Swarmer develops software that makes drones autonomous and allows them to operate together, in large, coordinated teams — no pilots needed. Our technology has been battle-tested in Ukraine— the world’s most intense proving ground for drone warfare.
In March 2026, we became the first Ukrainian defense startup to go public on NASDAQ, following a $15M Series A — the largest investment in a Ukrainian defense tech company since the start of the war.
Working at Swarmer means operating at the intersection of engineering rigor and frontline reality. The problems and environments are complex, and the stakes are very real. We built this software to enable democratic nations to defend themselves.
If you are motivated by building resilient systems that matter and by seeing the direct impact of your work, you’ll find purpose here.
What we’re looking for:
We're looking for an experienced Cybersecurity Engineer to join our team. You'll be responsible for defending our endpoints, identities, SaaS stack, networks, and cloud environment against the people actively trying to breach them. Product security lives with a separate team, so your focus stays sharp: keep the corporate perimeter tight.
This is a builder's role, not a maintainer's. You'll stand up and run our detection stack (SIEM/SOAR, EDR), lock down and manage the device fleet (MDM, hardening), and design identity controls built on ZeroTrust principles (SSO, MFA, ZTNA).
You won't be handed a mature security program to babysit. You'll design it, implement it, and operate it, with recognized frameworks as your guardrails and real-world attack patterns as your test cases.
What you’ll do:
Own and continuously improve our SIEM/SOAR capabilities, including log source onboarding, detection rules and correlation logic, alert tuning, dashboards, automated response workflows, and integration across the security stack
Monitor and analyze security events and logs to catch anomalies and potential threats; investigate, contain, and remediate incidents, documenting timelines, root causes, and lessons learned
Deploy and manage endpoint and server protection across the fleet (EDR/NGAV, MDM), including policy enforcement, compliance configuration, and hardening baselines (encryption, security policies, benchmarks)
Implement and operate identity and Zero Trust access controls, including SSO, MFA, conditional access, ZTNA, device posture checks, RBAC, least privilege, privileged access management, and periodic access reviews
Manage vulnerabilities across endpoints, servers, and cloud, with risk-based prioritization and remediation tracking
Monitor cloud and SaaS security posture, remediate misconfigurations, and review third-party integrations and access scopes
Review infrastructure projects and architecture from a security lens, ensuring secure-by-default configurations
Document technical security controls (runbooks, hardening guides) and support internal and external audits
What we need:
4+ years of hands-on experience in cybersecurity or IT infrastructure engineering, with a clear specialization in security
Hands-on experience with SIEM/SOAR platforms, covering log source integration, detection engineering, alert investigation, and security automation
Hands-on experience with EDR/NGAV platforms, covering endpoint policy management, detection, investigation, and response
Experience hardening and managing endpoints across Windows, macOS, and Linux, including MDM platforms
Experience with identity and Zero Trust access technologies, including SSO, MFA, conditional access, device posture, and ZTNA
Solid grasp of networking fundamentals (TCP/IP, DNS, DHCP, VPN), with practical experience configuring firewalls and other network security controls
Working knowledge of common attack techniques and how to detect and prevent them
Practical familiarity with recognized security frameworks and standards (e.g., CIS, NIST, MITRE ATT&CK)
Strong risk-assessment instincts, with th


