Skip to content
AlertMediaAlertMediaUnited States

Security Engineer

Hands-on Security Engineer responsible for securing cloud applications and AWS infrastructure, strengthening detection and incident response, embedding controls into CI/CD, and supporting audits and enterprise customer security reviews. Requires 3+ years of security experience and practical AWS security expertise.

Salary not listed
Remote3+ YOESecurity Engineering

About the role

Responsibilities

  • Partner with Engineering to design, implement, and improve security controls across software, application architecture, and AWS infrastructure.
  • Strengthen security monitoring, detection, and incident response capabilities.
  • Integrate security controls into CI/CD pipelines and software development workflows.
  • Support compliance efforts, including SOC 2 and ISO audits.
  • Lead technical portions of enterprise customer security reviews and architecture discussions.
  • Develop deep product knowledge and advise Sales and Legal on customer security questions.
  • Communicate security risks, requirements, and recommendations to technical teams, business partners, and customers.
  • Identify opportunities to improve security and compliance controls across the product and infrastructure.

Requirements

  • 3+ years of experience in security engineering, information security, compliance, or a related role.
  • Hands-on experience securing AWS environments.
  • Experience with AWS security services, including Identity and Access Management, Virtual Private Cloud, Key Management Service, Web Application Firewall, Security Hub, GuardDuty, and Macie.
  • Knowledge of identity and access management, encryption standards, cloud infrastructure, and security tooling.
  • Experience integrating security into CI/CD pipelines and software development workflows.
  • Experience supporting SOC 2 and/or ISO audits.
  • Experience supporting application security, cloud security, or incident response programs.
  • Experience participating in customer security reviews and explaining technical concepts to different audiences.
  • Experience leading technical security or architecture discussions with enterprise customers.
  • Strong analytical, project management, organization, and prioritization skills.
  • Collaborative and adaptable approach, with the ability to work across technical and business teams.

Compensation and Benefits

  • Competitive base salary and company-wide bonus program.
  • Generous and flexible time off and parental leave policies.
  • Medical, dental, vision, and life insurance fully paid for employees.
  • 401(k) with company match.
  • Rewards and incentives.
  • Community service opportunities.
  • Career development opportunities through the Learning & Development team.

Skills

AWSaws iamamazon vpcaws kmsaws wafaws security hubamazon guarddutyamazon macieCI/CDApplication SecurityCloud SecurityIncident ResponseSOC 2ISO 27001encryption
Plaid

Security Analyst, Third-Party Ecosystem Risk Management

PlaidNew York, NY +3

Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.

119k – 176k/yrHybrid4+ YOESecurity Engineering
Vanta

Manager, Security Operations

VantaUnited States

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

178k – 209k/yrRemote5+ YOESecurity Engineering
Decagon

Governance, Risk, and Compliance Manager

DecagonSan Francisco, CA

Manages Decagon’s governance, risk, and compliance program, including enterprise certifications, audit evidence, vendor risk, customer security assessments, and RFP responses. Requires 3–5 years of GRC experience, strong communication and project management skills, and familiarity with technical security controls and privacy regulations.

190k – 275k/yrOn-site5+ YOESecurity Engineering
OpenRouter

Third-Party Risk Analyst

OpenRouterUnited States

Build and operate OpenRouter’s third-party risk program, assessing model providers, subprocessors, and SaaS vendors across security, privacy, and AI regulatory requirements. The role requires 4+ years of vendor security risk experience, technical fluency, and strong independent judgment.

Salary not listedRemote4+ YOESecurity Engineering
Cloudflare

AI Security Research & Red Team Engineer

CloudflareAustin, TX +1

Conducts AI-focused security research, agent and LLM testing, adversary simulation, and detection-efficacy validation. The role requires 4+ years of offensive or application security experience, strong penetration-testing or cloud-security fundamentals, and knowledge of AI attack vectors and MITRE ATT&CK.

166k – 208k/yrHybrid4+ YOESecurity Engineering