
Security Engineer II
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Arizona.
• Conduct thorough investigations and resolve intricate security incidents across shared, virtualized, and dedicated Linux environments.
• Assess the extent of compromises, contain incidents, preserve critical evidence, and create detailed incident reports.
• Develop and implement protective measures for customer sites, accounts, and infrastructure.
• Create malware and webshell signatures, along with log-based detections, while minimizing false positives.
• Evaluate the security posture of in-house applications, infrastructure, control plane, customer panel, internal tools, and third-party/open-source dependencies.
• Enhance secrets management by transitioning static credentials into Vault, adopting dynamic credentials, and removing plaintext secrets.
• Oversee identity and access lifecycle management, including directory and SSO migrations, privileged access reviews, and offboarding processes.
• Lead vulnerability management efforts and expedite patching across a diverse fleet, including the remediation of end-of-life operating systems and runtimes.
• Develop automation and tools for detection, monitoring, response, and operational safety.
• Review and manage internal AI and agent tools to ensure data protection, appropriate permission scopes, agent identity, and prevent potential abuse pathways.
• Collaborate with Systems, Development, Abuse, and Support teams to implement security measures.
• Mentor junior team members and contribute to shared knowledge and runbooks.
• Assist in the creation of security policies, standards, processes, and compliance initiatives.
• 3–6 years of experience in security engineering, incident response, application security, offensive security, or systems administration.
• Proven capability to independently resolve complex security challenges.
• Expertise in at least one of the following areas: application security, incident response and detection engineering, or offensive security and penetration testing, with working knowledge in the other two.
• Strong practical knowledge of Linux, preferably Debian/Ubuntu, including processes, namespaces, capabilities, filesystems, kernels, and failure modes.
• Experience managing long-lived production systems, including the ability to repair hosts under load while serving real users.
• Familiarity with multi-tenant or customer-facing environments where users may be untrusted.
• Proficiency in production scripting and automation using Python, Go, Bash, Perl, or similar languages.
• Experience with log analysis and investigations at scale.
• Knowledge of intrusion detection and web application firewalls, such as mod_security.
• Working understanding of cloud platform security, including AWS, GCP, Azure, or OpenStack, IAM, network controls, and workload isolation.
• Familiarity with secrets management and CI/CD security practices, including Vault or similar tools, pipeline hardening, and supply chain risk management.
• Proficient in version control and infrastructure as code, using tools such as Git and Ansible or similar.
• Current and practical knowledge of AI tools utilized in real engineering scenarios.
• Excellent written and verbal communication skills, including the ability to simplify technical risks for non-technical stakeholders.
• Strong ethical standards, healthy skepticism, and the ability to remain effective under pressure.
• Comprehensive health, vision, and dental coverage for the entire family at no cost to the team member.
• 3% Safe Harbor contribution to 401(k) plan, with an additional employer match of up to 1%.
• Opportunities for profit sharing and bonuses.
• Generous paid time off starting at 15 vacation days.
• 11 paid holidays.
• Paid sick leave with 80 hours accrued.
• Tuition reimbursement at a 50/50 rate up to a specified amount.
• Pet insurance options available.
• Thrive Pass wellness allowance of $30 per month.
• Access to Udemy online learning courses.
• Disability insurance coverage.
• Generous maternity and paternity leave policies.
• Discounted personal travel through the corporate booking program, Egencia.
• Relaxed work environment.
• Engaging monthly company events.
• Complimentary web hosting services.
• Company-issued laptop for work purposes.
• Opportunities for professional growth.
• Extensive training provided.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.