
Senior Security Engineer
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in Bulgaria, +6 more countries.
• Take charge of infrastructure vulnerability management, which encompasses a central register, risk-based SLAs, exception handling, closure tracking, and reporting.
• Prioritize remediation efforts for infrastructure by utilizing contextual risk indicators such as KEV, EPSS, exposure, asset criticality, and compensating controls.
• Automate processes related to scanner integrations, finding pipelines, normalization, ticket routing, and reporting.
• Contribute to collaborative security finding workflows.
• Establish security logging coverage and retention across production, cloud, and identity systems.
• Choose and manage a partner for detection and response services.
• Oversee cloud security posture management in collaboration with the platform team, focusing on account guardrails, hardening baselines, CSPM triage, internet-facing surface inventory, and image/container security.
• Facilitate security incident response, including runbooks, tabletop exercises, and corrective actions following incidents.
• Collaborate with Product Security on product-related vulnerabilities and customer-facing product risks.
• Work alongside product, platform engineering, and IT teams on remediation efforts.
• Provide technical documentation for SOC 2, PCI DSS, and customer due diligence requirements.
• Engage with Product & Platform teams to support discussions related to customer-facing security.
• Assist in maintaining and operationalizing the Internal AI Use Policy and its applications.
• Secure internal AI tools and agentic workflows, focusing on data access, identity, credentials, tool permissions, logging, and detection of inappropriate behavior.
• Ensure that agentic workflows are auditable.
• A minimum of 8 years’ experience in security engineering, with a focus on vulnerability management, cloud security posture, detection, or incident response.
• Proficiency with AWS and Kubernetes.
• Ability to conceptualize infrastructure as code.
• Expertise in security logging and SIEM-class tools.
• Experience working with a managed detection service provider.
• Practical experience managing infrastructure vulnerability at scale across fleets, images, containers, and dependencies.
• Background in prioritizing remediation using KEV, EPSS, exposure, asset criticality, and compensating controls.
• Experience in driving remediation actions through teams that own systems.
• Familiarity with SOC 2 and/or PCI DSS technical controls.
• Experience in securing payment systems or regulated fintech environments.
• Background in detection engineering, threat modeling, or DFIR.
• Exposure to EU regulatory requirements, including GDPR Art. 33/34 and the Cyber Resilience Act, as well as ISO27001.
• Experience at a product company scaling from mid-market to enterprise customers.
• Competitive salary.
• Generous "Time to Recharge" policy with unlimited paid time off.
• Work From Anywhere benefit: up to four weeks each calendar year to work temporarily from another approved location.
• Two-week cross-functional onboarding program.
• Annual team off-site event.
• Cycle-to-work scheme (Swapfiets subscription) or commuting reimbursement.
• Extensive paid family leave.
• Three paid volunteer days annually.
• Access to cutting-edge equipment and tools.
• Join an international, travel-loving team.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.