Apply

Senior Security Engineer

Posted about 6 hours agoViewed

View full description

💎 Seniority level: Senior, 5+ years

📍 Location: United States

🔍 Industry: Technology

🏢 Company: ButterflyMX👥 251-500💰 $50,000,000 Series D about 3 years agoSmart HomeSecurityReal EstateSoftware

🗣️ Languages: English

⏳ Experience: 5+ years

🪄 Skills: AWSAWS EKSCybersecurityIoTCI/CDTerraform

Requirements:
  • 5+ years of security engineering experience building, managing & scaling security operations in a cloud native startup.
  • Experience securing a tech stack that includes SaaS, Mobile, & IoT.
  • Proficiency in deploying security solutions in remote-first organizations with a cloud tech stack for SaaS.
  • AWS Security SME knowledge of securing EC2, S3, Lambda, EKS.
  • Experience with AWS Security Stack: WAF, Inspector, Security Hub, GuardDuty.
  • Knowledge of security overlay solutions: EDR, SIEM, CNAPP/CSPM, DSPM, DLP, IDS/IPS.
  • Extensive experience across multiple security domains: cloud security, data security, incident management, etc.
  • Experience maintaining SOC 2 Type II compliance and implementing data privacy controls.
  • Expertise in DevSecOps practices, including automating security testing in CI/CD pipelines.
  • Incident response management experience and ability to educate on application security vulnerabilities.
  • Continuous improvement mindset and inclination to engage in hands-on work.
Responsibilities:
  • Design, implement, mature & maintain robust security controls & processes across our technology stack to protect sensitive data & systems.
  • Lead vulnerability management & remediation efforts to improve the security posture & resiliency of ButterflyMX.
  • Extend detection & response capabilities, triaging alerts, investigating, and remediating incidents.
  • Drive security incident response efforts including containment, investigation, recovery, and lessons learned.
  • Ensure compliance with industry standards & best practices such as SOC2, ISO, NIST, GDPR, CCPA.
  • Evaluate & implement new security technologies to enhance security posture.
  • Collaborate with teams to integrate security into the product development lifecycle.
  • Stay updated with security threats and trends.
  • Develop & conduct regular security awareness training for employees.
  • Serve as a point of contact for security-related inquiries.
Apply

Related Jobs

Apply

📍 U.S. based only

🧭 Full-Time

🔍 Information Security

🏢 Company: GuidePoint Security

  • 3+ years of architecture, implementation, and troubleshooting experience with SIEM/SOAR solutions.
  • Proficiency in developing log ingestion and aggregation strategies.
  • Expertise in developing security-focused content for SIEM platforms.
  • Familiarity with key security events on common IT platforms.
  • Deep proficiency in Windows, Mac, and Linux operating systems.
  • General networking and security troubleshooting skills.
  • Scripting and development skills in BASH, Perl, Python, or Java.
  • Strong knowledge of regular expressions.
  • Ability to prioritize and deliver on projects autonomously.
  • Architecture, implementation, and troubleshooting of SIEM/SOAR solutions.
  • Development of log ingestion and aggregation strategies.
  • Creation of complex threat detection logic and operational dashboards.
  • Optimization of resources to identify and mitigate risks.

PythonBashCiscoLinuxTerraformNetworkingAnsible

Posted 13 days ago
Apply
Apply

📍 US

🧭 Full-Time

💸 116000.0 - 182000.0 USD per year

🔍 Technology

🏢 Company: Mozilla👥 5001-10000💰 $300,000 Angel about 20 years ago🫂 Last layoff 3 months agoInternetOpen SourceWeb BrowsersSoftwareBrowser Extensions

  • 3+ years of relevant hands-on experience in a cybersecurity domain designing, publishing and building security practices.
  • 3+ years of experience translating technical and administrative security controls into actionable platform configurations.
  • Strong infrastructure security knowledge from high-level architectural concepts to implementation.
  • Experience securing large-scale deployments in major cloud stacks (AWS, GCP, or Azure).
  • Proficiency in using Terraform and GitHub Actions.
  • Experience with CNAPP / CSPM / CWPP solutions and Web Application Firewalls.
  • Experience in vulnerability management and with DevOps or SRE teams.
  • Development skills primarily in Python and Go.
  • Protect the services our products depend on from security risks and attacks.
  • Design, implement, and maintain tooling, systems, and processes for securing our cloud infrastructure.
  • Design, review, and improve the security controls of the organization.
  • Write, maintain, and expand security automation and monitoring tools.
  • Work with developers and operations to keep infrastructure safe.
  • Collaborate with cross-functional teams to enhance security practices.
  • Support other cybersecurity functions to improve security posture.

AWSPythonCybersecurityGCPAzureGoCI/CDDevOpsTerraform

Posted 25 days ago
Apply
Apply

📍 U.S.

