Skip to content
FigmaFigma

Security Scientist

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

About the job

Responsibilities

  • Collaborate cross-functionally to understand security and anti-abuse problems and develop solutions with engineering, product, data science, and other teams.
  • Analyze attacker and user behavior by creating datasets, metrics, and experiments to guide strategy and decision-making.
  • Build detections, tune signal quality, and measure coverage across products, platforms, and internal systems.
  • Lead and support security investigations, developing datasets, tooling, and analysis to scope incidents, identify root causes, and reduce detection and response time.
  • Translate threat intelligence into prioritized detection coverage, hardened high-risk surfaces, and security strategy.
  • Conduct investigations and security design reviews to identify current and emerging attack vectors.
  • Promote secure practices across the organization.

Requirements

  • Strong understanding of real-world security, anti-abuse, detection, and response challenges.
  • Fluency in SQL and proficiency in Python, R, or a similar scripting language.
  • Experience with distributed data processing systems and frameworks.
  • Strong knowledge of statistical methods and experimental design.
  • Excellent judgment and creative problem-solving skills.

Nice-to-haves

  • Self-starting mindset with strong communication and collaboration skills.

Compensation

  • Annual base salary: $140,000–$348,000 USD.
  • Equity and benefits may include health, dental, and vision coverage; retirement contributions; parental and family planning support; mental health and wellness benefits; paid time off; and other lifestyle benefits.

Skills

SQL, Python, R, Hive, Amazon Redshift, Presto, Snowflake, Spark, Statistical Methods, Experimental Design, Threat Intelligence, Security Investigations, Anti-Abuse, Detection Engineering

Coinbase

Coinbase

United States

Analyst, Privacy
$135k+/yrRemote3+ YOESecurity Engineering

Own Coinbase’s privacy incident management program, leading investigations, response coordination, remediation, retrospectives, and process improvements. The role requires 3+ years in privacy, security, incident response, or technology risk, plus SQL, Python, automation, and privacy regulatory knowledge.

Writer

Writer

New York, NY
Security Engineer, Application Security
$132k+/yrHybrid4+ YOESecurity Engineering

Build and scale application security for an enterprise AI platform, including threat modeling, secure architecture, automated controls, code review, and penetration testing. Requires at least four years of application security experience, programming expertise, and knowledge of DevSecOps and security-testing practices.

Mercor

Mercor

San Francisco, CA
Security Engineer, Application Security
$130k+/yrOn-site5+ YOESecurity Engineering

Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.

Modal

Modal

New York, NY

Detection And Response Engineer
$150k+/yrOn-siteSecurity Engineering

Build automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.

Figma

Figma

United States

Federal Compliance Manager
$153k+/yrRemote5+ YOESecurity Engineering

Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.