
Security Engineer
Posted Sep 17

Posted Sep 17
This is a fully remote position, open to applicants in United States, +2 more countries.
• Design and implement security measures across cloud, infrastructure, and internal platforms.
• Collaborate with engineering teams to enhance cloud architecture, Identity and Access Management (IAM), and infrastructure security.
• Responsible for conducting product security evaluations for new features, services, and significant architectural modifications.
• Lead threat modeling and secure design choices early in the Software Development Life Cycle (SDLC).
• Operate and enhance Application Security (AppSec) workflows including Static Application Security Testing (SAST), Software Composition Analysis (SCA), secrets scanning, and Infrastructure as Code (IaC) scanning.
• Assess vulnerabilities across applications, containers, and cloud findings, and drive remediation efforts based on risk-based Service Level Agreements (SLAs).
• Define and manage the vulnerability management lifecycle encompassing intake, prioritization, exception handling, validation, and reporting.
• Enhance Cloud-Native Application Protection Platform (CNAPP) coverage and the quality of findings across cloud accounts and workloads.
• Strengthen the security posture of Kubernetes and containerized applications.
• Monitor, investigate, and respond to security incidents and events.
• Develop automation to enhance security operations, access workflows, and incident response capabilities.
• Provide timezone support to assist broader teams within the fully remote organization.
• A minimum of 5 years of experience in security engineering, product security, cloud/platform security, or closely related fields.
• Strong practical experience in securing cloud environments such as AWS, Azure, and GCP.
• Comfortable handling technical security challenges from start to finish in fast-paced settings.
• Hands-on experience with product/application security within engineering contexts, including secure design reviews, threat modeling, and code-level risk discussions.
• Experience managing AppSec tools and processes at scale, including SAST, SCA, secrets, and IaC scanning.
• Solid experience in vulnerability triage and remediation management, emphasizing risk-based prioritization and SLAs.
• Familiarity with CNAPP or similar cloud security platforms, including adjusting findings for engineering actionability.
• Working knowledge of Kubernetes and container security within production environments.
• Ability to partner with developers and platform teams to ensure secure defaults are implemented without impeding delivery.
• Proficient in writing scripts and automations to enhance security reliability and scalability.
• Experience in incident response, investigation, and post-incident fortification within cloud-native environments.
• Security-focused, detail-oriented, and an effective communicator within remote-first teams.
• Multi-cloud experience beyond AWS (e.g., Azure, GCP, OCI) is a plus.
• Background in offensive security or penetration testing is advantageous.
• Experience scaling security in a startup environment from early stages to audit-ready maturity is advantageous.
• Relevant security certifications are a plus (e.g., OSCP, OSCE, AWS Security Specialty, Kubernetes security certifications).
• Meaningful stock options.
• Comprehensive benefits package.
• 401k plan.
• Opportunity to learn from and collaborate with leading experts in security and AI.
• Regular opportunities for in-person meetings.
• Support for travel to collaborate with colleagues in person.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.