Apply

Senior Security Engineer

Posted 3 days agoViewed

View full description

πŸ’Ž Seniority level: Senior, 5+ years

πŸ“ Location: United States

πŸ” Industry: Payments, Healthcare

🏒 Company: TruemedπŸ‘₯ 1-10πŸ’° $3,500,000 Seed over 1 year agoPaymentsWellnessHealth Care

πŸ—£οΈ Languages: English

⏳ Experience: 5+ years

πŸͺ„ Skills: CybersecurityComplianceRisk Management

Requirements:
  • 5+ years of experience in security engineering, compliance, or security operations
  • Hands-on experience with SOC2 Type II audits
  • Strong background in vulnerability management, endpoint security, and secure software development practices
  • Familiarity with MDMs, antivirus tools, SIEMs, and web security best practices
  • Experience working with GRC teams and responding to enterprise security questionnaires
Responsibilities:
  • Lead SOC2 Type II Compliance
  • Governance, Risk, and Compliance (GRC)
  • Security Tooling & Implementation
  • Incident Response & Risk Mitigation
  • Cross-Team Collaboration
Apply

Related Jobs

Apply

πŸ“ United States

πŸ’Έ 145000.0 - 160000.0 USD per year

πŸ” Software Development

🏒 Company: Harness

  • At least 7 years of relevant industry experience in roles such as systems engineer, security engineer, cloud security specialist, or site reliability engineer.
  • Expert-level professional knowledge in enterprise applications and infrastructure.
  • Extensive experience working in a cloud-native environment, with proficiency in platforms like AWS, GCP, and Azure.
  • Familiarity with industry regulations and compliance certifications, including ISO 27001, SOC 2, FedRAMP, and SOX.
  • A desire to contribute to a high-growth environment and take a leading role in building new programs from the ground up.
  • Strong attention to detail and a willingness to ask questions when uncertain.
  • Comfort with ambiguity, with a proactive approach to bringing clarity in uncertain situations.
  • Take a leading role in the design of the next level of secure operations for Harness' cloud and business infrastructure
  • Take charge of implementing and overseeing security tooling, encompassing the detection and alerting systems for identifying malicious activity and insecure configurations
  • Utilize automation to effectively manage and enhance the security posture of Harness' multi-cloud Kubernetes-based infrastructure
  • Use Harness CI/CD to integrate security processes like vulnerability management into the SDLC
  • Contribute to the development, review, and implementation of technical security and compliance-related engineering requirements across global Engineering teams
  • Detect, respond, and mitigate security related events and incidents.
  • Collaborate with fellow Developers and Product Managers to analyze and implement security standards, methods, and architectures

AWSCloud ComputingCybersecurityGCPKubernetesAzureCI/CDRESTful APIsLinuxDevOpsTerraformComplianceAnsibleScripting

Posted about 21 hours ago
Apply
Apply

πŸ“ United States

🧭 Full-Time

πŸ” Software Development

🏒 Company: DockerπŸ‘₯ 251-500πŸ’° $105,000,000 Series C almost 3 years agoDeveloper ToolsDeveloper PlatformInformation TechnologySoftware

