Principal Software Engineer
TLDR
Build scalable pipelines processing terabytes of security telemetry daily, powering AI agents that detect malicious activity through data correlation and search.
About Us
Nebulock is an agentic threat hunting platform that autonomously surfaces behaviors, not just IOCs, from various data sources. Nebulock acts like a teammate: a 24/7 AI threat hunter that investigates hypotheses, reasons through telemetry, and learns from an environment. Today, threat hunting is broken. Security teams spend weeks chasing alerts, writing detections by hand, and manually validating findings often just to confirm what their existing tools already flagged. Meanwhile, attackers exploit credentials, move laterally, and operate in silence. Nebulock flips the model. We continuously and autonomously hunt across endpoint, identity, and cloud telemetry. We identify the subtle behavioral signals that point to credential misuse, lateral movement, insider threats, and post-access activity. Then we turn those hunts into hardened, behavior-based detections automatically.
Position Overview
The Data Platform team is responsible for ingesting security telemetry data from our customers’ environments, transforming the data, and making it available to AI agents that continuously scan this data to look for malicious activities. We also tackle hard problems such as correlating entities across events from disparate sources and generating a queryable baseline view of activities that will allow agents to detect anomalies.
As a Principal Software Engineer on this team, you will lead cross-functional projects and drive architectural changes to meet strict latency and reliability requirements. You’ll co-own the data ingestion, transformation, and search layers that power agentic threat hunting workflows. We currently ingest terabytes of data per day and are growing fast. This role is ideal for engineers who have built large distributed systems from the ground up and scaled it to process billions of events/requests per day.
Expected Impact
Design, build, and maintain scalable data pipelines that ingest and process large volumes of security telemetry (TBs / day)
Own API and event stream integrations across a wide range of third-party data sources (EDR, IAM, Cloud, SaaS)
Partner with product stakeholders to build data solutions that will be consumed by both internal and external customers
Guide the future technical direction that allows rapid development of product capabilities and efficient scaling of backend systems
Use AI agents to build creative solutions to solve problems such as data mapping and entity correlation
Set and promote engineering standards and best practices, including observability, monitoring and automated testing
Be a mentor to junior engineers and help grow the engineering talent within the team
Qualifications
8+ years of experience building large-scale distributed systems supporting customer-facing products
Proficiency in Python, Java, Go, Rust, or similar
Hands-on experience designing large-scale event streaming systems such as Kafka or similar
Experience working on search or analytics products over large datasets
Strong systems thinking and understanding of performance, cost and complexity trade-offs
Experience with either AWS or GCP
Ability to adapt, iterate, and ship quickly
Hunger for growth and the desire to work in a low-ego environment
Nice to Haves
Experience building and scaling distributed systems from the ground up
DevOps or platform engineering experience
Cybersecurity experience
Startup experience
What We Offer
A dynamic startup environment with opportunities for rapid career growth
A collaborative culture that values innovation and creativity
Competitive salary and equity options
Comprehensive benefits package (including 401K)
Opportunities to travel for conferences, workshops, and team-building events
Benefits
Equity Compensation
equity options
Learning Budget
Opportunities to travel for conferences, workshops, and team-building events
Paid Time Off
Comprehensive benefits package (including 401K)
Remote-Friendly
Fully remote role
Nebulock builds an autonomous threat hunting platform that operates around the clock, surfacing behavioral signals from diverse data sources to tackle security challenges head-on. Designed for security teams, it automates the identification of issues like credential misuse and lateral movement, drastically reducing the time spent on alert validation and detection writing. By turning complex threat hunts into behavior-based detections, Nebulock redefines proactive cybersecurity.