Security Engineer
Bright Machines is a San Francisco-based AI-enabled manufacturer that uses robotics, software, and production data to assemble AI and data-center infrastructure.
About Bright Machines
Bright Machines operates the Bright Factory manufacturing platform, combining virtual product development, AI-enabled robotics, and factory intelligence for data-center infrastructure assembly and traceability.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will execute information-security operations across corporate IT, platform, and product environments. You will maintain ISO 27001 certification, complete customer security reviews, integrate security into the SDLC, manage vulnerabilities, coordinate penetration tests, support incident response and access governance, assess vendor risk, and report security posture.
Requirements
- 5+ years of security engineering, IT security, application security, or related experience
- Experience maintaining an ISO 27001 ISMS
- Knowledge of OWASP Top 10 and secure SDLC practices
- Hands-on experience with SAST, DAST, and SCA tooling
- Scripting proficiency, such as Python
- Infrastructure-as-code familiarity, such as Terraform or Ansible
- Familiarity with GRC platforms
- Cloud security literacy in AWS, Azure, or GCP
- Experience completing customer security questionnaires
- Familiarity with EDR or managed SOC platforms
- Strong written and verbal English communication skills
Responsibilities
- Execute information-security operations across corporate IT, platform, and product environments
- Maintain ISO 27001 certification through evidence collection, internal audits, and corrective actions
- Complete customer security questionnaires and support customer audits
- Support threat modeling, secure code review, and application-security tooling
- Run vulnerability scanning, triage, and remediation tracking
- Coordinate penetration tests and track findings to closure
- Support infrastructure security controls with the Infrastructure Engineer
- Maintain and participate in incident-response activities and tabletop exercises
- Support identity and access governance, access reviews, and MFA/SSO enforcement
- Conduct security risk assessments for vendors, tools, and integrations
- Maintain security policies, standards, and awareness training
- Report security posture, risk, and compliance status