  • Have 6 to 8 years of experience in Information Technology, Security Engineering, Governance, Risk and Compliance
  • Will have familiarity setting up APIs and Webhooks, at least one scripting language, and at least one public cloud architecture and control tool
  • Experience conducting security compliance reviews and audits for SaaS products and hosted environments including AWS and Azure.
  • Have strong knowledge of information security risk management and information security technologies (e.g: SIEM, vulnerability management, data loss prevention and /or endpoint protection)
  • Thrive in fast-paced environments and can adapt quickly in the face of constantly evolving cybersecurity challenges
  • Strong project management skills with the ability to lead and execute security assessment projects, vendor evaluations and initiatives on time with multiple stakeholders
  • Enjoy fostering collaboration and cross-functional partnerships to help spread awareness and
  • Build and implementation of cybersecurity controls
  • Have experience in-depth knowledge and experience of cybersecurity frameworks including ISO 27001, 27701 and 27018
  • Experience with the entire controls monitoring lifecycle, including identifying, assessing, monitoring, and remediating controls.
  • Excellent verbal and written communication skills with the ability to document, communicate, and report security assessments
  • Serve as the subject matter expert and provide technical leadership and feedback for compliance / GRC projects
  • Appropriately handling and managing confidential information including proprietary and trade secret information
  • Stay up-to-date with changes in regulations, standards, and emerging regulatory requirements and ensure compliance
  • Lead the development, implementation and maintenance of comprehensive GRC strategies
  • Build automated evidence gathering and continuous control testing through integrations maturing our governance program.
  • Establish partnerships with internal/external auditors, regulators, business stakeholders develop security requirements and controls.
  • Optimize security compliance monitoring and alerting systems; aggregate compliance alerts and advise on system policy violations
  • Perform critical data security reviews over newly released products and features.
  • Ensure controls are operating effectively via assessment and attestation
  • Own the vulnerability management program to identify and provide guidance for improvements
  • Security Metrics - Uses automated and manual processes to produce relevant KPIs about the Information security program
  • Policies and Procedures - Maintains corporate Information Security policies and departmental procedures and maps them to relevant control standards
  • Recertification - Operates periodic processes to hire, transfer, and termination protocols are complied with and regular access reviews are conducted
  • Security Awareness - Builds and maintains company awareness and education progress
  • Risk Assessment - Builds and operates the company platform to document, measure, and report assessments, risks, controls findings, and remediation activity
  • Draft policies and best practices that will be consumed by the entire organization
  • Maintain knowledge of certifications and controls such as SOC 2, ISO 27001 / ISO 27018, and 27701
  • Evaluate vendors against compliance and security standards

AWSDockerProject ManagementSQLCybersecurityJiraAPI testingAzureCommunication SkillsAnalytical SkillsCollaborationCI/CDProblem SolvingAgile methodologiesRESTful APIsLinuxDevOpsTerraformWritten communicationDocumentationMicroservicesComplianceMS OfficeRisk ManagementStakeholder managementScriptingSoftware Engineering

Posted 18 days ago
Apply
Apply

πŸ“ Colombia, Chile, Mexico, United States

πŸ” Sales

🏒 Company: Tenable, Inc.

  • Experience with cloud computing infrastructures such as AWS, Azure, GCP, etc.
  • Knowledge of Terraform, AWS CloudFormation, or other cloud automation tools
  • Engage with large clients to architect solutions
  • AWS Certified Security, Azure Security Engineering Certification, GCP Cloud Professional
  • Experienced in IaC DevOps workflow (DevSecOps preferred)
  • Perform tailored solution demonstrations
  • Partner with regional sales teams to drive product awareness
  • Run and own the complete PoV Process
  • Be a mentor for our customers and Channel Partners
  • Provide feedback to Product Management

AWSCloud ComputingCybersecurityGCPKubernetesSalesforceAzureCommunication SkillsCI/CDRESTful APIsMentoringDevOpsTerraformPresentation skillsComplianceJSONSales experience

Posted 30 days ago
Apply
Apply
πŸ”₯ Senior Security Engineer
Posted about 1 month ago

