
Senior Security Engineer
Posted 7 hours ago

Posted 7 hours ago
This is a fully remote position, open to applicants in United States.
• Take charge of Cloud Security Posture Management, encompassing Kubernetes and Container security practices, admission control, network policies, image integrity, and environment hardening.
• Oversee a thorough vulnerability lifecycle, prioritizing remediation based on real production exposure.
• Work collaboratively with Platform Engineering to uphold secure SDLC and CI/CD safeguards, emphasizing artifact validity and pipeline integrity.
• Transform HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls.
• Assess and secure infrastructure-as-code across all environments.
• Carry out incident response responsibilities, which include forensic investigations and blameless post-mortem analyses.
• Contribute to the development of security standards within Engineering through design reviews, collaborative pairing, and mentoring peers.
• Assist in bug bounty triage and maintain professional relationships with external security researchers.
• Assume responsibility for cloud-native and application security across the Redox platform.
• Conduct code reviews and convert control gaps into engineering proposals that drive production impact.
• Integrate security into the SDLC through container security, Kubernetes hardening, and architecture reviews.
• A minimum of 5 years in security engineering, demonstrating a history of hands-on delivery in system hardening, security engineering projects, and peer mentorship.
• Strong technical expertise in Kubernetes security, particularly in network policy orchestration, admission control (Kyverno), and container hardening protocols.
• Experience with threat modeling for applications developed using Node.js, TypeScript, Python, or Go.
• Practical experience in supporting secure SDLC practices and CI/CD safeguards utilizing GitHub Actions, ensuring artifact validity and pipeline integrity.
• Direct experience in hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets through AWS Secrets Manager, Vault, or similar platforms.
• Extensive experience throughout the vulnerability management lifecycle, from initial triage to production remediation.
• Capability to implement compliance frameworks such as HITRUST and SOC 2 into practical technical controls that align with engineering workflows.
• Excellent written communication skills, with the ability to document decisions clearly and collaborate effectively in a remote, asynchronous organizational culture.
• Proficiency in AI tools and techniques, including prompt engineering, with hands-on experience across various large language model platforms, showcasing the ability to automate workflows using AI.
• 100% remote-first culture (must be based in the US).
• Unlimited Flexible Time Off.
• 15+ Observed Holidays.
• Rest & R^Charge days (ensuring a guaranteed 3-day weekend each month).
• R^Charge (6 weeks paid sabbatical + stipend).
• 401k match of 50% for up to 8% starting on Day 1.
• Medical/Dental/Vision Benefits commencing on Day 1.
• HSA & FSA, Life, Disability, Medical Travel & Employee Assistance Program.
• Paid Parental Leave (16 weeks).
• Productivity Stipend & Wellness Fund.
• Redox Issued MacBook.
• Virtual and/or in-person Team & Company Events.
• Stock Options.
• Employee Referral Bonus Program.
Darktrace
Alteryx
Banner Health
Xcelerate Solutions
Get handpicked remote jobs straight to your inbox weekly.