
Senior Security Engineer
Posted 13 hours ago

Posted 13 hours ago
This is a fully remote position, open to applicants in Utah.
• Take full ownership of vulnerability management from start to finish, which includes penetration testing, CSPM/CWPP tools, MTTR, and risk reporting.
• Manage application security tasks, comprising SAST, DAST, SCA, secret scanning, threat modeling, secure code reviews, and training for developers.
• Ensure the security of AI/LLM systems throughout model integrations, RAG pipelines, and LLM provider APIs.
• Assess AI features for vulnerabilities such as prompt injection, data exfiltration, model misuse, and output guardrails prior to launch.
• Spearhead cloud and infrastructure security initiatives in Azure/AKS and GCP while adhering to FedRAMP and GCC High standards.
• Implement IAM, network segmentation, encryption, Kubernetes runtime protection, IaC scanning, WAF, and zero-trust architectural designs in collaboration with DevOps.
• Develop security automation that includes CI/CD security gates, detection-as-code, SOAR, custom tools, and automated compliance evidence gathering.
• Lead or assist in detection and incident response efforts across endpoint, cloud, and application layers.
• Maintain the incident response strategy.
• Align technical controls with NIST 800-53 and manage SSPs, POA&Ms, and continuous monitoring activities.
• Provide technical insights for customer security evaluations.
• Report directly to the CISO and work in partnership with Platform Engineering, Product, and DevOps teams.
• A minimum of 5 years of practical experience in security engineering.
• Expertise in at least three areas: vulnerability management, application security, cloud security, security automation, and detection engineering.
• Strong experience in cloud-native security, particularly in Azure and/or GCP.
• Familiarity with Kubernetes, container hardening, and infrastructure-as-code security practices.
• Experience with vulnerability scanners, SAST/DAST/SCA, CSPM/CWPP, EDR, SIEM, and secret scanning tools.
• Proficiency in programming languages such as Python, Go, TypeScript, or Bash, adequate for developing automation and custom tools.
• US citizenship is required for FedRAMP and defense-related customers.
• Preferred experience in securing AI/ML systems and LLM applications.
• Background in SaaS security at a B2B or GovTech organization is preferred.
• Working knowledge of FedRAMP, CMMC, NIST 800-53, NIST 800-171, and SOC 2 standards is preferred.
• Experience supporting FedRAMP or CMMC assessments is preferred.
• Familiarity with GCC High, Azure Government, or AWS GovCloud is preferred.
• Knowledge of DFARS 252.204-7012, CUI handling, and ITAR/EAR regulations is preferred.
• Certifications such as OSCP, GIAC, cloud security certifications, or CISSP are preferred.
• Prior experience as a founding member or early security hire at a startup is preferred.
• A background check will be conducted, potentially including credit history, criminal records, and employment verification.
• Eligibility to obtain or currently possess a security clearance is required for government contracts.
• Competitive salary with a performance-based incentive plan.
• Stock options.
• Comprehensive health insurance plan.
• Flexible work arrangements, including options for full remote work.
• Extensive opportunities for professional development.
• Fast track for career progression.
Pair Team
Veta Virtual
Chinook Systems Inc.
Rithum
Get handpicked remote jobs straight to your inbox weekly.