πŸ“ United States

🧭 Full-Time

πŸ” Software Development

🏒 Company: Monarch Money

  • 5+ years of experience in security engineering roles, with a focus on data security, application security, and infrastructure security, ideally in a cloud-first environment.
  • Proficiency in a programming language (Python preferred) to support execution of security initiatives.
  • Demonstrated experience implementing data encryption and access controls for sensitive data.
  • Experience securing cloud environments (AWS preferred) with a deep understanding of IAM, VPCs, and security groups.
  • Knowledge of secure coding principles and experience with security testing tools (SAST, DAST) within CI/CD pipelines.
  • Ability to explain complex security concepts clearly to both technical and non-technical stakeholders.
  • Implement and enforce data encryption standards for data at rest and in transit, ensuring strong key management practices.
  • Design and maintain data access controls and policies, limiting access to sensitive data (e.g., PII) and enforcing the principle of least privilege.
  • Monitor and detect data exfiltration risks, unauthorized access, and anomalies around data handling.
  • Conduct regular audits of PII storage, access, and handling to ensure sensitive data remains secure.
  • Embed security best practices within the Software Development Lifecycle (SDLC), including secure coding, code review, and application security testing.
  • Deploy and maintain security tools in the CI/CD pipeline, such as SAST, DAST, and dependency scanning tools, to identify and remediate application vulnerabilities.
  • Perform threat modeling, vulnerability assessments, and penetration testing to identify and mitigate risks.
  • Design and enforce security configurations in cloud environments (e.g., AWS), including IAM roles, security groups, and VPC segmentation.
  • Establish automated monitoring and alerting to detect anomalies or potential breaches across cloud infrastructure.
  • Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote data security practices.
  • Work with leadership to align security initiatives with business goals, ensuring that security is a core component of product and infrastructure decisions.

AWSDockerPostgreSQLPythonCloud ComputingCybersecurityKubernetesMySQLCommunication SkillsCI/CDRESTful APIsLinuxDevOpsTerraformComplianceJSONAnsible

Posted about 1 month ago
Apply
Apply

πŸ“ United States, United Kingdom

🧭 Full-Time

πŸ’Έ 147000.0 - 184000.0 USD per year

πŸ” Security

🏒 Company: HackerOne

  • 5+ years of experience in detection and response related security roles
  • Experience working with AWS (or similar cloud environment), Linux, OSX, SentinelOne (or other similar endpoint security software)
  • Experience working with DataDog (or other similar log analysis and querying software)
  • Familiarity with modern programming languages of some kind such as Ruby, Python, Rust, JavaScript, and similar.
  • Proficient in responding to alerts and incidents within a cloud based SAAS environment
  • Adaptable thinker, able to creatively solve old problems in new ways and new problems in old ways
  • Strong collaboration and communication skills with other teams to plan a project, align priorities, lead and model the work, document your decisions, and complete the project
  • Understands ways to catch wily threat actors
  • Possesses the fine art of crafting useful, actionable, high signal alerts
  • Proficiency in automating detection and response processes through API calls, webhook creation, etc.
  • Willingness and ability to participate in the response to critical incidents as needed.
  • Evaluating potential detection techniques and tools and using them to create useful, actionable, high signal alerts.
  • Developing automation and improving existing tooling and alerting to minimize alert fatigue and maximize effective incident response.
  • Collaborating will be key as you will work closely with IT, Engineering, Support and other teams across the company.
  • You will play a vital role in managing security incidents, from assembling the response team to organizing and leading blameless retrospectives. You'll also help develop clear response processes for various types of incidents and playbooks for various alerts generated by our tools.

AWSDockerPythonCloud ComputingCybersecurityKubernetesAPI testingREST APICommunication SkillsAnalytical SkillsCollaborationCI/CDProblem SolvingLinuxDevOpsTerraformWritten communicationComplianceExcellent communication skillsAdaptabilityTeamworkTroubleshootingActive listeningJSONRisk ManagementStrategic thinkingScripting

Posted about 1 month ago
Apply
Apply

πŸ“ Alabama, Arizona, Arkansas, California, Colorado, Connecticut, Florida, Georgia, Illinois, Indiana, Iowa, Kansas, Kentucky, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, Ohio, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, or Washington, D.C.

