Senior individual contributor leading security architecture and automated controls across AWS, on-premises, and hybrid infrastructure. The role requires deep AWS security expertise, infrastructure-as-code and CI/CD experience, scripting ability, and cross-functional technical leadership.
145k – 165k/yr
Remote7+ YOESecurity Engineering
About the role
Responsibilities
Lead Infrastructure Security Architecture
Define and evolve security architecture across AWS and colocation environments.
Establish secure reference architectures, engineering standards, and reusable control patterns.
Provide technical leadership for infrastructure, platform, and product initiatives.
Identify systemic risks and lead sustainable programs to address them.
Strengthen Cloud and Hybrid Security
Design and improve security across cloud accounts, networks, identities, workloads, and shared services.
Establish controls for identity and access management, segmentation, encryption, secrets, logging, monitoring, and workload protection.
Develop preventative guardrails through infrastructure-as-code, policy-as-code, automation, and cloud-native security services.
Improve consistency across cloud, on-premises infrastructure, and hybrid connectivity.
Partner with Engineering and Product
Engage early in the design of products, platforms, services, and integrations.
Lead threat modeling, security architecture reviews, and technical risk assessments.
Translate security risks into practical engineering recommendations.
Help teams adopt secure-by-design principles through reusable patterns, tooling, and documentation.
Build, Automate, and Apply AI
Design and implement security tooling, integrations, and automated controls.
Embed security capabilities into infrastructure provisioning, engineering workflows, and CI/CD pipelines.
Use AI-assisted tooling for scripting, detection development, alert analysis, vulnerability triage, threat modeling, and technical documentation.
Validate AI-generated outputs and apply appropriate controls for confidentiality, accuracy, access, and human oversight.
Improve Risk Reduction and Resilience
Provide technical direction for vulnerability and exposure management across AWS and on-premises infrastructure.
Identify recurring patterns across incidents, penetration tests, vulnerabilities, and control assessments.
Act as a senior technical escalation point during significant security incidents.
Ensure investigations and lessons learned produce durable architectural and engineering improvements.
Provide Senior Technical Leadership
Lead complex security initiatives spanning multiple teams and planning cycles.
Mentor security engineers and guide engineers in adjacent teams.
Raise standards for security architecture, automation, documentation, and technical decision-making.
Communicate security risks and recommendations to technical teams, product leaders, and senior stakeholders.
Requirements
Significant experience in security engineering, infrastructure security, cloud security, security architecture, or platform engineering.
Deep hands-on experience securing AWS environments.
Strong knowledge of AWS identity and access management, network architecture, account governance, encryption, logging, monitoring, secrets management, and workload protection.
Experience designing or securing on-premises, data-center, or colocation-hosted infrastructure.
Strong knowledge of enterprise networking, segmentation, firewalls, secure remote access, privileged administration, and hybrid connectivity.
Experience with infrastructure-as-code, CI/CD security, containerized environments, and cloud-native platforms.
Demonstrated experience designing and implementing automated security controls and engineering solutions.
Proficiency with Python, Go, or a comparable language.
Practical experience using AI-assisted tooling to improve security engineering and operational workflows.
Experience leading complex initiatives across engineering, infrastructure, or product teams.
Strong knowledge of security architecture, threat modeling, vulnerability management, detection, and incident response.
Ability to operate independently, navigate ambiguity, and influence technical and leadership audiences.
Nice-to-Haves
Advanced AWS certification in security, architecture, networking, or cloud engineering.
Experience in fintech, payments, SaaS, or another regulated technology environment.
Experience securing large or complex AWS multi-account estates.
Experience with Kubernetes, container security, software supply-chain security, and policy-as-code.
Experience with CNAPP, CSPM, SIEM, EDR, DLP, WAF, vulnerability-management, network-security, or secrets-management platforms.
Familiarity with PCI DSS, SOC 2, GDPR, NIST, or ISO 27001.
Senior individual contributor owning cloud security architecture and guardrails for GCP workloads at a fintech trading platform. Leads threat modeling, edge defenses with Cloudflare/Armor, policy-as-code, incident response, and compliance controls while mentoring engineers.
145k – 195k/yrHybrid8+ YOESecurity Engineering
Staff Security Analyst, Customer Assurance
OktaBellevue, WA +3
Staff Security Analyst on Okta's Customer Assurance team bridging customers and internal engineering. Own technical security questionnaires, due diligence, risk narratives, and training for sales teams while driving AI/automation to scale responses. Requires strong cloud security, identity, compliance knowledge plus exceptional communication and consulting skills.
148k – 204k/yrHybrid5+ YOESecurity Engineering
Staff Product Security Engineer
OktaBellevue, WA +4
Staff-level product security engineer leading security reviews, threat modeling, penetration testing, and LLM/AI security assessments for Okta's identity platform. Requires deep manual security expertise and strong communication skills.
141k – 248k/yrHybrid7+ YOESecurity Engineering
Member of Technical Staff II
IllumioSunnyvale, CA
Develop containerized microservices in Go for a multi-tenant cloud security platform that processes real-time cloud events and telemetry to deliver security insights and recommendations. Own full SDLC, design, operations, and mentoring while partnering with Product on requirements.
141k – 162k/yrOn-site2+ YOESecurity Engineering
Staff Security Engineer
LiveKitUnited States
Staff Security Engineer owns security across applications, infrastructure, and workflows at LiveKit. Requires 6+ years software engineering experience, hands-on security expertise in cloud/container environments, threat modeling, and incident response.