🧭 Full-Time

💸 200000.0 - 275000.0 USD per year

🔍 InsurTech

🏢 Company: Quanata👥 101-250Software EngineeringInformation TechnologySoftware

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent relevant experience).
  • 6 - 8 years of experience in cybersecurity, including 3 or more years in threat hunting, detection, and intelligence roles.
  • Strong expertise with SIEM platforms and SOAR tools.
  • Advanced understanding of application architectures and hands-on experience securing cloud environments.
  • Proficiency in building detection rules and managing automation workflows.
  • Deep knowledge of frameworks like MITRE ATT&CK and Lockheed Martin Cyber Kill Chain.
  • Excellent communication skills with the ability to engage technical and non-technical stakeholders.
  • One or more relevant certifications.
  • Develop, implement, and maintain proactive threat detection capabilities within the SIEM, correlating logs from multiple sources to identify and neutralize threats.
  • Build and manage SOAR playbooks, runbooks, and automation workflows to scale security operations and streamline incident response.
  • Collaborate with product development teams to understand application architectures, data flows, and infrastructure platforms to design effective detection rules.
  • Conduct regular threat hunts and use threat intelligence to identify and mitigate vulnerabilities and risks.
  • Lead efforts to correlate internal and external threat intelligence.
  • Create scalable frameworks to enable team contributions and ensure program sustainability.
  • Engage with product development teams for security insights on new features.
  • Report findings and metrics to stakeholders with actionable recommendations.

PythonCloud ComputingCybersecurity

Posted 26 days ago
Apply
Apply

📍 United States

🧭 Full-Time

💸 127350 - 203760 USD per year

🔍 Security technology

🏢 Company: Axon👥 1001-5000💰 $246,000,000 Post-IPO Equity over 6 years agoGovTechElectronicsHardwareSoftware

  • A fundamental understanding of how modern, distributed cloud-based applications function.
  • Demonstrated experience in security best practices or an interest in building that knowledge.
  • Experience responding to and investigating information security events and incidents.
  • 1+ year(s) of experience using SOAR and SIEM solutions.
  • Fluency in development languages like Python or Go, and shell scripting (bash/powershell).
  • Experience interacting with cloud platforms like Azure and AWS via APIs.
  • Working competency with GitOps.
  • Strong problem-solving skills.
  • Strong written and verbal communication skills.
  • Bachelor’s degree or higher, or equivalent experience.
  • Design, develop, implement, and maintain tooling to improve Axon’s ability to detect and respond to security events.
  • Participate in an on-call rotation to investigate and remediate escalated security events.
  • Evaluate and integrate new security tools and technologies into the SOC.
  • Partner with teams throughout the company to build secure solutions.
  • Write run books and draft incident reports for leadership.
  • Engineer solutions for current security attack methods.
  • Contribute to enhancing the overall Information Security Program.
  • Stay current on security industry trends through educational opportunities.

AWSPythonBashAzureGoCommunication SkillsProblem SolvingVerbal communication

Posted 3 months ago
Apply
Apply

📍 US

🧭 Full-Time

🔍 Cybersecurity

  • 2+ years of security monitoring and incident response experience.
  • Experience with Linux, Mac, and knowledge of Windows.
  • Configuration and maintenance experience with endpoint security solutions such as Crowdstrike, SentinelOne, and Carbon Black.
  • Experience with security tools including SIEM, Metasploit, Splunk, and Wireshark.
  • In-depth knowledge of SIEM log ingestion and alert creation.
  • Hands-on experience with TCP/IP and networking.
  • Ability to write scripts/code using Python or other scripting languages for automation.
  • Knowledge of incident response and investigation tools and techniques.
  • Experience with security operations in cloud platforms such as AWS, GCP, and Azure.
  • Experience in responding to security questionnaires and customer queries.
  • Represent security in internal and external meetings to discuss security analysis, findings and security/compliance responses.
  • Review past incidents and identify attack trends while fine-tuning alerts.
  • Participate in developing and implementing new security processes.
  • Identify and track assets to communicate potential risks and build action plans.
  • Maintain a repository of cybersecurity threat information for risk assessments.
  • Build tools for automating security events and reporting.
  • Implement and monitor IDS/IPS systems and reports.
  • Investigate security events to determine risks.
  • Develop tools to enhance security and threat intelligence workflows.
  • Collaborate on customer questionnaires and compliance audits.

AWSPythonCybersecurityGCPAzureLinuxNetworkingScripting

Posted 4 months ago
Apply
Apply

📍 United States

💸 $145,000 - $200,000 per year

🔍 Ticketing

🏢 Company: SeatGeek👥 500-1000💰 $238,000,000 Series E over 2 years agoSearch EngineTicketingSportsEventsEdiscovery

  • Experience working in a threat detection role and solid understanding of security fundamentals.
  • Proficiency in one or more programming languages (Python, C#, Go) for coding and code reviews.
  • Experience working with highly technical engineering teams.
  • Holistic solutions to secure a cloud environment rather than reactive fixes.
  • Ability to think like an attacker to improve detection & response.
  • Experience contributing to the security community (public research, blogging, presentations, etc.) is a plus.
  • Take ownership and drive Security Operations initiatives, both within and outside the team.
  • Lead our cloud security strategy and its implementation, partnering with our Cloud Product teams to build monitors and guardrails.
  • Hold an active role in our incident response & on-call programs, improving visibility, detections, and responses for critical systems.
  • Engineer resilient solutions and enhance our existing security controls, tools, and processes at scale through automation.
  • Partner with engineering and non-engineering teams to influence security awareness and best practices.

AWSPythonAgileC#StrategyGo

Posted 4 months ago
Apply