🧭 Full-Time

πŸ’Έ 144000.0 - 189000.0 USD per year

πŸ” Health Insurance

🏒 Company: Oscar HealthπŸ‘₯ 1001-5000πŸ’° $140,000,000 Private over 4 years agoπŸ«‚ Last layoff almost 5 years agoHealth InsuranceInsurTechInsuranceHealth Care

  • 3+ years experience in security engineering or technical related role, focused on security operations
  • Deep understanding of security concepts, including network security, endpoint security, vulnerability management, and incident response.
  • Hands on experience with security information and event management (SIEM) systems.
  • Experience with security automation and orchestration tools.
  • Proficiency in scripting languages (e.g., Python, PowerShell, Bash).
  • Design, implement, and maintain security monitoring and detection systems, including SIEM, SOAR, and XDR platforms.
  • Develop and implement security automation workflows to improve security operations and incident response processes.
  • Enhance security visibility by implementing robust logging and alerting mechanisms across the environment.
  • Identify and improve security vulnerabilities and misconfigurations.
  • Lead incident response efforts, including containment, eradication, and postincident analysis.
  • Collaborate with other teams to integrate security best practices into their workflows.
  • Research emerging security technologies and threats.
  • Mentor junior security engineers.
  • Contribute to the development and maintenance of security policies and procedures.
  • Participate in on-call rotation for security incidents.
  • Compliance with all applicable laws and regulations.
  • Other duties as assigned.

AWSPythonCloud ComputingCybersecurityGCPAzureCommunication SkillsAnalytical SkillsProblem SolvingMentoringLinuxComplianceTeamworkScripting

Posted about 1 month ago
Apply
Apply
πŸ”₯ Senior Security Engineer
Posted about 1 month ago

πŸ“ United States

🧭 Full-Time

πŸ’Έ 109305.0 - 136631.0 USD per year

πŸ” FinTech

🏒 Company: joinroot

  • At least three years of experience in application security, security engineering, or cloud security. This includes a strong understanding of cloud security principles in AWS, GCP, or Azure, with hands-on experience securing cloud-based applications and infrastructure (e.g., IAM, network security, logging/monitoring).
  • Proven ability to identify, assess, and mitigate security risks at scale in modern software development environments.
  • Ability to translate security best practices into engineering requirements, especially as they relate to application security.
  • Strong understanding of the OWASP Top Ten and SAMM framework for measuring and improving application security maturity.
  • Experience performing threat modeling, particularly in an Agile development environment.
  • Experience maintaining SAST and/or SCA tools, including the maintenance and tuning of detections.
  • Proficiency in scripting and automation using programming languages such as Python or Ruby.
  • Experience embedding security solutions into DevOps processes and pipelines and leveraging automation to enforce security policies.
  • Familiarity with common attack vectors, industry best practices, and risk mitigation strategies.
  • Experience working with compliance frameworks (e.g., SOC 2, PCI-DSS, NIST, ISO 27001).
  • Strong analytical abilities and excellent communication skills, enabling you to effectively influence both technical and non-technical stakeholders.
  • Willingness to participate in an on-call rotation to address critical security incidents and ensure timely response.
  • Proactively identify, assess, and remediate security vulnerabilities across cloud infrastructure, applications, and internal systems.
  • Drive projects that safeguard Root’s products, infrastructure, and customer data.
  • Lead threat modeling sessions, security reviews, and architectural assessments to bolster our product security.
  • Collaborate with engineering and DevOps teams to integrate security best practices throughout the software development lifecycle (SDLC) and cloud operations.
  • Implement and refine security monitoring, detection, and response capabilities across our technology ecosystem.
  • Provide technical leadership and mentorship to engineering teams on secure coding, vulnerability management, and risk assessment.
  • Work alongside compliance and risk teams to align security initiatives with regulatory requirements (e.g., SOC 2, PCI-DSS, NIST, OWASP).
  • Develop and deploy automation tools and processes that streamline security operations and reduce friction for development teams.
  • Keep current with emerging threats, vulnerabilities, and industry trends to continuously evolve Root’s security program.

