Apply

Senior Security Engineer

Posted about 2 months agoViewed

View full description

πŸ’Ž Seniority level: Senior, 5+ years

πŸ“ Location: United States

πŸ” Industry: Security

🏒 Company: VantaπŸ‘₯ 501-1000πŸ’° $150,000,000 Series C 8 months agoInternetArtificial Intelligence (AI)ComplianceCyber SecuritySoftware

πŸ—£οΈ Languages: English

⏳ Experience: 5+ years

πŸͺ„ Skills: Project ManagementCommunication SkillsCollaboration

Requirements:
  • Experience in threat modeling and penetration testing
  • Some coding experience and ability to read code for flaws
  • Strong collaboration and communication skills
  • Highly organized project management skills
Responsibilities:
  • Identify potential security risks through exercises
  • Prioritize and plan projects for risk resolution
  • Build maintainable programs for operational excellence
  • Collaborate on project plans and pull requests for security
  • Run tools to enhance the security program
  • Support bug bounty and penetration testing programs
  • Establish a network of security champions
  • Deliver training to address security knowledge gaps
  • Provide input in architectural discussions
Apply

Related Jobs

Apply

πŸ“ Canada, United States

🧭 Full-Time

πŸ’Έ 143000.0 - 210000.0 USD per year

πŸ” Security

  • Minimum of 5+ years of combined experience in security, GRC, risk, or a related space with hands-on technical work building automation solutions as they relate to compliance controls, evidence, GRC platforms, etc.
  • Experience in effectively analyzing data and programs for security risk, compliance, and maturity.
  • Willingness to wear different hats and work on areas where needed.
  • Must excel in communication, and demonstrate the ability to explain technical security concepts to a non-technical audience.
  • Must have a highly collaborative and teamwork-focused approach, as well as a heart for mentoring and leveling up your teammates.
  • Must be able to assess and mitigate corporate risk within the organization.
  • Sophisticated program/project management abilities.
  • Nice to have: experience with Drata and/or Vanta (integrations, automation, onboarding as a GRC platform).
  • Own, design and manage the continued enhancement of various GRC programs including but not limited to strategy, roadmap, and controls to address regulatory requirements across multiple jurisdictions.
  • Communicate our compliance framework and various program requirements to all relevant stakeholders (internal and external).
  • Engage cross-functionally (with groups such as Engineering, Finance, Legal, Product, and Sales) to establish a thoughtful, strategic and tactical approach to multiple GRC programs and related processes.
  • You will assist with analysis and preparation for internal and external audits.
  • Accurately and effectively communicate our compliance position and programs to auditors and customers.
  • Partner with other members of the security team to establish security guidelines that enable the organization to move fast in a safe and secure manner.
  • To operate as a technical leader by helping define the GRC roadmap and by leveling up junior employees.
  • Build strong relationships with partner and stakeholder teams in order to build a scalable GRC program.

Project ManagementSQLCloud ComputingCybersecurityData AnalysisCommunication SkillsAnalytical SkillsCollaborationMentoringDevOpsComplianceRisk Management

Posted 20 days ago
Apply
Apply

πŸ“ United States

🧭 Full-Time

πŸ” Software Development

🏒 Company: DockerπŸ‘₯ 251-500πŸ’° $105,000,000 Series C about 3 years agoDeveloper ToolsDeveloper PlatformInformation TechnologySoftware

  • Have 6 to 8 years of experience in Information Technology, Security Engineering, Governance, Risk and Compliance
  • Will have familiarity setting up APIs and Webhooks, at least one scripting language, and at least one public cloud architecture and control tool
  • Experience conducting security compliance reviews and audits for SaaS products and hosted environments including AWS and Azure.
  • Have strong knowledge of information security risk management and information security technologies (e.g: SIEM, vulnerability management, data loss prevention and /or endpoint protection)
  • Thrive in fast-paced environments and can adapt quickly in the face of constantly evolving cybersecurity challenges
  • Strong project management skills with the ability to lead and execute security assessment projects, vendor evaluations and initiatives on time with multiple stakeholders
  • Enjoy fostering collaboration and cross-functional partnerships to help spread awareness and
  • Build and implementation of cybersecurity controls
  • Have experience in-depth knowledge and experience of cybersecurity frameworks including ISO 27001, 27701 and 27018
  • Experience with the entire controls monitoring lifecycle, including identifying, assessing, monitoring, and remediating controls.
  • Excellent verbal and written communication skills with the ability to document, communicate, and report security assessments
  • Serve as the subject matter expert and provide technical leadership and feedback for compliance / GRC projects
  • Appropriately handling and managing confidential information including proprietary and trade secret information
  • Stay up-to-date with changes in regulations, standards, and emerging regulatory requirements and ensure compliance
  • Lead the development, implementation and maintenance of comprehensive GRC strategies
  • Build automated evidence gathering and continuous control testing through integrations maturing our governance program.
  • Establish partnerships with internal/external auditors, regulators, business stakeholders develop security requirements and controls.
  • Optimize security compliance monitoring and alerting systems; aggregate compliance alerts and advise on system policy violations
  • Perform critical data security reviews over newly released products and features.
  • Ensure controls are operating effectively via assessment and attestation
  • Own the vulnerability management program to identify and provide guidance for improvements
  • Security Metrics - Uses automated and manual processes to produce relevant KPIs about the Information security program
  • Policies and Procedures - Maintains corporate Information Security policies and departmental procedures and maps them to relevant control standards
  • Recertification - Operates periodic processes to hire, transfer, and termination protocols are complied with and regular access reviews are conducted
  • Security Awareness - Builds and maintains company awareness and education progress
  • Risk Assessment - Builds and operates the company platform to document, measure, and report assessments, risks, controls findings, and remediation activity
  • Draft policies and best practices that will be consumed by the entire organization
  • Maintain knowledge of certifications and controls such as SOC 2, ISO 27001 / ISO 27018, and 27701
  • Evaluate vendors against compliance and security standards

