Apply

Senior Security Engineer

Posted 1 day agoViewed

View full description

💎 Seniority level: Senior, 5+ years

📍 Location: Canada

🔍 Industry: Software Development

🏢 Company: Docker👥 251-500💰 $105,000,000 Series C almost 3 years agoDeveloper ToolsDeveloper PlatformInformation TechnologySoftware

🗣️ Languages: English

⏳ Experience: 5+ years

🪄 Skills: AWSDockerPythonSoftware DevelopmentCloud ComputingCybersecurityKubernetesOAuthGoCI/CDRESTful APIsLinuxDevOpsTerraformCompliance

Requirements:
  • 5+ years of experience security engineering roles, with a focus on product security, infrastructure security, ideally in a cloud-first environment
  • 3+ years of experience developing in Python or Golang
  • Knowledge of secure coding principles and experience with security testing tools (SAST, DAST) within CI/CD pipelines
  • Understand, authentication, authorization, including technologies like OAuth, SAML, OIDC, MFA, cryptography applications and Zero Trust principals.
  • Strong cloud expertise with hands-on experience in cloud ecosystems (e.g: AWS, GCP, or Azure)
  • Knowledge on securing containerized environments: (Docker, Kubernetes) and implementing runtime security tools
  • Previous experience evolving and enforcing policies to assist co-workers in maintaining corporate and cloud security
  • Familiar with data privacy and compliance regulations (e.g, SOC 2, ISO 27xxx, GDPR, CCPA, FIPS) aligning security initiatives
Responsibilities:
  • Embed security best practices within the Software Development Lifecycle (SDLC), including secure coding, code review, and application security testing
  • Partner closely with engineering to drive security architecture and processes that implement security controls across our software and systems
  • Design and enforce security configurations in cloud environments (e.g. AWS), including IAM roles, security groups, and VPC segmentation
  • Establish automated monitoring and alerting to detect anomalies or potential breaches across cloud infrastructure
  • Maintain cloud and infrastructure security: AWS Security Hub, AWS IAM, AWS Key Management (KMS), OPA for Terraform
  • Take ownership, define strategy, and drive improvement for part so our security program such as threat modeling, secrets management, or container security
  • Plan and perform product security assessments including architecture review, threat modeling, code review, pen testing and general security consulting to proactively build security controls
  • Partner with detection and response to create new capabilities or respond to security events
  • Work with leadership to align security initiatives with business goals, ensuring that security is a core component of product and infrastructure
  • Serve as a security subject matter expert for software security and architecture
  • Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote security practices
  • Have the ability to participate in our incident response team on-call rotation
Apply

Related Jobs

Apply

📍 United States, Canada

🧭 Full-Time

💸 124000.0 - 155000.0 USD per year

🔍 Software Development

🏢 Company: Recharge👥 11-50Electronics

  • 5+ years of experience in network and/or security roles, with a focus on edge security tools
  • 2+ years experience with k8s, Helm, IaC, Terraform, Docker, Linux, Kubernetes, etc
  • 2+ years experience with Monitoring, Metrics and Logging (Splunk) solutions
  • 2+ years experience in cloud-native environments such as GCP, AWS, or Azure
  • Bachelor’s degree in Computer Science, Information Technology, or related field
  • Relevant certifications such as CISSP, CCSP, GSEC, or equivalent
  • Design, implement, and maintain secure cloud / network architectures, ensuring the confidentiality, integrity, and availability of data.
  • Review IAM and access controls to ensure adherence to the principles of least privilege.
  • Create and maintain network and security documentation.
  • Collaborate with cross-functional teams to integrate security measures into network designs and implementations.
  • Manage Endpoint / EDR / XDR / Anti-malware tools and policies
  • Monitor network traffic for unusual activity and respond to security incidents in a timely manner.
  • Audit and review user and merchant network activity to ensure system and data safety
  • Conduct regular vulnerability assessments on network infrastructure to identify and remediate potential security risks.
  • Maintain and continuously improve incident response plans, participate in tabletop exercises, and lead incident response efforts when necessary.
  • Mentor other engineers on security configurations and best practices
  • Investigate, analyze and evangelize good security posture throughout the organization
  • Automate security tools and processes where possible
  • Live by and champion our values: Accountability, Collaboration, Iteration and Details

AWSDockerCloud ComputingGCPKubernetesAzureLinuxTerraformCompliance

Posted 18 days ago
Apply
Apply
🔥 Senior Security Engineer
Posted about 1 month ago

📍 Canada

🧭 Full-Time

🔍 Financial services / Cryptocurrency

🏢 Company: Shakepay👥 51-100💰 $35,197,607 Series A about 3 years agoCryptocurrencyBitcoinPaymentsFinTech

  • 5+ years of broad Security experience, including Enterprise & Operational Security, Incident Response, Offensive Security, GRC, and Product Security.
  • 5+ years experience in a cloud environment, preferably AWS.
  • Proficiency in a high-level programming language for automation and alert capabilities.
  • Exceptional communication skills for managing expectations and scope.
  • Experience in a highly regulated environment, preferably a startup.
  • Work closely with teams to design security solutions balancing security needs with customer experience and product growth.
  • Serve as a subject matter expert and mentor in security domains.
  • Manage internal and external relationships regarding security processes.
  • Lead threat modeling for production and development systems.
  • Own and improve the Zero Trust environment.
  • Build and automate alert responses in code.
  • Participate in an on-call rotation during incidents.
  • Engage in governance, compliance, and regulatory audits.

AWSCybersecurityGitCompliance

Posted about 1 month ago
Apply
Apply

📍 United States, Canada

🧭 Full-Time

🔍 Security

In-depth knowledge of IAM principles, standards, and best practices
  • Design, implement, and maintain robust IAM solutions
  • Manage authentication, authorization, and provisioning across diverse platforms
  • Collaborate closely with various teams to ensure alignment between IAM solutions and organizational security requirements

AWSCloud ComputingCybersecurityLDAPOAuth

Posted about 2 months ago
Apply
Apply

📍 United States, Canada

🧭 Full-Time

🔍 Healthcare Technology

  • 5+ years experience with AWS services
  • Strong knowledge of Kubernetes
  • Experience with microservices architecture
  • Design and implement cloud infrastructure
  • Lead technical architecture decisions
  • Mentor junior engineers

AWSCloud ComputingCybersecurityComplianceRisk Management

Posted about 2 months ago
Apply