AWSDockerPythonSQLCloud ComputingCybersecurityGCPKubernetesLDAPAzureCI/CDRESTful APIsLinuxDevOpsTerraformComplianceNetworkingJSONRisk ManagementAnsibleScripting

Posted about 1 month ago
Apply
Apply

πŸ“ United States

🧭 Full-Time

πŸ” Information Security

🏒 Company: JobgetherπŸ‘₯ 11-50πŸ’° $1,493,585 Seed about 2 years agoInternet

  • 5 years experience as a Senior Security Engineer
  • Extensive knowledge of healthcare data privacy regulations
  • Advanced certifications like CISSP, CISM, or HITRUST CCM
  • Strong understanding of security governance frameworks
  • Excellent communication skills
  • Lead the development and maintenance of information security policies
  • Ensure compliance with healthcare regulatory requirements
  • Manage the Information Security Committee and audits
  • Develop and implement security awareness programs
  • Coordinate vendor security assessments
  • Run incident response protocols and recovery exercises
  • Collaborate on cloud security and threat modeling

LeadershipCloud ComputingCybersecurityComplianceRisk Management

Posted about 1 month ago
Apply
Apply
πŸ”₯ Senior Security Engineer
Posted about 1 month ago

πŸ“ United States

🧭 Full-Time

πŸ’Έ 200000.0 - 220000.0 USD per year

πŸ” Software Development

🏒 Company: Human InterestπŸ‘₯ 501-1000πŸ’° $161,000,000 Private about 2 years agoWealth ManagementRetirementFinanceInsurTechEmployee BenefitsInsuranceFinTech

  • Minimum 2 years in a security focused engineering role
  • Minimum 5 years in software engineering role.
  • Proficient coding ability in at least one modern programming language. E.g.Typescript/Javascript, Ruby, Java, Python, Golang
  • Practical experience securing cloud environments.
  • Strong communication skills: you can easily discuss complex technical concepts with both engineers and non-engineers.
  • Strong ownership and bias for action: You love to roll up your sleeves.
  • Leader and Mentor: You are a recognized leader in your areas of responsibility, and enjoy sharing knowledge and mentoring others.
  • Operational Excellence: you raise the bar on the quality of the software and infrastructure that you work on.
  • Build practical controls to improve the effectiveness and robustness of our engineering team
  • Foster a DevSecOps culture through education, automation, and tooling.
  • Secure our SDLC process through automation
  • Implement checks in pipeline
  • Perform security reviews of application code
  • Take part in team on call rotation for security events and monitoring alerts
  • Advocate and educate security best practices
  • Create tooling and automation to efficiently respond to security events
  • Partner with stakeholders to respond and mitigate security threats

AWSPythonSoftware DevelopmentSQLCloud ComputingCybersecurityCommunication SkillsCI/CDRESTful APIsDevOpsJSONScriptingSoftware Engineering

Posted about 1 month ago
Apply
Apply
πŸ”₯ Senior Security Engineer
Posted about 1 month ago

πŸ“ United States

🧭 Full-Time

πŸ’Έ 150000.0 - 180000.0 USD per year

πŸ” Sports Gaming

🏒 Company: Underdog Sports

  • 5+ years of experience in cloud security, preferably with AWS services
  • Hands-on experience with Kubernetes and container environments
  • Knowledge of at least one programming language (Python, Ruby, JavaScript/TypeScript)
  • Experience with security frameworks and compliance standards
  • Manage and optimize tooling for cloud security monitoring
  • Investigate security incidents and perform root cause analysis
  • Implement security logging and monitoring
  • Conduct vulnerability management
  • Develop and maintain security automation scripts
  • Secure and optimize CDN configurations
  • Collaborate with development and operations teams

AWSPythonCloud ComputingCybersecurityKubernetesTerraform

Posted about 1 month ago
Apply