Senior Engineer, Security

Posted 1 day ago

This is a fully remote position, open to applicants in New York.

📋 Description

• Address security issues across infrastructure by implementing Terraform and application modifications.

• Ensure the completion of remediation efforts, even when fixes are the responsibility of other teams.

• Manage vulnerability assessments from Snyk, Prowler, and ASV findings through validated solutions.

• Maintain AWS security posture, focusing on IAM, least privilege access, network boundaries, secrets management, and logging practices.

• Establish and uphold technical security baselines as code, which includes host hardening, WAF configuration, and deployment strategies.

• Carry out routine penetration testing on the company’s environment.

• Execute threat modeling and security assessments for new services and integrations with payment and custody providers.

• Act as the technical lead during security incidents, including conducting forensic investigations.

• Manage and enhance Datadog detection coverage while fine-tuning alerts for significant signals.

• Report to Platform Engineering and collaborate closely with the CISO, who sets the security direction and serves as the escalation point.


⛳️ Requirements

• A minimum of five years of hands-on experience in security engineering, particularly with production systems.

• Proficient in writing and deploying code using Terraform and Python.

• Sufficient application fluency to directly address vulnerabilities.

• Extensive experience with AWS security, including IAM and least privilege at an organizational level.

• Familiarity with container workloads in ECS or EKS.

• Experience in application security, including threat modeling and practical offensive testing against cloud and application targets.

• Background in security incident response, including forensic investigation.

• Proven experience in managing vulnerability assessments and driving remediation efforts through teams not under direct supervision.

• Experience in regulated environments, translating ISO 27001, PCI DSS, or SOC 2 requirements into engineering tasks.

• Skills in detection engineering using Datadog or a similar SIEM tool.

• Experience in securing CI/CD pipelines, especially with GitHub Actions.

• Practical knowledge in cryptography and secrets management, including key rotation and certificate lifecycle management.

• Familiarity with AI coding tools for large-scale remediation and reviewing AI-generated code from a security standpoint.

• Experience with payments, cards, or digital assets.


🏝️ Benefits

• An equal opportunity employer dedicated to fostering an inclusive and diverse workforce.

• Reasonable accommodations provided throughout the recruitment process.

• Participation in a voluntary diversity survey; participation does not influence the job application.

People also viewed

Campbell's20 hours ago

Workday Platform Owner – Integration, Reporting, Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$127.9k – $175.9k/year
ApplyView job
VALCE Talent Solutions20 hours ago

SAP Basis, Security Experience

MX flagMexico OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
The Hello Team21 hours ago

Senior Cybersecurity & Compliance Consultant, HIPAA, NIST, SOC 2

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Anduril Industries22 hours ago

Senior Security Engineer

US flagCalifornia, +1 more stateFull-timeCybersecurity / Security Engineer$1/year
ApplyView job
Anduril Industries22 hours ago

Senior Security Engineer – OT

US flagCalifornia, +1 more stateFull-timeCybersecurity / Security Engineer$1/year
ApplyView job
Optiv23 hours ago

Senior Cybersecurity Advisor – AI

US flagKansas OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers