
Senior Security Engineer
Posted Jul 17

Posted Jul 17
This is a fully remote position, open to applicants in United States.
• Take ownership of the company's security strategy, roadmap, and overall security posture.
• Act as the in-house authority on security best practices and risk management.
• Collaborate across various departments to ensure security is integrated into engineering, product, IT, and legal functions.
• Lead initiatives in threat modeling, secure code reviews, and architectural assessments.
• Establish and uphold secure coding standards and processes for vulnerability management.
• Promote the use of SAST, DAST, SCA, and additional security tools.
• Develop and sustain security tools, automation, and infrastructure as code.
• Apply security controls across application, API, and infrastructure layers.
• Work closely with engineers on authentication, authorization, and data protection measures.
• Manage vulnerability scanning, patching, and incident response protocols.
• Enhance cloud security practices, including IAM, networking, secrets management, logging, and monitoring.
• Integrate security measures into CI/CD pipelines and automate security checkpoints.
• Collaborate with the Legal team to create and uphold security policies and standards.
• Lead or assist with compliance initiatives (e.g., SOC 2, ISO 27001).
• Stay informed about changing regulatory requirements.
• Over 7 years of practical software engineering experience.
• Proficient in application security, including threat modeling, code reviews, and SDLC integration.
• Experience securing cloud environments (AWS, GCP, or Azure), with a focus on IAM and networking.
• Capability to operate both strategically and tactically—setting direction while remaining actively involved.
• Excellent communication skills; able to convert security concepts into clear, actionable advice.
• Familiarity with compliance frameworks (SOC 2, ISO 27001) is a plus.
• Knowledge of security tools (SAST, DAST, SCA, SIEM, vulnerability management) is a plus.
• Experience in developing security programs within startup or high-growth settings is a plus.
• Relevant certifications (CISSP, CCSP, CSSLP, OSCP) are a plus.
• Coverage for Medical/Dental, Orthodontics, and Vision.
• 401k matching program.
• Flexible Paid Time Off policy.
• Mindfulness First Fridays.
• Monthly Technology Stipend.
• Stipend for Home Office Setup.
• Professional Development Stipend.
• Paid Parental Leave.
• Charitable Donation Matching.
• Volunteer Days.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.