AWSDockerProject ManagementSQLCybersecurityJiraAPI testingAzureCommunication SkillsAnalytical SkillsCollaborationCI/CDProblem SolvingAgile methodologiesRESTful APIsLinuxDevOpsTerraformWritten communicationDocumentationMicroservicesComplianceMS OfficeRisk ManagementStakeholder managementScriptingSoftware Engineering

Posted 23 days ago
Apply
Apply

πŸ“ Colombia, Chile, Mexico, United States

πŸ” Sales

🏒 Company: Tenable, Inc.

  • Experience with cloud computing infrastructures such as AWS, Azure, GCP, etc.
  • Knowledge of Terraform, AWS CloudFormation, or other cloud automation tools
  • Engage with large clients to architect solutions
  • AWS Certified Security, Azure Security Engineering Certification, GCP Cloud Professional
  • Experienced in IaC DevOps workflow (DevSecOps preferred)
  • Perform tailored solution demonstrations
  • Partner with regional sales teams to drive product awareness
  • Run and own the complete PoV Process
  • Be a mentor for our customers and Channel Partners
  • Provide feedback to Product Management

AWSCloud ComputingCybersecurityGCPKubernetesSalesforceAzureCommunication SkillsCI/CDRESTful APIsMentoringDevOpsTerraformPresentation skillsComplianceJSONSales experience

Posted about 1 month ago
Apply
Apply
πŸ”₯ Senior Security Engineer
Posted about 1 month ago

πŸ“ United States

🧭 Full-Time

πŸ” Software Development

🏒 Company: Monarch Money

  • 5+ years of experience in security engineering roles, with a focus on data security, application security, and infrastructure security, ideally in a cloud-first environment.
  • Proficiency in a programming language (Python preferred) to support execution of security initiatives.
  • Demonstrated experience implementing data encryption and access controls for sensitive data.
  • Experience securing cloud environments (AWS preferred) with a deep understanding of IAM, VPCs, and security groups.
  • Knowledge of secure coding principles and experience with security testing tools (SAST, DAST) within CI/CD pipelines.
  • Ability to explain complex security concepts clearly to both technical and non-technical stakeholders.
  • Implement and enforce data encryption standards for data at rest and in transit, ensuring strong key management practices.
  • Design and maintain data access controls and policies, limiting access to sensitive data (e.g., PII) and enforcing the principle of least privilege.
  • Monitor and detect data exfiltration risks, unauthorized access, and anomalies around data handling.
  • Conduct regular audits of PII storage, access, and handling to ensure sensitive data remains secure.
  • Embed security best practices within the Software Development Lifecycle (SDLC), including secure coding, code review, and application security testing.
  • Deploy and maintain security tools in the CI/CD pipeline, such as SAST, DAST, and dependency scanning tools, to identify and remediate application vulnerabilities.
  • Perform threat modeling, vulnerability assessments, and penetration testing to identify and mitigate risks.
  • Design and enforce security configurations in cloud environments (e.g., AWS), including IAM roles, security groups, and VPC segmentation.
  • Establish automated monitoring and alerting to detect anomalies or potential breaches across cloud infrastructure.
  • Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote data security practices.
  • Work with leadership to align security initiatives with business goals, ensuring that security is a core component of product and infrastructure decisions.

AWSDockerPostgreSQLPythonCloud ComputingCybersecurityKubernetesMySQLCommunication SkillsCI/CDRESTful APIsLinuxDevOpsTerraformComplianceJSONAnsible

