
Senior Security Engineer
Posted Aug 18

Posted Aug 18
This is a fully remote position, open to applicants in California, +5 more states.
• Conduct security evaluations for new tools, vendors, and projects, focusing on data management, AI implementation, Data Processing Agreements (DPAs), Personally Identifiable Information (PII), authentication/authorization, and third-party security assessments.
• Take ownership of access and infrastructure security, which includes IAM least-privilege assessments, S3/database access controls, environment segregation, service-to-service authentication, and network configuration audits.
• Manage vulnerability assessments across cloud environments and endpoints while overseeing IDS/IPS and EDR/MDR tools.
• Lead the end-to-end security incident response process: triage, investigate, contain, document, and create runbooks.
• Implement and uphold technical controls that support PCI DSS and SOC 2 / ISO 27001 compliance initiatives.
• Perform internal audits, assess risk metrics, and develop disaster recovery plans.
• Collaborate with DevOps/IT on patch management and establish secure infrastructure defaults.
• Present tooling and risk recommendations to engineering leadership.
• Develop the in-house AppSec scanning program and assess, pilot, and integrate SAST/SCA/IaC tools into GitLab CI and Jenkins.
• Establish severity-based remediation Service Level Agreements (SLAs) and drive implementation across services.
• Create internal security tools and automation using custom scripts, APIs, Python/boto3, dashboards, and reports.
• Develop and optimize detection pipelines utilizing tools like Datadome and ELK/Kibana.
• Conduct threat modeling and penetration testing for AI/LLM systems, coordinate external penetration tests, and facilitate remediation efforts.
• Maintain security policies and practices, promoting company-wide training and adoption.
• Over 7 years of practical security engineering experience across application security, cloud security, and network/penetration testing.
• Proven independent experience in driving tooling or architectural decisions and effectively advocating for recommendations to leadership.
• Self-motivated, pragmatic, and highly focused on prioritization.
• Experience in building production automation from the ground up, including API integrations, custom collectors, or internal tools.
• Proficient hands-on experience deploying and operating open-source security tools such as Burp Suite Community/OWASP ZAP, Nmap, Nuclei, Metasploit, Semgrep, Trivy, Wazuh/OSSEC, ELK/Kibana, Prowler/ScoutSuite, and HashiCorp Vault, or equivalent tools.
• Strong background in AWS security.
• Familiarity with PCI DSS, SOC 2, and ISO 27001 sufficient to implement controls and assist with audits.
• Capability to threat-model emerging technologies such as AI/LLM applications.
• Excellent communication skills for conveying cost/coverage trade-offs and technical risks to engineers and executives.
• Bachelor’s degree in Computer Science or a related field, or equivalent practical experience.
• U.S. work authorization is required; applicants must reside in CA, CO, NC, NJ, NV, or TX.
• Bonus: OSCP, GPEN, or similar certifications; experience with bug bounties; or experience securing LLM/AI-based systems.
• Equity in a pre-IPO company supported by leading venture capitalists.
• Comprehensive medical, dental, and vision insurance.
• Monthly stipend for home office expenses.
• Professional development opportunities.
• Flexible paid time off policy.
• 10 paid holidays.
• An additional 6 Sesame Wellness days.
• A culture that prioritizes overall wellness and work-life balance.
CrowdStrike
Triumph Enterprises, Inc.
LaunchDarkly
Staffbase
Get handpicked remote jobs straight to your inbox weekly.