{"id":1297446,"url":"https://alion.io/job/outerlimit-security-engineer","title":"Security Engineer","company":{"id":3799759,"name":"Outerlimit","domain":"outerlimit.com","url":"https://alion.io/company/outerlimit","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"BambooHR","truth_index":null},"role":"Security","role_family":"Security","seniority":null,"employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["London, United Kingdom"],"countries":["GB"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":74000,"max_usd":159000,"period":"year","method":"role_country_seniority_unknown","sample_n":73},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":".NET","optional":false},{"name":"Azure","optional":false},{"name":"C#","optional":false},{"name":"Crowdstrike","optional":false},{"name":"Docker","optional":false},{"name":"Least Privilege","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"Model Context Protocol","optional":false},{"name":"ServiceNow","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false},{"name":"Terraform","optional":false},{"name":"Tines","optional":false},{"name":"AI Agents","optional":true},{"name":"Amazon ECS","optional":true},{"name":"Function Calling","optional":true},{"name":"LLM","optional":true},{"name":"Python","optional":true},{"name":"Tool Use","optional":true}],"status":"live","first_seen_at":"2026-09-01T00:00:00Z","employer_posted_date":"2026-09-01","last_verified_at":"2026-09-26T10:11:14Z","board_verified":true,"closed_at":null,"days_open":26,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":26},"description":"We are looking for a Security Engineer to design and build the platform that feeds Outerlimitsecurity telemetry from the Global portal into the tools our customers run their security operations in (SIEM, SOAR, XDR etc).\nToday we discover shadow AI, enforce policy at the appliance and MCP gateway, and record every tool call an agentattempts. That signal needs to land natively in Splunk, Microsoft Sentinel, CrowdStrike, XSIAM, Chronicle and Elastic, and drive response through Torq, Tines, ServiceNow SecOps and Logic Apps.\nThis is greenfield, and it is not an architecture-only role. You will write most of v1 yourself.\nThis is for someone who can:\nDesign and build a versioned, documented public API over our existing Data Platform\nBuild signed, idempotent event delivery with bounded retry, dead-lettering and replay\nBuild a cursor-paginated pull and export API to carry bulk SIEM and XDR telemetry\nBuild native connectors for destinations such as Microsoft Sentinel, Splunk and XSIAM\nBuild self-service API key and webhook management in the portal, including scoping, rotation, revocationand audit\nExtend our tenant-scoped authorisationmodel to machine credentials, so an API key never sees more than its creator can\nMake the decisions that set our external API standards, including versioning, deprecationand delivery guarantees\nThe decisions made in the first six months become compatibility obligations we live with for years, and the standards you set become the ones other Outerlimit teams follow.\nWhatyou'llbring\nExperience\nProven experience designing, buildingand operatingexternally consumed APIs in production\nAble to talk specifically about versioning and deprecation, not only endpoints\nGenuinely senior without being a manager, able to scope your own work and carry a project this size\nEvent Delivery & Distributed Systems\nDeep experience with asynchronous, event-driven delivery using queues or streams\nStrong understanding of at-least-once semantics, idempotency, retry and dead-letter design\nAble to debug delivery under load, and treats delivery guarantees as a product feature\nSecurity Domain\nDirect experience with SIEM, SOAR or XDR, either building integrations for them or working inside one\nUnderstanding of how a SOC consumes data, and what separates a useful integration from a noisy one\nSound judgment on multi-tenant isolation, data residency and least privilege\nAwareness of egress as an attack surface, including SSRF, credential handling and rate-limiting\nProgramming & Cloud\nStrong ability in C# .NET with modern engineering practices\nStrong cloud platform depth, ideally Azure with Terraform, and willing to be hands-on with infrastructure\nDocker, and experience writing production-quality code that others can pick up\nNice to have\nExperience shipping a certified marketplace integration end to end, such as Splunkbase, a Sentinel solution or ServiceNow Store\nFamiliarity with security data standards such as OCSF or ECS, and the practical limits of schema normalisation\nPython\nWorking knowledge of the AI agent ecosystem, including MCP, agent frameworks and LLM tool use\nHow we work\nSmall teams with real ownership\nInfrastructure as code and per-region deployments\nZero-build-warning discipline, and tests that exist to catch regressions rather than to raise a coverage number\nEngineers own what they ship in production\nTechnical decisions are argued on merit and written down\nThis is a role for someone who wants to own a hard, externally visible systemend to end and still be in the code.","description_format":"text","description_chars":3527,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Artificial Intelligence","AI Agents","Cybersecurity AI"],"lifecycle":[{"event":"open","at":"2026-09-26T10:11:14Z"}],"liveness":{"score":55,"band":"ok","label":"Likely open","p_open":1,"p_active":0.608,"p_room":0.9,"age_days":26,"expected_fill_days":42,"reasons":["conf:16","win:mid"],"computed_at":"2026-09-27T03:09:23Z"},"pay":null,"html_url":"https://alion.io/job/outerlimit-security-engineer","json_url":"https://alion.io/job/outerlimit-security-engineer.json","meta":{"generated_at":"2026-09-27T03:09:23Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2890,"day_limit":5000,"remaining_today":2110,"minute_limit":60,"resets_at":"2026-09-28T00:00:00Z"}}}