
Senior Security Engineer
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in California.
• Design and implement security measures across systems, which include secure configurations, identity management, network segmentation, and logging practices.
• Develop sustainable Python services, API integrations, and automation processes that incorporate testing, error handling, monitoring, and secure credential management.
• Create AI/LLM-driven security workflows and establish data protection measures, least-privilege access, and human approval for sensitive operations.
• Utilize Terraform or similar infrastructure-as-code tools along with CI/CD pipelines to deploy consistent, reviewable security infrastructure and identify configuration drift.
• Engineer and integrate security components such as firewalls, VPNs, web application firewalls, endpoint protection, vulnerability scanners, and SIEM platforms.
• Conduct threat modeling and security design evaluations, pinpoint control gaps, and collaborate with service owners for remediation efforts.
• Draft and maintain architecture documentation, design decisions, runbooks, standard operating procedures, and materials for operational handoff.
• Engage in engineering projects from requirements gathering through to production, as well as review code and designs.
• Diagnose security services using logs, metrics, and network analysis; enhance reliability and support an on-call rotation.
• Transform incidents and operational feedback into enhancements through blameless postmortems, automated checks, and risk-reduction metrics.
• Automate reviews of firewall rules, configurations of security tools, vulnerability enrichment, and remediation workflows.
• Develop AI/LLM-assisted alert enrichment, investigation summaries, and documentation retrieval, ensuring evaluation, auditability, and human oversight.
• Create reusable infrastructure-as-code modules and deployment pipelines that include security validation, drift detection, and rollback procedures.
• Enhance security telemetry, service health monitoring, and operational runbooks.
• Over 8 years of experience in security engineering.
• Practical experience in securing and managing Azure and GCP environments, covering aspects like cloud identity, networking, logging, and workload security.
• Strong proficiency in Python, with experience in automation or integrations that have been developed, tested, deployed, and supported.
• Hands-on experience integrating AI/LLMs into tools or workflows beyond their conversational use.
• Awareness of AI/LLM limitations, evaluation requirements, and associated security risks.
• Familiarity with infrastructure as code, version control, code review processes, and CI/CD practices.
• Understanding of concepts such as least privilege, defense in depth, secure configurations, vulnerability management, encryption, and secrets management.
• Knowledge of network security principles, including TCP/IP, DNS, TLS, routing, segmentation, firewalls, VPNs, web application firewalls, and intrusion detection/prevention systems.
• Experience with Terraform or comparable tools, configuration management, Git, CI/CD, policy as code, and change management.
• Proven experience in threat modeling, secure design practices, vulnerability assessment, remediation prioritization, and system hardening.
• Proficiency in administration and troubleshooting for Linux, Mac, and Windows platforms, including patching, availability, and operational recovery.
• Ability to convey technical findings through architecture diagrams, design documents, runbooks, procedures, knowledge transfer, and guidance for both technical and non-technical audiences.
• Capability to collaborate effectively across security, IT, cloud, and development teams.
• Medical, dental, vision, health savings account or health reimbursement account.
• Healthcare spending accounts and dependent care spending accounts.
• Life and AD&D insurance.
• Disability insurance.
• 401(k) with Company match.
• Tuition reimbursement.
• Charitable donation matching.
• Paid holidays and vacation.
• Paid sick time.
• Floating holidays.
• Compassion and bereavement leaves.
• Parental leave.
• Mental health and wellbeing programs.
• Fitness programs.
• Free and discounted games.
• Voluntary benefits including supplemental life and disability, legal services, ID protection, and rental insurance.
• Relocation assistance may be available if the Company requires geographic relocation.
• Incentive compensation may be available; however, it is not guaranteed.
Integrity360
Rackspace Technology
Efficient Computer
Presidio
Get handpicked remote jobs straight to your inbox weekly.