Apply

Senior Security Engineer

Posted about 2 months agoViewed

View full description

💎 Seniority level: Senior, 5 years

📍 Location: United States

💸 Salary: 200000.0 - 220000.0 USD per year

🔍 Industry: Software Development

🏢 Company: Human Interest👥 501-1000💰 $161,000,000 Private about 2 years agoWealth ManagementRetirementFinanceInsurTechEmployee BenefitsInsuranceFinTech

🗣️ Languages: English

⏳ Experience: 5 years

🪄 Skills: AWSPythonSoftware DevelopmentSQLCloud ComputingCybersecurityCommunication SkillsCI/CDRESTful APIsDevOpsJSONScriptingSoftware Engineering

Requirements:
  • Minimum 2 years in a security focused engineering role
  • Minimum 5 years in software engineering role.
  • Proficient coding ability in at least one modern programming language. E.g.Typescript/Javascript, Ruby, Java, Python, Golang
  • Practical experience securing cloud environments.
  • Strong communication skills: you can easily discuss complex technical concepts with both engineers and non-engineers.
  • Strong ownership and bias for action: You love to roll up your sleeves.
  • Leader and Mentor: You are a recognized leader in your areas of responsibility, and enjoy sharing knowledge and mentoring others.
  • Operational Excellence: you raise the bar on the quality of the software and infrastructure that you work on.
Responsibilities:
  • Build practical controls to improve the effectiveness and robustness of our engineering team
  • Foster a DevSecOps culture through education, automation, and tooling.
  • Secure our SDLC process through automation
  • Implement checks in pipeline
  • Perform security reviews of application code
  • Take part in team on call rotation for security events and monitoring alerts
  • Advocate and educate security best practices
  • Create tooling and automation to efficiently respond to security events
  • Partner with stakeholders to respond and mitigate security threats
Apply

Related Jobs

Apply

📍 United States

💸 145000.0 - 160000.0 USD per year

🔍 Software Development

🏢 Company: Harness

  • At least 7 years of relevant industry experience in roles such as systems engineer, security engineer, cloud security specialist, or site reliability engineer.
  • Expert-level professional knowledge in enterprise applications and infrastructure.
  • Extensive experience working in a cloud-native environment, with proficiency in platforms like AWS, GCP, and Azure.
  • Familiarity with industry regulations and compliance certifications, including ISO 27001, SOC 2, FedRAMP, and SOX.
  • A desire to contribute to a high-growth environment and take a leading role in building new programs from the ground up.
  • Strong attention to detail and a willingness to ask questions when uncertain.
  • Comfort with ambiguity, with a proactive approach to bringing clarity in uncertain situations.
  • Take a leading role in the design of the next level of secure operations for Harness' cloud and business infrastructure
  • Take charge of implementing and overseeing security tooling, encompassing the detection and alerting systems for identifying malicious activity and insecure configurations
  • Utilize automation to effectively manage and enhance the security posture of Harness' multi-cloud Kubernetes-based infrastructure
  • Use Harness CI/CD to integrate security processes like vulnerability management into the SDLC
  • Contribute to the development, review, and implementation of technical security and compliance-related engineering requirements across global Engineering teams
  • Detect, respond, and mitigate security related events and incidents.
  • Collaborate with fellow Developers and Product Managers to analyze and implement security standards, methods, and architectures

AWSCloud ComputingCybersecurityGCPKubernetesAzureCI/CDRESTful APIsLinuxDevOpsTerraformComplianceAnsibleScripting

Posted 4 days ago
Apply
Apply

📍 United States

🧭 Full-Time

🔍 Payments, Healthcare

🏢 Company: Truemed👥 1-10💰 $3,500,000 Seed over 1 year agoPaymentsWellnessHealth Care

