
Senior Security Engineer
Posted 10 hours ago

Posted 10 hours ago
This is a fully remote position, open to applicants in United States.
• Lead intricate infrastructure security projects that involve multiple teams, systems, and dependencies, with a focus on AWS cloud environments and CI/CD pipelines.
• Design, implement, and manage security controls across AWS and relevant cloud platforms.
• Develop secure-by-default solutions utilizing infrastructure as code, policy as code, CI/CD, and automation techniques.
• Enhance cloud governance, security posture, and operational resilience.
• Define and uphold security baselines for cloud accounts, operating systems, containers, AMIs, Kubernetes, networks, and associated infrastructure.
• Assist with cloud account onboarding, offboarding, inventory management, configuration drift management, exception handling, and control validation.
• Design and refine cloud and infrastructure network security, which includes segmentation, traffic visibility, ingress and egress control, DNS, firewalls, routing, private connectivity, monitoring, and enforcement.
• Secure CI/CD and software supply chains, encompassing build and deployment workflows, dependencies, artifacts, containers, registries, third-party actions, secrets, and runner environments.
• Support asset and identity governance for applications, infrastructure, containers, service accounts, workload identities, API keys, AI agents, and MCP tools.
• Engage in AI security initiatives related to AI models, agents, and tool integrations, which include threat modeling, prompt injection defenses, data egress protection, guardrails, human-in-the-loop controls, and monitoring.
• Employ risk-based security analysis by assessing reachability, attack paths, asset criticality, exploitability, and business impact.
• Validate findings from scanning tools and AI outputs, establish ownership and remediation expectations, and enhance finding-quality feedback loops.
• Represent the Security team in architecture discussions, change management, design reviews, and operational forums.
• Articulate risks, trade-offs, assumptions, dependencies, and business implications to both technical and non-technical audiences.
• Create standards, runbooks, architecture decision records, dashboards, documentation, and enablement materials.
• Mentor engineers and assist partner teams in adopting secure patterns without direct management oversight.
• Participate in on-call rotations and provide incident response support for cloud and infrastructure security incidents.
• Monitor emerging threats and translate relevant developments into enhancements to Guidewire’s security controls.
• Typically, at least 5 years of experience in security engineering, cloud security, infrastructure security, DevSecOps, or a comparable practical background.
• Required hands-on experience in designing and operating secure AWS environments.
• Strongly preferred experience with Google Cloud Platform (GCP); experience with other cloud platforms is a plus.
• Proficiency in cloud governance, access management integration, policy enforcement, logging and monitoring, data protection, network security, configuration management, and cloud account lifecycle controls.
• Hands-on experience with infrastructure-as-code tools such as Terraform, CloudFormation, or similar technologies.
• Practical experience in building, securing, testing, and operating CI/CD pipelines, ideally using GitHub Actions or similar platforms.
• Familiarity with pipeline automation, secrets management, artifact handling, and runner security.
• Hands-on experience with scripting or programming in languages like Python, Go, or another suitable language.
• Solid understanding of cloud and infrastructure networking, including segmentation, routing, DNS, firewalls, ingress and egress controls, private connectivity, and network telemetry.
• Experience in securing containers and Kubernetes platforms, preferably EKS or an equivalent solution.
• Knowledge of threat modeling, secure design, vulnerability management, security testing, risk assessment, monitoring, and incident response.
• Ability to assess the effectiveness of security controls using evidence, operational feedback, exceptions, findings, and relevant metrics.
• Demonstrated experience in building, operating, or contributing to security measurement and analysis capabilities.
• Familiarity with identity and access control concepts, including authentication, authorization, privileged access management, identity governance, zero-standing privilege, workload and non-human identities, and secrets management.
• Understanding of software supply-chain security concepts, including SBOMs, artifact signing, provenance, dependency management, secure registries, and CI/CD runner hardening.
• Basic knowledge of foundational AI security concepts, including LLM risks and prompt safety.
• Capability to own complex tasks, navigate ambiguity, make trade-offs, identify risks, and achieve outcomes across multiple teams.
• Strong written and verbal communication skills.
• Preferred: hands-on experience or in-depth knowledge of AI security risks and controls, including LLMs, AI agents, MCP, AI gateways, prompt injection defense, sensitive-data leakage, and advanced AI models/tools.
• Preferred: familiarity with NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, ISO/IEC 42001, or similar frameworks.
• Preferred: certifications such as AWS Security Specialty, CISSP, GIAC, or equivalent practical expertise.
• Health insurance
• Dental insurance
• Vision insurance
• Paid time off
• Company sponsored retirement plan
• Some roles may qualify for the annual company bonus plan
• Some roles may be eligible for commissions
• Some roles may qualify for long-term incentive awards
• Disability accommodations provided throughout the hiring process
• Appeals process available for denied accommodations or non-selection decisions
Redox
Darktrace
Alteryx
Banner Health
Get handpicked remote jobs straight to your inbox weekly.