
Security Engineer
Posted 14 hours ago

Posted 14 hours ago
This is a fully remote position, open to applicants in United States.
• Take charge of scanning activities across code, dependencies, images, cloud configurations, and external attack surfaces.
• Automate the triage of vulnerabilities, directing them to the appropriate owners and facilitating remediation when safe.
• Ensure that unresolved vulnerabilities remain within service level agreements (SLAs).
• Lead the enhancement of security gates within build and deployment pipelines.
• Prevent the deployment of vulnerable dependencies and misconfigurations.
• Establish secure baselines for the cloud environment and identify as well as remediate any drift.
• Promote least privilege access and zero trust principles across systems, credentials, and workloads.
• Conduct application security design reviews, code assessments, and threat modeling exercises.
• Collaborate with DevOps to create reusable, secure-by-default CI/CD processes, logging mechanisms, and authentication pathways.
• Act as the technical lead during investigations and develop tools to expedite future incident responses.
• Streamline repetitive security processes through automation.
• Work closely with engineering, DevOps, and the head of security.
• Assume responsibility for significant security surfaces from the first week and broaden scope over time.
• A minimum of 4 years of experience in security engineering or infrastructure engineering with substantial security responsibilities, preferably at a cloud-native organization.
• Proficiency in coding with Python, Go, or a similar programming language.
• Extensive knowledge of cloud identity and access management (IAM) and Kubernetes security.
• Proven experience in designing systems with least privilege access and short-lived credentials as a default.
• Strong understanding of CI/CD practices and experience in securing pipelines.
• Capability to engage openly with engineers during design reviews, pull requests, and documentation processes.
• Ability to prioritize tasks based on real-world risks and effectively communicate decisions to engineers and leadership.
• Bonus: Experience in securing systems that handle email or other highly sensitive customer data.
• Bonus: Background in developing and automating a comprehensive vulnerability management program from start to finish.
• Bonus: Knowledge of application security for large language models (LLMs), including prompt injection, model pipelines, and AI agent safeguards.
• Bonus: Experience in supply chain security, including artifact signing, provenance, and software bill of materials (SBOMs).
• Bonus: Experience in detection engineering or collaboration with a Security Operations Center (SOC).
• Bonus: Previous employment at a security vendor.
• Must be located in the United States.
• A flat, flexible, and fast-paced organizational culture.
• Empowerment to make decisions.
• Clearly defined key performance indicators (KPIs) for success, along with the autonomy to achieve them.
• Opportunity for remote work arrangements.
InPost Group
Grupo Boticário
IPIRANGA
Dental Speed Graph
Get handpicked remote jobs straight to your inbox weekly.