Apply

Senior Security Engineer

Posted 2024-11-11

View full description

💎 Seniority level: Senior, Minimum of 6 years

📍 Location: USA

🔍 Industry: Transportation supply chain logistics

🏢 Company: DAT

🗣️ Languages: English

⏳ Experience: Minimum of 6 years

🪄 Skills: AWSLeadershipPythonAgileCybersecurityGCPJavaProduct ManagementC++AzureCommunication SkillsCollaborationDevOpsWritten communicationCompliance

Requirements:
  • Minimum of a Bachelor's Degree in Computer Science or related fields.
  • Applicable industry certifications (CISSP, Sec+, CISM, SANS GIAC).
  • Minimum of 6 years of experience in Information Security, with at least 2 years in a senior role.
  • Experience with threat modeling and evaluating security tools.
  • Strong verbal and written communication skills.
  • Familiarity with cloud security and DevSecOps principles.
  • Knowledge of security frameworks and standards.
Responsibilities:
  • Design, implement, and manage security systems across the organization.
  • Conduct regular security assessments including vulnerability scans and penetration testing.
  • Monitor and respond to security incidents, ensuring quick resolution.
  • Establish and maintain security tools such as firewalls and intrusion detection systems.
  • Ensure compliance with industry standards and regulations.
  • Lead incident response efforts and perform root cause analysis.
  • Collaborate with various teams to integrate security into systems.
Apply

Related Jobs

Apply

📍 United States

🧭 Full-Time

💸 127350 - 203760 USD per year

🔍 Security technology

🏢 Company: Axon

  • A fundamental understanding of how modern, distributed cloud-based applications function.
  • Demonstrated experience in security best practices or an interest in building that knowledge.
  • Experience responding to and investigating information security events and incidents.
  • 1+ year(s) of experience using SOAR and SIEM solutions.
  • Fluency in development languages like Python or Go, and shell scripting (bash/powershell).
  • Experience interacting with cloud platforms like Azure and AWS via APIs.
  • Working competency with GitOps.
  • Strong problem-solving skills.
  • Strong written and verbal communication skills.
  • Bachelor’s degree or higher, or equivalent experience.

  • Design, develop, implement, and maintain tooling to improve Axon’s ability to detect and respond to security events.
  • Participate in an on-call rotation to investigate and remediate escalated security events.
  • Evaluate and integrate new security tools and technologies into the SOC.
  • Partner with teams throughout the company to build secure solutions.
  • Write run books and draft incident reports for leadership.
  • Engineer solutions for current security attack methods.
  • Contribute to enhancing the overall Information Security Program.
  • Stay current on security industry trends through educational opportunities.

AWSPythonBashAzureGoCommunication SkillsProblem Solving

Posted 2024-11-21
Apply
Apply

📍 US

💸 166000 - 207500 USD per year

🔍 People success platform

🏢 Company: Lattice

  • 5+ years of experience in security operations, auditing, or IT focused on IAM systems and compliance.
  • Strong expertise in managing IAM tools and controls within platforms like Okta, Zscaler, and CrowdStrike.
  • Demonstrated ability to assess IAM configurations and recommend security improvements.
  • Knowledge of compliance frameworks (SOC2 preferred) and authentication protocols.

  • Conduct in-depth audits of systems for IAM configurations, ensuring compliance with security standards.
  • Review and enhance IAM security controls across systems like Okta, Zscaler, and CrowdStrike.
  • Collaborate with IT and engineering teams to optimize IAM configurations for secure access.
  • Lead compliance initiatives, including SOC2 audits, preparing documentation and ensuring evidence is accessible.
  • Manage IAM-related security alerts and optimize alert rules and thresholds.
  • Develop and maintain detailed documentation for IAM processes and controls.

CybersecurityLDAPOAuthCommunication SkillsAnalytical SkillsCollaborationProblem SolvingLinuxAttention to detailOrganizational skillsTime ManagementWritten communicationDocumentationCompliance

Posted 2024-11-14
Apply
Apply

📍 U.S.

  • Seeking a dedicated professional with in-depth knowledge of IAM principles, standards, and best practices.
  • Experience in safeguarding systems and supporting security compliance initiatives.
  • Ability to partner cross-functionally to drive impactful outcomes.

