
Senior Software Engineer, Security
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in United States.
• Conduct threat modeling and security design assessments for new features, services, and architectural modifications.
• Execute secure code evaluations focused on authentication, authorization, input handling, secrets management, and data protection.
• Implement and oversee SAST, SCA, DAST, secret scanning, IaC scanning, and CI/CD security guardrails.
• Advocate for secure-by-default libraries, frameworks, standardized patterns, and developer guidance.
• Collaborate with platform engineering on AWS hardening, Terraform evaluations, network segmentation, and environment isolation.
• Assist in security incident investigations, root cause analyses, and post-incident enhancements.
• Lead vulnerability triage, prioritization, remediation tracking, and metrics reporting.
• Address customer and vendor security questionnaires, RFP security sections, and trust-and-safety inquiries in collaboration with sales and legal teams.
• Facilitate SOC 2, ISO 27001, PCI 4.0, and other compliance audit processes.
• Monitor and react to security alerts related to endpoints, cloud, and applications.
• Conduct user access reviews, IAM hygiene tasks, and maintain RBAC systems.
• Maintain security runbooks, process documentation, and operational playbooks; implement automation wherever feasible.
• Over 5 years of experience in security engineering, security operations, or a related combined role.
• Practical experience with SOC 2, ISO 27001, or PCI compliance audit processes.
• Strong foundation in application security, including threat modeling and secure code review.
• Familiarity with OWASP Top 10 and CWE vulnerability classifications.
• Experience with SAST, SCA, DAST, secret scanning, or IaC scanning methodologies.
• Working knowledge of AWS infrastructure and services, including IAM, VPC networking, and security configurations.
• Understanding of infrastructure-as-code and CI/CD pipeline security, with a preference for Terraform.
• Proficient in Python and capable of reading backend service code.
• Excellent written communication skills for audit documentation, security questionnaires, policies, and runbooks.
• Comfortable utilizing AI-assisted development tools such as Claude Code or Copilot.
• Nice-to-have: Experience in AI/ML security, endpoint and cloud security tools, SIEM detections, vulnerability management, security incident handling, startup experience, or relevant security certifications.
• Competitive equity grants.
• 100% employer-paid benefits.
• Fully remote flexibility.
• 401k match up to 4% for all US-based full-time team members.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.