  • 5+ years of experience in security engineering, compliance, or security operations
  • Hands-on experience with SOC2 Type II audits
  • Strong background in vulnerability management, endpoint security, and secure software development practices
  • Familiarity with MDMs, antivirus tools, SIEMs, and web security best practices
  • Experience working with GRC teams and responding to enterprise security questionnaires
  • Lead SOC2 Type II Compliance
  • Governance, Risk, and Compliance (GRC)
  • Security Tooling & Implementation
  • Incident Response & Risk Mitigation
  • Cross-Team Collaboration

CybersecurityComplianceRisk Management

Posted 7 days ago
Apply
Apply

📍 Canada, United States

🧭 Full-Time

💸 143000.0 - 210000.0 USD per year

🔍 Security

  • Minimum of 5+ years of combined experience in security, GRC, risk, or a related space with hands-on technical work building automation solutions as they relate to compliance controls, evidence, GRC platforms, etc.
  • Experience in effectively analyzing data and programs for security risk, compliance, and maturity.
  • Willingness to wear different hats and work on areas where needed.
  • Must excel in communication, and demonstrate the ability to explain technical security concepts to a non-technical audience.
  • Must have a highly collaborative and teamwork-focused approach, as well as a heart for mentoring and leveling up your teammates.
  • Must be able to assess and mitigate corporate risk within the organization.
  • Sophisticated program/project management abilities.
  • Nice to have: experience with Drata and/or Vanta (integrations, automation, onboarding as a GRC platform).
  • Own, design and manage the continued enhancement of various GRC programs including but not limited to strategy, roadmap, and controls to address regulatory requirements across multiple jurisdictions.
  • Communicate our compliance framework and various program requirements to all relevant stakeholders (internal and external).
  • Engage cross-functionally (with groups such as Engineering, Finance, Legal, Product, and Sales) to establish a thoughtful, strategic and tactical approach to multiple GRC programs and related processes.
  • You will assist with analysis and preparation for internal and external audits.
  • Accurately and effectively communicate our compliance position and programs to auditors and customers.
  • Partner with other members of the security team to establish security guidelines that enable the organization to move fast in a safe and secure manner.
  • To operate as a technical leader by helping define the GRC roadmap and by leveling up junior employees.
  • Build strong relationships with partner and stakeholder teams in order to build a scalable GRC program.

Project ManagementSQLCloud ComputingCybersecurityData AnalysisCommunication SkillsAnalytical SkillsCollaborationMentoringDevOpsComplianceRisk Management

Posted 19 days ago
Apply
Apply

📍 United States

🧭 Full-Time

🔍 Software Development

🏢 Company: Docker👥 251-500💰 $105,000,000 Series C about 3 years agoDeveloper ToolsDeveloper PlatformInformation TechnologySoftware

  • Have 6 to 8 years of experience in Information Technology, Security Engineering, Governance, Risk and Compliance
  • Will have familiarity setting up APIs and Webhooks, at least one scripting language, and at least one public cloud architecture and control tool
  • Experience conducting security compliance reviews and audits for SaaS products and hosted environments including AWS and Azure.
  • Have strong knowledge of information security risk management and information security technologies (e.g: SIEM, vulnerability management, data loss prevention and /or endpoint protection)
  • Thrive in fast-paced environments and can adapt quickly in the face of constantly evolving cybersecurity challenges
  • Strong project management skills with the ability to lead and execute security assessment projects, vendor evaluations and initiatives on time with multiple stakeholders
  • Enjoy fostering collaboration and cross-functional partnerships to help spread awareness and
  • Build and implementation of cybersecurity controls
  • Have experience in-depth knowledge and experience of cybersecurity frameworks including ISO 27001, 27701 and 27018
  • Experience with the entire controls monitoring lifecycle, including identifying, assessing, monitoring, and remediating controls.
  • Excellent verbal and written communication skills with the ability to document, communicate, and report security assessments
  • Serve as the subject matter expert and provide technical leadership and feedback for compliance / GRC projects
  • Appropriately handling and managing confidential information including proprietary and trade secret information
  • Stay up-to-date with changes in regulations, standards, and emerging regulatory requirements and ensure compliance
  • Lead the development, implementation and maintenance of comprehensive GRC strategies
  • Build automated evidence gathering and continuous control testing through integrations maturing our governance program.
  • Establish partnerships with internal/external auditors, regulators, business stakeholders develop security requirements and controls.
  • Optimize security compliance monitoring and alerting systems; aggregate compliance alerts and advise on system policy violations
  • Perform critical data security reviews over newly released products and features.
  • Ensure controls are operating effectively via assessment and attestation
  • Own the vulnerability management program to identify and provide guidance for improvements
  • Security Metrics - Uses automated and manual processes to produce relevant KPIs about the Information security program
  • Policies and Procedures - Maintains corporate Information Security policies and departmental procedures and maps them to relevant control standards
  • Recertification - Operates periodic processes to hire, transfer, and termination protocols are complied with and regular access reviews are conducted
  • Security Awareness - Builds and maintains company awareness and education progress
  • Risk Assessment - Builds and operates the company platform to document, measure, and report assessments, risks, controls findings, and remediation activity
  • Draft policies and best practices that will be consumed by the entire organization
  • Maintain knowledge of certifications and controls such as SOC 2, ISO 27001 / ISO 27018, and 27701
  • Evaluate vendors against compliance and security standards

