
Staff Security Engineer
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in Texas.
• Take charge of strategy and hands-on engineering for Detection and Response platforms; recognize, onboard, and standardize log sources across cloud, containers, endpoints, and SaaS.
• Develop and manage SOAR tooling, including AI agents for alert triage and investigation enhancement.
• Lead incident response efforts for intricate threats, create runbooks, promote post-incident enhancements, and design/run BCP/DR tabletop exercises.
• Integrate security into the SDLC through threat modeling, secure design evaluations, SAST/DAST tooling, AI code review, and automated security checkpoints in CI/CD pipelines and AI processes.
• Manage host- and application-level vulnerability management and drive remediation efforts.
• Advocate for security-as-code practices across engineering teams.
• Construct AI-driven security tools for threat detection, anomaly identification, automated triage/remediation, and post-mortem summarization.
• Define and execute security models for LLM-based systems and internal AI tools.
• Design harness patterns to guide LLM behavior and safeguard against prompt injection, indirect RAG injection, and data exfiltration.
• Assess and govern AI tool adoption from a security and data-risk viewpoint.
• Oversee AWS security posture and enforce baselines across Linux/Windows, network devices, and enterprise SaaS.
• Collaborate with IT to safeguard corporate identity, endpoints, and enterprise SaaS, including automated access reviews, offboarding checks, and vendor onboarding.
• Engineer, configure, and manage EDR, DLP, and endpoint security initiatives.
• Offer IAM architecture expertise across identity and access systems.
• Guide junior and mid-level security engineers through design reviews, collaboration, and direct feedback.
• Establish and promote security engineering standards throughout the organization.
• Work with IT operations, platform, and software teams to translate threat intelligence into detection and fortification priorities.
• Report directly to the VP of InfoSec and IT and partner with software, platform, infrastructure, data, and compliance teams.
• Background in software engineering or strong scripting skills (Python, Go, Typescript, or shell): you produce production-quality code, maintain it in version control, and prefer shipping a tool over filing a ticket.
• Expertise in one or more areas: AI Security, Product Security, Detection & Response.
• Over 8 years in security engineering with a proven track record of progressing into technical leadership roles.
• Extensive hands-on SIEM experience (DataDog, ELK, or equivalent).
• Comprehensive and practical AWS security and IAM knowledge.
• In-depth understanding of Product security fundamentals: threat modeling, SAST/DAST, secure SDLC.
• Experience working with AI/LLM APIs and practical knowledge of LLM security risks.
• Strong hands-on experience with EDR, DLP, and vulnerability management.
• Experience with containerized workloads and Kubernetes security.
• Proven success in mentoring engineers and enhancing team capabilities.
• Experience in start-ups or scale-ups within regulated SaaS (healthcare, fintech, or similar) is a plus.
• Certifications such as CISSP, GIAC, or OSCP are a plus.
• Familiarity with MITRE ATT&CK applied to detection engineering is a plus.
• Experience in "Security as code" (OPA, Checkov, tfsec, or similar) is a plus.
• Skills in data science or anomaly detection as applied to security telemetry are a plus.
• Background in the healthcare industry (HIPAA, HITRUST) is a plus.
• Familiarity with Kubernetes/EKS, Terraform/Terragrunt, Atlantis, Cloudflare, Buildkite, Wiz, Semgrep, EscapeTech, GitHub Advanced Security, Datadog, HashiCorp Vault, N8N, Snowflake, and Linear is a plus.
• Curative Health Plan (100% employer-covered medical premiums for you and 50% coverage for dependents on the base plan).
• $0 copays and $0 deductibles (with completion of our Baseline Visit).
• Preventive and primary care included.
• Mental health support available.
• One-on-one care navigation provided.
• Chronic condition programs (diabetes, weight management, hypertension).
• Maternity and family planning support offered.
• 24/7/365 Curative Telehealth services.
• Pharmacy benefits included.
• Comprehensive dental and vision coverage.
• Employer-provided life and disability coverage with additional supplemental options available.
• Flexible spending accounts offered.
• Generous PTO policy along with 11 paid annual company holidays.
• 401K available for full-time employees.
• Generous paid parental leave of up to 8–12 weeks, depending on role eligibility.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.