
Security Engineer
Posted Jul 1

Posted Jul 1
This is a fully remote position, open to applicants in India.
• Design, implement, and sustain security measures throughout cloud infrastructure (AWS/GCP), CI/CD pipelines, and internal systems.
• Lead efforts in application security, including threat modeling, secure code evaluations, and the integration of SAST/DAST tools into the development lifecycle.
• Take ownership of vulnerability management by triaging, prioritizing, and facilitating the remediation of issues identified in scans, penetration tests, and bug bounty reports.
• Monitor and respond to security incidents while creating and maintaining incident response documentation.
• Manage identity and access controls (SSO, RBAC, least-privilege enforcement) for both internal and customer-facing systems.
• Assist with customer security questionnaires, audits, and certifications (e.g., SOC 2, ISO 27001).
• Collaborate with engineering teams to incorporate secure-by-design principles into new features and services.
• Assess and implement security tools (secrets management, endpoint protection, cloud security posture management).
• Educate the wider team on security best practices and advocate for a security-first culture.
• A minimum of 2 years of experience in security engineering, application security, or a comparable infrastructure/security role.
• Strong comprehension of cloud security principles (AWS or GCP), network security, and IAM.
• Experience with secure SDLC methodologies — including code reviews, dependency scanning, and CI/CD pipeline security.
• Familiarity with widely recognized frameworks and standards (OWASP Top 10, SOC 2, ISO 27001, GDPR).
• Practical scripting/automation abilities (Python, Go, or similar) for developing internal security tools.
• Experience in responding to and documenting security incidents.
• Effective communicator capable of translating security risks into language understandable by non-security stakeholders.
• Experience in securing a SaaS product that handles sensitive financial data (preferred).
• Previous involvement in leading a SOC 2 Type II or ISO 27001 audit from the engineering perspective (preferred).
• Familiarity with container security (Docker/Kubernetes) and Infrastructure as Code (IaC) scanning (Terraform) (preferred).
• Relevant certifications (OSCP, CISSP, CCSP) are a positive indicator, but not mandatory.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Flexible work hours and remote work options.
• Opportunities for professional development and continuous learning.
• A collaborative and inclusive work environment.
GuidePoint Security
Redpanda Data
CyberSheath
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.