  • Play a central role in enhancing security posture of enterprise and cloud-native environments.
  • Design, implement, and maintain robust IAM solutions.
  • Manage authentication, authorization, and provisioning across diverse platforms.
  • Collaborate closely with various teams to ensure alignment between IAM solutions and organizational security requirements.

LeadershipCloud ComputingCybersecurityLDAPMicrosoft Active DirectoryOAuthCommunication SkillsAnalytical SkillsCollaboration

Posted 2024-11-07
Apply
Apply

📍 United States

🧭 Full-Time

💸 110000 - 130000 USD per year

🔍 Data center services and interconnection

🏢 Company: Cologix, Inc.

  • A computer science related baccalaureate degree from an accredited college or equivalent experience.
  • Minimum of 5 - 8 years’ experience in security in an enterprise environment.
  • Experience with vulnerability scanning applications, log management, alerting platforms.
  • Knowledge of information systems security standards and practices.
  • Hands-on security knowledge of platforms like Windows, Linux, IOS.
  • Ability to interpret information security data to identify potential security issues.
  • Advanced professional security certifications like CISSP, CRISC, CISM are preferred.

  • Install, document, troubleshoot, and maintain network security infrastructure.
  • Configure security tools to enhance detection and response capabilities.
  • Collaborate on cybersecurity risk remediation and compliance.
  • Respond to security events and validate findings.
  • Plan and implement security tools for incident response.
  • Maintain system documentation and incident runbooks.
  • Manage updates and patching of security applications.
  • Participate in project planning as a security SME.

Cloud ComputingCybersecurityCustomer serviceLinuxDocumentationCompliance

Posted 2024-11-07
Apply
Apply

📍 US

🧭 Full-Time

🔍 Cybersecurity

  • 2+ years of security monitoring and incident response experience.
  • Experience with Linux, Mac, and knowledge of Windows.
  • Configuration and maintenance experience of endpoint security solutions (e.g., Crowdstrike, SentinelOne, Carbon Black).
  • Familiarity with security tools like SIEM, Metasploit, Splunk, Wireshark.
  • In-depth knowledge of SIEM log ingestion and alert creation.
  • Hands-on experience with TCP/IP and networking.
  • Ability to write scripts/code using Python or other scripting languages for automation.
  • Knowledge of incident response tools and techniques.
  • Experience with cloud platforms security operations (AWS, GCP, Azure).
  • Experience responding to security questionnaires and customer inquiries.

  • Represent security in internal and external meetings to discuss security analysis and compliance responses.
  • Review past incidents to identify attack trends and refine alerts.
  • Develop, document, and implement new security processes.
  • Identify and track assets to assess risks and communicate them to stakeholders.
  • Maintain a repository of cybersecurity threat information for risk assessments.
  • Automate security events and reporting processes.
  • Implement and monitor IDS/IPS rules and alerts.
  • Investigate security events to determine their threat level.
  • Research tools to enhance security workflows.
  • Collaborate on customer questionnaires and compliance audits.

AWSPythonCybersecurityGCPAzureLinux

Posted 2024-10-21
Apply
Apply

📍 United States

🧭 Full-Time

💸 121000 - 203000 USD per year

🔍 Financial Services

🏢 Company: MQ Referrals Only

  • At least 5+ years of experience as an engineer with a Bachelor's degree; or 3 years of experience with an advanced degree; or 8+ years of relevant experience instead of a degree.
  • Industry standard certifications like OSCP/OSCE/CEH, CISSP, CWAD.
  • Experience or knowledge about Payments or Financial Services.
  • 5+ years of experience in software security (AppSec).
  • Expert-level knowledge of common web application vulnerabilities (OWASP Top 10).
  • Knowledge in threat modeling methodologies such as STRIDE or PASTA.
  • Developer-level proficiency in languages such as Python, Java, JavaScript, and Golang.
  • Knowledge of cloud native technologies including containers, Kubernetes, and AWS, GCP, or Azure services.
  • Experience with static analysis, dynamic analysis, and software composition analysis security tools.

