
Lead Security Engineer
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in India.
• Design and implement multi-cloud security measures within Coupa's cloud infrastructure, including VPC segmentation, security groups/NACLs, IAM policy creation, and Organizations/SCPs guardrails.
• Develop policy-as-code and Infrastructure as Code (IaC) security guardrails, integrating them into CI/CD pre-merge and pre-deploy processes.
• Enhance the security of containerized workloads through image scanning, admission control, pod security standards, and runtime detection.
• Create automated remediation solutions for cloud misconfigurations and drift.
• Manage the vulnerability management program and act as the technical escalation point for security incidents and vulnerability assessments.
• Oversee forensic investigations, containment, root cause analysis, and remediation utilizing cloud-native tools and EDR solutions.
• Collaborate with Risk & Compliance to translate SOC 2, ISO 27001, PCI-DSS, and FedRAMP requirements into actionable technical controls.
• Automate evidence gathering by linking cloud telemetry with GRC tools.
• Guide security engineers through design reviews, threat modeling sessions, and code/architecture evaluations.
• Maintain reference architectures, threat models, and runbooks; actively participate in and enhance the on-call rotation.
• Over 10 years of experience in security engineering, including practical experience securing large-scale production cloud environments.
• Proven experience in leading projects or mentoring engineering teams.
• Extensive hands-on expertise in AWS security, encompassing IAM, VPC/networking, KMS, GuardDuty, Security Hub, Config, and Organizations/SCPs.
• Familiarity with GCP or Azure security practices.
• Experience with Terraform or equivalent IaC and policy-as-code frameworks in production settings.
• Knowledge of container and Kubernetes security tools.
• Strong foundation in software engineering principles, particularly in Python and/or Go.
• Familiar with Git-based workflows.
• Experience in developing and maintaining CI/CD security integrations, including SAST, DAST, and SCA.
• Proficient with SIEM/SOAR platforms and vulnerability management tools like Wiz, Qualys, or Tenable.
• Understanding of SOC 2, ISO 27001, PCI-DSS, FedRAMP, and NIST 800-53 standards.
• Excellent verbal and written communication abilities.
• Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent hands-on experience.
• Willingness to travel internationally as needed.
• Two paid wellness days off for all employees each year.
• A paid day off on your birthday or another preferred day within your birthday month.
• 40 hours of paid volunteer time off each year.
• Access to a free, confidential Employee Assistance Program available 24/7/365.
• Business travel coverage through Zurich Travel Assist.
• Financial referral bonuses for successful employee hires.
• Location-specific medical and dental insurance.
• Retirement and pension plans.
• Life or accident insurance coverage.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.