
Senior Security Engineer
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in India.
• Develop and execute multi-cloud security measures throughout Coupa's cloud infrastructure, such as VPC segmentation, security groups/NACLs, IAM policy development, permission boundaries, and Organizations/SCPs guardrails.
• Create policy as code and IaC security guidelines, integrating them into CI/CD processes as pre-merge and pre-deploy checkpoints.
• Strengthen containerized workloads and Kubernetes clusters through image scanning, admission control, pod security standards, network policies, and runtime detection strategies.
• Take charge of vulnerability assessments for application packages, container images, and third-party dependencies.
• Develop and enforce secure coding practices, cloud configurations, and IAM policy corrections.
• Assist with incident response and forensic activities through log analysis, root-cause investigations, and validation of remediation efforts.
• Collaborate with Risk & Compliance to provide technical evidence and validate controls for SOC 2, ISO 27001, PCI-DSS, and FedRAMP compliance.
• Guide and support fellow security engineers by reviewing architectural designs and remediation strategies.
• Engage in the on-call/incident rotation and enhance remediation and response procedures.
• Over 7 years of experience in security engineering or penetration testing.
• Hands-on experience with AWS, GCP, or Azure cloud security principles, including IAM and networking.
• Proficient scripting and automation ability in Python, Bash, or JavaScript.
• Familiarity with dependency and container vulnerability scanning tools and CI/CD integration.
• Understanding of SOC 2, ISO 27001, PCI-DSS, and FedRAMP standards.
• Strong critical thinking and root-cause analysis proficiency.
• Excellent written and verbal communication skills.
• Bachelor's degree in Computer Science, Information Systems, or a related discipline, or equivalent practical experience.
• Relevant certifications are advantageous: CISSP, CCSP, CISA, or AWS/GCP security certifications.
• Two designated company-wide paid wellness days off annually.
• Paid day off on your birthday or another day of your choice within your birthday month.
• 40 hours of paid Volunteer Time Off each year.
• Complimentary, confidential, 24/7/365 Employee Assistance Program counseling and resources.
• Business Travel Protection through Zurich Travel Assist, offering medical, safety, pre-trip planning, and emergency support.
• Financial referral bonuses for successful candidate referrals.
• Location-specific benefits packages that include comprehensive medical/dental insurance, retirement/pension plans, and life or accident coverage.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.