree in a technical field, or equivalent working experience.
Tools you’ll work with
AWS, Azure, EKS, AKS, Terraform, Lambda, Python, Kubernetes, SIEM, FedRAMP, ISO 27001, SOC 2
Collaboration
- Infrastructure and Product Engineering
- IT, Legal & Compliance, and Product Management
- Engineering and Security leadership
Benefits
- Company equity
- Health, Dental, Vision
- Short-term Disability
- Long-term Disability
- Life Insurance, AD&D Insurance
- Flexible Spending Account (FSA)
- Commuter Benefits
- Parental Leave
- 401(K)
- Flexible work schedule
- Unlimited vacation policy
- Learning & Development program
- Virtual company events and happy hours
- Fitness subsidies
- Inclusive, dog-friendly office
- Direct impact on product and culture