Corporate Security Engineer, IAC & Automation
Corporate Security Automation Engineer leading design, implementation, and optimization of security infrastructure using IaC (Terraform), automation, endpoint protection, DLP, and ZTNA in a fast-scaling fintech. Requires 5+ years IT experience with 3+ in enterprise cloud security, scripting, and security frameworks.
About the job
Responsibilities
- Lead the design, implementation, automation, and optimization of corporate security infrastructure.
- Enhance security controls, align goals with business objectives, and drive automation and self-service capabilities.
- Work with IaC tools like Terraform to ensure enterprise configurations are steady, change-managed, and machine-readable.
- Design and deploy endpoint security measures aligned with industry standards, including vulnerability management.
- Ensure a strong security posture for corporate SaaS applications by configuring vendor capabilities or building automations.
- Mature and manage data protection controls, including Data Loss Prevention (DLP) tools and secure data handling processes.
- Build secure methods for sharing data with internal teams and external partners.
- Collaborate with IT, Infrastructure, and Security teams to implement security measures, maintain critical corporate systems, and drive process improvement through automation.
- Develop and run incident response and disaster recovery plans, including tabletop exercises.
Requirements
- 5+ years of IT experience, including 3+ years in enterprise security within cloud environments.
- Expertise in IaC tools like Terraform (preferred), Puppet, Chef or Ansible.
- Proven ability to lead projects and drive measurable security improvements through automation.
- Experience leveraging scripting (Python, Go, and/or TypeScript).
- Solid understanding of networking, authentication standards, and security frameworks (MITRE ATT&CK, NIST CSF, CIS benchmarks).
- Hands-on experience in ZTNA and DLP solutions (e.g., Netskope, Zscaler).
- Skilled at simplifying technical concepts for non-technical audiences and influencing decisions.
Nice-to-Haves
- Experience with workflow automation tools like n8n.
- Familiarity with modern software engineering practices.
Skills
Terraform, Puppet, Chef, Ansible, Python, Go, TypeScript, Netskope, Zscaler, Ztna, Dlp, Mitre Att&Ck, Nist Csf, Cis Benchmarks, Kubernetes
Similar jobs
Security Engineering jobsSecurity Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Own Coinbase’s privacy incident management program, leading investigations, response coordination, remediation, retrospectives, and process improvements. The role requires 3+ years in privacy, security, incident response, or technology risk, plus SQL, Python, automation, and privacy regulatory knowledge.
Build and scale application security for an enterprise AI platform, including threat modeling, secure architecture, automated controls, code review, and penetration testing. Requires at least four years of application security experience, programming expertise, and knowledge of DevSecOps and security-testing practices.
Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.
Build automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.