AWSDockerProject ManagementSQLCybersecurityJiraAPI testingAzureCommunication SkillsAnalytical SkillsCollaborationCI/CDProblem SolvingAgile methodologiesRESTful APIsLinuxDevOpsTerraformWritten communicationDocumentationMicroservicesComplianceMS OfficeRisk ManagementStakeholder managementScriptingSoftware Engineering

Posted 22 days ago
Apply
Apply

📍 Colombia, Chile, Mexico, United States

🔍 Sales

🏢 Company: Tenable, Inc.

  • Experience with cloud computing infrastructures such as AWS, Azure, GCP, etc.
  • Knowledge of Terraform, AWS CloudFormation, or other cloud automation tools
  • Engage with large clients to architect solutions
  • AWS Certified Security, Azure Security Engineering Certification, GCP Cloud Professional
  • Experienced in IaC DevOps workflow (DevSecOps preferred)
  • Perform tailored solution demonstrations
  • Partner with regional sales teams to drive product awareness
  • Run and own the complete PoV Process
  • Be a mentor for our customers and Channel Partners
  • Provide feedback to Product Management

AWSCloud ComputingCybersecurityGCPKubernetesSalesforceAzureCommunication SkillsCI/CDRESTful APIsMentoringDevOpsTerraformPresentation skillsComplianceJSONSales experience

Posted about 1 month ago
Apply
Apply
🔥 Senior Security Engineer
Posted about 1 month ago

📍 United States

🧭 Full-Time

🔍 Software Development

🏢 Company: Monarch Money

  • 5+ years of experience in security engineering roles, with a focus on data security, application security, and infrastructure security, ideally in a cloud-first environment.
  • Proficiency in a programming language (Python preferred) to support execution of security initiatives.
  • Demonstrated experience implementing data encryption and access controls for sensitive data.
  • Experience securing cloud environments (AWS preferred) with a deep understanding of IAM, VPCs, and security groups.
  • Knowledge of secure coding principles and experience with security testing tools (SAST, DAST) within CI/CD pipelines.
  • Ability to explain complex security concepts clearly to both technical and non-technical stakeholders.
  • Implement and enforce data encryption standards for data at rest and in transit, ensuring strong key management practices.
  • Design and maintain data access controls and policies, limiting access to sensitive data (e.g., PII) and enforcing the principle of least privilege.
  • Monitor and detect data exfiltration risks, unauthorized access, and anomalies around data handling.
  • Conduct regular audits of PII storage, access, and handling to ensure sensitive data remains secure.
  • Embed security best practices within the Software Development Lifecycle (SDLC), including secure coding, code review, and application security testing.
  • Deploy and maintain security tools in the CI/CD pipeline, such as SAST, DAST, and dependency scanning tools, to identify and remediate application vulnerabilities.
  • Perform threat modeling, vulnerability assessments, and penetration testing to identify and mitigate risks.
  • Design and enforce security configurations in cloud environments (e.g., AWS), including IAM roles, security groups, and VPC segmentation.
  • Establish automated monitoring and alerting to detect anomalies or potential breaches across cloud infrastructure.
  • Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote data security practices.
  • Work with leadership to align security initiatives with business goals, ensuring that security is a core component of product and infrastructure decisions.

