
Senior Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in North America.
• Design and develop a security-focused infrastructure by default across Aptible's AWS-based PaaS.
• Take charge of and enhance the vulnerability management program, which includes triage, prioritization, and confirmed remediation.
• Manage the comprehensive penetration testing program utilizing XBOW, manual testing, and third-party assessments.
• Facilitate remediation efforts within Ruby, Go, and TypeScript codebases, as well as infrastructure.
• Lead incident response activities, encompassing detection, containment, eradication, and post-incident reviews.
• Create and maintain detection tools, alerting systems, and operational runbooks.
• Adjust and expand the AWS Security Agent.
• Engage in the on-call rotation for incidents related to security.
• Conduct compliance recertifications and uphold standards like SOC 2 or HITRUST.
• Organize evidence collection and collaborate with auditors.
• Leverage AI tools to enhance development and investigation processes.
• Work closely with the Engineering team and report directly to the VP of Security.
• Over 5 years of experience in security engineering.
• Proven history of managing security-critical systems in production environments.
• Practical security engineering experience, including coding and infrastructure operation.
• Excellent communication skills in both written form and during incidents.
• Solid engineering fundamentals and coding proficiency across a full-stack codebase.
• Expertise in at least one mainstream programming language, with a quick ability to learn new languages/frameworks.
• Practical experience in cloud infrastructure security, preferably with AWS.
• Familiarity with AWS-native security tools such as AWS Security Agent, GuardDuty, and Security Hub.
• Experience with distributed systems.
• Genuine penetration testing experience, including the use of automated/AI-assisted tools like XBOW.
• Experience in driving penetration test remediation to successful completion.
• Background in managing or significantly contributing to a vulnerability management program.
• Experience in leading or actively participating in incident response efforts.
• Understanding of identity management, network security, and detection tools.
• Capability to manage compliance recertifications as a project.
• Ability to collaborate effectively with Engineering in a small, autonomous team.
• Availability to work in the Pacific, Mountain, Central, or Eastern Time Zone.
• Must reside and work in an eligible North American time zone and possess legal authorization to work in the country of residence.
• Compensated take-home project.
• Remote work flexibility.
• Involvement in an on-call rotation.
• Final in-person onsite interview.
• Support for accommodations related to disabilities or special needs.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.