
Senior Security Engineer
Posted Aug 7

Posted Aug 7
This is a fully remote position, open to applicants in United States.
• Lead the design, execution, and ongoing enhancement of Wpromote's security engineering program.
• Collaborate with IT leadership to influence security decisions and report directly to the Director of IT.
• Act as a senior security authority and escalation point within the security function.
• Assess, integrate, and optimize the security tools portfolio.
• Develop identity, access, and session governance strategies for Google Workspace and other identity providers.
• Specify GCP security requirements and convert them into Cloud IAM, organizational policy, service account governance, and audit logging controls.
• Promote phishing-resistant MFA, secrets management architecture, SAML SSO, SCIM provisioning, and session policy.
• Oversee the OAuth application vetting process, token lifecycle management, and third-party application risk assessment.
• Manage incident response and forensic practices, conduct independent investigations, and coordinate with external partners during significant escalations.
• Implement detection, policy, configuration, and response automation as version-controlled, peer-reviewed, and tested code.
• Collaborate with platform engineering on Terraform and cloud guardrails.
• Mentor and develop team members while influencing security decisions across the organization.
• A minimum of 5 years of practical security engineering experience in a professional setting.
• Proven success in managing security architecture and projects from inception to completion.
• Experience in detection engineering, including the selection, building, and operation of a SIEM; crafting and fine-tuning detections; and managing log pipelines, alerting, and monitoring.
• At least 4 years of hands-on security cloud engineering experience, with a strong preference for GCP, including Cloud IAM, organizational policy, service account governance, and audit logging.
• Extensive knowledge in identity and access management, including SAML SSO federation and SCIM provisioning and deprovisioning.
• Expertise in SaaS identity security, including phishing-resistant MFA, passkeys, hardware keys, secrets management architecture, OAuth app governance, token lifecycle management, and third-party application risk.
• Practical experience with incident response and forensic methodologies, including proper evidence handling.
• Familiarity with endpoint security posture, including EDR operations such as CrowdStrike Falcon or equivalent, and device trust or conditional access design.
• Experience in operating vulnerability management or exposure management programs, including prioritization based on exploitability, asset criticality, and business risk.
• Proficiency in security automation and infrastructure-as-code, including detection-as-code and Terraform, beyond basic scripting.
• This position does not qualify for immigration sponsorship.
• Nice-to-have: background in infrastructure, cloud platforms, DevOps, SRE, or systems engineering.
• Nice-to-have: experience in scaling or enhancing a security program in a rapidly growing environment.
• Nice-to-have: industry certifications such as GCP Professional Cloud Security Engineer, GIAC, CISSP, or OSCP.
• Nice-to-have: experience with least-privilege access management across vendor systems, mentoring, SOC 2 or similar compliance frameworks, and proficiency in Python or Bash scripting.
• Unlimited PTO.
• Extended holiday break (Winter).
• 100% paid parental leave.
• 401(k) matching.
• Comprehensive medical, dental, vision, life, and pet insurance.
• Sponsored life insurance.
• Short-term disability insurance and additional voluntary insurance options.
• Annual Class Pass credits.
• Flexibility for remote work.
• Office hubs located in Los Angeles, Chicago, and New York for learning and development opportunities, events, collaborative workspace, and in-person teamwork.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.