AWSDockerPostgreSQLPythonCloud ComputingCybersecurityKubernetesMySQLCommunication SkillsCI/CDRESTful APIsLinuxDevOpsTerraformComplianceJSONAnsible

Posted about 1 month ago
Apply
Apply

📍 United States, United Kingdom

🧭 Full-Time

💸 147000.0 - 184000.0 USD per year

🔍 Security

🏢 Company: HackerOne

  • 5+ years of experience in detection and response related security roles
  • Experience working with AWS (or similar cloud environment), Linux, OSX, SentinelOne (or other similar endpoint security software)
  • Experience working with DataDog (or other similar log analysis and querying software)
  • Familiarity with modern programming languages of some kind such as Ruby, Python, Rust, JavaScript, and similar.
  • Proficient in responding to alerts and incidents within a cloud based SAAS environment
  • Adaptable thinker, able to creatively solve old problems in new ways and new problems in old ways
  • Strong collaboration and communication skills with other teams to plan a project, align priorities, lead and model the work, document your decisions, and complete the project
  • Understands ways to catch wily threat actors
  • Possesses the fine art of crafting useful, actionable, high signal alerts
  • Proficiency in automating detection and response processes through API calls, webhook creation, etc.
  • Willingness and ability to participate in the response to critical incidents as needed.
  • Evaluating potential detection techniques and tools and using them to create useful, actionable, high signal alerts.
  • Developing automation and improving existing tooling and alerting to minimize alert fatigue and maximize effective incident response.
  • Collaborating will be key as you will work closely with IT, Engineering, Support and other teams across the company.
  • You will play a vital role in managing security incidents, from assembling the response team to organizing and leading blameless retrospectives. You'll also help develop clear response processes for various types of incidents and playbooks for various alerts generated by our tools.

AWSDockerPythonCloud ComputingCybersecurityKubernetesAPI testingREST APICommunication SkillsAnalytical SkillsCollaborationCI/CDProblem SolvingLinuxDevOpsTerraformWritten communicationComplianceExcellent communication skillsAdaptabilityTeamworkTroubleshootingActive listeningJSONRisk ManagementStrategic thinkingScripting

Posted about 1 month ago
Apply
Apply

📍 Alabama, Arizona, Arkansas, California, Colorado, Connecticut, Florida, Georgia, Illinois, Indiana, Iowa, Kansas, Kentucky, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, Ohio, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, or Washington, D.C.

🧭 Full-Time

💸 144000.0 - 189000.0 USD per year

🔍 Health Insurance

🏢 Company: Oscar Health👥 1001-5000💰 $140,000,000 Private over 4 years ago🫂 Last layoff almost 5 years agoHealth InsuranceInsurTechInsuranceHealth Care

  • 3+ years experience in security engineering or technical related role, focused on security operations
  • Deep understanding of security concepts, including network security, endpoint security, vulnerability management, and incident response.
  • Hands on experience with security information and event management (SIEM) systems.
  • Experience with security automation and orchestration tools.
  • Proficiency in scripting languages (e.g., Python, PowerShell, Bash).
  • Design, implement, and maintain security monitoring and detection systems, including SIEM, SOAR, and XDR platforms.
  • Develop and implement security automation workflows to improve security operations and incident response processes.
  • Enhance security visibility by implementing robust logging and alerting mechanisms across the environment.
  • Identify and improve security vulnerabilities and misconfigurations.
  • Lead incident response efforts, including containment, eradication, and postincident analysis.
  • Collaborate with other teams to integrate security best practices into their workflows.
  • Research emerging security technologies and threats.
  • Mentor junior security engineers.
  • Contribute to the development and maintenance of security policies and procedures.
  • Participate in on-call rotation for security incidents.
  • Compliance with all applicable laws and regulations.
  • Other duties as assigned.