  • Perform and troubleshoot various application security tools into CI/CD pipeline.
  • Conduct spot validations to test issues/fixes.
  • Perform Design Reviews and Threat Modeling for products.
  • Liaison with Bug Bounty programs and developer teams to track issues.
  • Provide support to all phases of penetration tests and red team activities.
  • Engage with Core Engineering leads to ensure timely risk remediation.
  • Work closely with development teams to ensure security and infrastructure requirements.
  • Define product security architecture strategies and procedures.
  • Document operational procedures and current state architecture.
  • Provide subject matter expertise to project teams.
  • Provide on-call rotation support to relevant services and tooling.

AWSPythonSoftware DevelopmentGCPJavaJavascriptKubernetesJavaScriptAzureGoGolangCI/CD

Posted 2024-10-18
Apply
Apply

📍 United States

💸 $145,000 - $200,000 per year

🔍 Ticketing

🏢 Company: SeatGeek

  • Experience working in a threat detection role and solid understanding of security fundamentals.
  • Proficiency in one or more programming languages (Python, C#, Go) for coding and code reviews.
  • Experience working with highly technical engineering teams.
  • Holistic solutions to secure a cloud environment rather than reactive fixes.
  • Ability to think like an attacker to improve detection & response.
  • Experience contributing to the security community (public research, blogging, presentations, etc.) is a plus.

  • Take ownership and drive Security Operations initiatives, both within and outside the team.
  • Lead our cloud security strategy and its implementation, partnering with our Cloud Product teams to build monitors and guardrails.
  • Hold an active role in our incident response & on-call programs, improving visibility, detections, and responses for critical systems.
  • Engineer resilient solutions and enhance our existing security controls, tools, and processes at scale through automation.
  • Partner with engineering and non-engineering teams to influence security awareness and best practices.

AWSPythonAgileC#StrategyGo

Posted 2024-10-18
Apply
Apply

📍 United States

🧭 Full-Time

🔍 Cybersecurity

🏢 Company: Trail of Bits

  • Extensive experience as a blockchain security engineer, with a deep understanding of Solidity security and the Ethereum Virtual Machine (EVM), including familiarity with Ethereum Yellow Paper.
  • Proficiency in Go and/or Rust. Multiple years working with Go and/or Rust, with in-depth expertise on the languages, their internal and pitfalls, as well as their tooling ecosystem.
  • Experience with various blockchain platforms such as Cosmos, Starknet, Substrate, and Solana, and a strong background in reviewing off-chain components and nodes, with a particular emphasis on L1/L2, consensus, VM, and network components.
  • Experience working with fuzzers, CodeQL, or Semgrep, including building harness, writing linting rules, and applying the tools on large codebases.
  • Excellent written and verbal communication skills, with a strong emphasis on engaging with customers, writing technical blog posts, and delivering presentations to the technical community.

  • Work directly with leading teams in the blockchain industry to review their code and help secure their products.
  • Design and implement solutions for difficult engineering and research problems. Provide expert guidance and innovative strategies to address and mitigate security vulnerabilities in client’s blockchain implementations.
  • Collaborate with teammates to maintain and continually improve our existing blockchain security tools using modern software engineering practices.
  • Contribute to the development and enhancement of open-source tools that Trail of Bits has developed, ensuring they remain cutting-edge and effective in the evolving blockchain landscape.
  • Push the boundaries of the industry through research and tooling, contributing to advancing blockchain security practices.
  • Identify emerging threats and develop proactive solutions to address them, position Trail of Bits as a leader in blockchain security.

BlockchainCybersecurityEthereumGoRustCommunication Skills

Posted 2024-10-14
Apply
Apply

📍 United States

🧭 Full-Time

🔍 Healthcare

  • BS / BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, or 6 years security domain experience without degree.
  • 4+ years combined experience as a security engineer in an enterprise environment (preferably cloud) across multiple disciplines.
  • 3+ years of relevant work experience in Enterprise Identity and Access management and/or Consumer Identity and Access management.
  • 2+ years of experience acting as a trusted technical decision-maker in a team setting.

  • Working cross-functionally to design, build, and operate solutions that improve and mature our security capabilities.
  • Leveraging data to understand trends, metrics, and opportunities to improve our security posture, researching options, and making recommendations.
  • Leading and enhancing incident/issues response efforts, analyzing, containing, and mitigating strategies to ensure effective resolution of security incidents.
  • Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures.

AWSCybersecurityGCPAzureCommunication SkillsWritten communication

Posted 2024-10-08
Apply