The opportunity
The Security team ensures that while AI moves at breakneck speed, everyone driving the racecar is wearing a seatbelt. We secure LangChain's core platform and protect AI agents from emerging threats.
What you'll do
Own the detection lifecycle: Translate threat models, incidents, and attacker behavior into telemetry requirements and detections-as-code. Validate coverage, measure signal quality, tune false positives, and continuously test whether defenses work.
Build security monitoring and telemetry: Design the telemetry pipeline end-to-end across cloud (GCP/AWS), Kubernetes, and the LangSmith/LangGraph control plane. Instrument services, define the signals that matter, and make security data reliable and useful.
Engineer investigations and threat hunting: Build tools and workflows for proactive hunting, evidence collection, incident scoping, and containment. Turn investigation findings into new detections and lasting improvements.
Use agents to scale the team: Build reliable internal AI agents and automation that triage alerts, enrich findings, gather evidence, scope incidents, and accelerate routine security work. Design human-in-the-loop controls and evaluations so automation is safe, observable, and trustworthy.
Lead incident response and participate in on-call: Triage, scope, contain, and remediate security incidents, then drive postmortems that produce durable engineering changes.
Partner with Product Security: Turn product threat models and vulnerability findings into production monitoring, and feed real-world detection and incident learnings back into secure design.