
Security Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Take ownership of the identity program, cloud security posture, and vulnerability management from start to finish.
• Reduce standing access and manual provisioning for joiner-mover-leaver changes, as well as non-human identity management.
• Strengthen and enhance the GCP-first cloud-native environment, focusing on organization policy, IAM least privilege, workload identity, network segmentation, secrets management, and posture monitoring.
• Collaborate with SRE to establish security guardrails for infrastructure-as-code.
• Manage vulnerability processes, including asset coverage, risk-based prioritization, remediation collaboration, SLAs, and actionable reporting.
• Utilize Censys to oversee the company’s external attack surface.
• Develop detection capabilities for identity, cloud, and SaaS.
• Engage in security escalation rotations and lead or co-lead high-severity incidents.
• Conduct blameless post-incident reviews, maintain runbooks, and facilitate tabletop exercises.
• Safeguard the company’s AI presence, including agent identity, MCP servers, tool permissions, secrets, data flows, prompt-injection boundaries, and AI tooling.
• Design and implement agentic security workflows for alert triage, evidence collection, access reviews, phishing response, and posture drift detection.
• Create Slack-native ChatOps requests, approvals, self-service paths, and automation for security processes.
• Work alongside SRE on cloud and infrastructure guardrails, contributing security expertise to their initiatives.
• Over 5 years of experience in security engineering, with substantial expertise in at least two of the following: identity and access management, cloud security, vulnerability management, detection, and response.
• Practical experience in identity operations, including SSO/SAML/OIDC, MFA and conditional access, device trust, and lifecycle automation.
• Proven experience securing cloud-first or cloud-native environments, preferably GCP, or a strong background in AWS/Azure with a genuine interest in GCP.
• Proficiency in scripting and automation using Python, Go, or similar languages, sufficient to create tools and API integrations.
• Experience in incident response as a primary responder or lead during high-severity incidents, including conducting post-incident analyses.
• Hands-on experience in building with LLMs or agent frameworks.
• Familiarity with a prescriptive control framework such as ISO 27XXX, CMMC, or FedRAMP.
• Ability to navigate ambiguity within a lean team and prioritize tasks independently.
• Strong written communication skills suited for an asynchronous, Slack-centric environment.
• Identity verification through CLEAR for candidates who receive an offer of employment.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.