
Senior Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in California.
• Design and enforce multi-cloud security measures throughout Coupa's cloud infrastructure, encompassing VPC segmentation, security groups/NACLs, IAM policy design, permission boundaries, and Organizations/SCPs.
• Develop policy-as-code and Infrastructure as Code (IaC) security guardrails and embed them into CI/CD as pre-merge and pre-deployment checkpoints.
• Strengthen containerized workloads and Kubernetes clusters by implementing image scanning, admission control, pod security standards, network policies, and runtime detection.
• Oversee vulnerability assessments of application packages, container images, and third-party dependencies.
• Create and implement secure code modifications, cloud configuration adjustments, and IAM policy remediations.
• Assist in incident response and forensic analysis through log scrutiny, root-cause investigation, and validation of remediation efforts.
• Collaborate with Risk & Compliance on technical evidence and control validation for SOC 2, ISO 27001, PCI-DSS, and FedRAMP.
• Mentor and support fellow security engineers by reviewing designs and remediation strategies.
• Engage in the on-call/incident rotation and refine remediation and response documentation.
• Over 5 years of experience in security engineering or cloud operations.
• Proven ability to independently manage intricate assessments from scoping through to remediation.
• Hands-on experience with AWS, GCP, or Azure security, including IAM, networking, and addressing cloud misconfigurations.
• Proficient scripting and automation abilities in Python, Bash, or JavaScript.
• Familiarity with tools for scanning dependencies and container vulnerabilities, along with CI/CD integration.
• Understanding of SOC 2, ISO 27001, PCI-DSS, and FedRAMP standards.
• Strong critical thinking and root-cause analysis capabilities.
• Excellent written and verbal communication skills for providing technical remediation guidance and risk context.
• Bachelor's degree in Computer Science, Information Systems, or a related discipline, or equivalent practical experience.
• CISSP, CCSP, CISA, or AWS/GCP security certifications are advantageous.
• Two company-wide paid wellness days off each year.
• Paid day off on your birthday or another day within your birthday month.
• 40 hours of paid volunteer time off annually.
• Free, confidential, 24/7/365 Employee Assistance Program.
• Business travel protection through Zurich Travel Assist.
• Monetary referral bonuses for successful referrals.
• Location-specific comprehensive medical/dental insurance.
• Location-specific retirement/pension plans.
• Location-specific life or accident protection.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.