Posted about 1 month ago
Apply
Apply

πŸ“ United States, United Kingdom

🧭 Full-Time

πŸ’Έ 147000.0 - 184000.0 USD per year

πŸ” Security

🏒 Company: HackerOne

  • 5+ years of experience in detection and response related security roles
  • Experience working with AWS (or similar cloud environment), Linux, OSX, SentinelOne (or other similar endpoint security software)
  • Experience working with DataDog (or other similar log analysis and querying software)
  • Familiarity with modern programming languages of some kind such as Ruby, Python, Rust, JavaScript, and similar.
  • Proficient in responding to alerts and incidents within a cloud based SAAS environment
  • Adaptable thinker, able to creatively solve old problems in new ways and new problems in old ways
  • Strong collaboration and communication skills with other teams to plan a project, align priorities, lead and model the work, document your decisions, and complete the project
  • Understands ways to catch wily threat actors
  • Possesses the fine art of crafting useful, actionable, high signal alerts
  • Proficiency in automating detection and response processes through API calls, webhook creation, etc.
  • Willingness and ability to participate in the response to critical incidents as needed.
  • Evaluating potential detection techniques and tools and using them to create useful, actionable, high signal alerts.
  • Developing automation and improving existing tooling and alerting to minimize alert fatigue and maximize effective incident response.
  • Collaborating will be key as you will work closely with IT, Engineering, Support and other teams across the company.
  • You will play a vital role in managing security incidents, from assembling the response team to organizing and leading blameless retrospectives. You'll also help develop clear response processes for various types of incidents and playbooks for various alerts generated by our tools.

AWSDockerPythonCloud ComputingCybersecurityKubernetesAPI testingREST APICommunication SkillsAnalytical SkillsCollaborationCI/CDProblem SolvingLinuxDevOpsTerraformWritten communicationComplianceExcellent communication skillsAdaptabilityTeamworkTroubleshootingActive listeningJSONRisk ManagementStrategic thinkingScripting

Posted about 1 month ago
Apply
Apply

πŸ“ Alabama, Arizona, Arkansas, California, Colorado, Connecticut, Florida, Georgia, Illinois, Indiana, Iowa, Kansas, Kentucky, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, Ohio, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, or Washington, D.C.

🧭 Full-Time

πŸ’Έ 144000.0 - 189000.0 USD per year

πŸ” Health Insurance

🏒 Company: Oscar HealthπŸ‘₯ 1001-5000πŸ’° $140,000,000 Private over 4 years agoπŸ«‚ Last layoff almost 5 years agoHealth InsuranceInsurTechInsuranceHealth Care

  • 3+ years experience in security engineering or technical related role, focused on security operations
  • Deep understanding of security concepts, including network security, endpoint security, vulnerability management, and incident response.
  • Hands on experience with security information and event management (SIEM) systems.
  • Experience with security automation and orchestration tools.
  • Proficiency in scripting languages (e.g., Python, PowerShell, Bash).
  • Design, implement, and maintain security monitoring and detection systems, including SIEM, SOAR, and XDR platforms.
  • Develop and implement security automation workflows to improve security operations and incident response processes.
  • Enhance security visibility by implementing robust logging and alerting mechanisms across the environment.
  • Identify and improve security vulnerabilities and misconfigurations.
  • Lead incident response efforts, including containment, eradication, and postincident analysis.
  • Collaborate with other teams to integrate security best practices into their workflows.
  • Research emerging security technologies and threats.
  • Mentor junior security engineers.
  • Contribute to the development and maintenance of security policies and procedures.
  • Participate in on-call rotation for security incidents.
  • Compliance with all applicable laws and regulations.
  • Other duties as assigned.

AWSPythonCloud ComputingCybersecurityGCPAzureCommunication SkillsAnalytical SkillsProblem SolvingMentoringLinuxComplianceTeamworkScripting

Posted about 1 month ago
Apply
Apply
πŸ”₯ Senior Security Engineer
Posted about 2 months ago

πŸ“ United States

🧭 Full-Time

πŸ’Έ 200000.0 - 220000.0 USD per year

πŸ” Software Development

🏒 Company: Human InterestπŸ‘₯ 501-1000πŸ’° $161,000,000 Private about 2 years agoWealth ManagementRetirementFinanceInsurTechEmployee BenefitsInsuranceFinTech

  • Minimum 2 years in a security focused engineering role
  • Minimum 5 years in software engineering role.
  • Proficient coding ability in at least one modern programming language. E.g.Typescript/Javascript, Ruby, Java, Python, Golang
  • Practical experience securing cloud environments.
  • Strong communication skills: you can easily discuss complex technical concepts with both engineers and non-engineers.
  • Strong ownership and bias for action: You love to roll up your sleeves.
  • Leader and Mentor: You are a recognized leader in your areas of responsibility, and enjoy sharing knowledge and mentoring others.
  • Operational Excellence: you raise the bar on the quality of the software and infrastructure that you work on.
  • Build practical controls to improve the effectiveness and robustness of our engineering team
  • Foster a DevSecOps culture through education, automation, and tooling.
  • Secure our SDLC process through automation
  • Implement checks in pipeline
  • Perform security reviews of application code
  • Take part in team on call rotation for security events and monitoring alerts
  • Advocate and educate security best practices
  • Create tooling and automation to efficiently respond to security events
  • Partner with stakeholders to respond and mitigate security threats

AWSPythonSoftware DevelopmentSQLCloud ComputingCybersecurityCommunication SkillsCI/CDRESTful APIsDevOpsJSONScriptingSoftware Engineering

Posted about 2 months ago
Apply