AWSPythonCloud ComputingCybersecurityGCPAzureCommunication SkillsAnalytical SkillsProblem SolvingMentoringLinuxComplianceTeamworkScripting

Posted about 1 month ago
Apply
Apply
🔥 Senior Security Engineer
Posted about 1 month ago

📍 United States

🧭 Full-Time

💸 109305.0 - 136631.0 USD per year

🔍 FinTech

🏢 Company: joinroot

  • At least three years of experience in application security, security engineering, or cloud security. This includes a strong understanding of cloud security principles in AWS, GCP, or Azure, with hands-on experience securing cloud-based applications and infrastructure (e.g., IAM, network security, logging/monitoring).
  • Proven ability to identify, assess, and mitigate security risks at scale in modern software development environments.
  • Ability to translate security best practices into engineering requirements, especially as they relate to application security.
  • Strong understanding of the OWASP Top Ten and SAMM framework for measuring and improving application security maturity.
  • Experience performing threat modeling, particularly in an Agile development environment.
  • Experience maintaining SAST and/or SCA tools, including the maintenance and tuning of detections.
  • Proficiency in scripting and automation using programming languages such as Python or Ruby.
  • Experience embedding security solutions into DevOps processes and pipelines and leveraging automation to enforce security policies.
  • Familiarity with common attack vectors, industry best practices, and risk mitigation strategies.
  • Experience working with compliance frameworks (e.g., SOC 2, PCI-DSS, NIST, ISO 27001).
  • Strong analytical abilities and excellent communication skills, enabling you to effectively influence both technical and non-technical stakeholders.
  • Willingness to participate in an on-call rotation to address critical security incidents and ensure timely response.
  • Proactively identify, assess, and remediate security vulnerabilities across cloud infrastructure, applications, and internal systems.
  • Drive projects that safeguard Root’s products, infrastructure, and customer data.
  • Lead threat modeling sessions, security reviews, and architectural assessments to bolster our product security.
  • Collaborate with engineering and DevOps teams to integrate security best practices throughout the software development lifecycle (SDLC) and cloud operations.
  • Implement and refine security monitoring, detection, and response capabilities across our technology ecosystem.
  • Provide technical leadership and mentorship to engineering teams on secure coding, vulnerability management, and risk assessment.
  • Work alongside compliance and risk teams to align security initiatives with regulatory requirements (e.g., SOC 2, PCI-DSS, NIST, OWASP).
  • Develop and deploy automation tools and processes that streamline security operations and reduce friction for development teams.
  • Keep current with emerging threats, vulnerabilities, and industry trends to continuously evolve Root’s security program.

AWSDockerPythonSQLCloud ComputingCybersecurityGCPKubernetesLDAPAzureCI/CDRESTful APIsLinuxDevOpsTerraformComplianceNetworkingJSONRisk ManagementAnsibleScripting

Posted about 1 month ago
Apply
Apply
🔥 Senior Security Engineer
Posted about 1 month ago

📍 United States

🧭 Full-Time

🔍 Security

🏢 Company: Vanta👥 501-1000💰 $150,000,000 Series C 8 months agoInternetArtificial Intelligence (AI)ComplianceCyber SecuritySoftware

  • Experience in threat modeling and penetration testing
  • Some coding experience and ability to read code for flaws
  • Strong collaboration and communication skills
  • Highly organized project management skills
  • Identify potential security risks through exercises
  • Prioritize and plan projects for risk resolution
  • Build maintainable programs for operational excellence
  • Collaborate on project plans and pull requests for security
  • Run tools to enhance the security program
  • Support bug bounty and penetration testing programs
  • Establish a network of security champions
  • Deliver training to address security knowledge gaps
  • Provide input in architectural discussions

Project ManagementCommunication SkillsCollaboration

Posted about 1 month ago
Apply