Senior Security Software Engineer, Security Operations
Provides technical leadership for Security Operations by building cloud security platforms, automated controls, vulnerability-management workflows, and developer-facing security capabilities. Requires senior-level production systems experience, AWS security architecture, Terraform, and strong cross-functional technical ownership.
About the job
Responsibilities
- Own the architecture and technical direction of critical Security Operations systems, automation, and developer-facing security capabilities.
- Design and build reliable production services, infrastructure-as-code, and policy-as-code governing cloud resources and software delivery workflows.
- Develop scalable guardrails and paved paths for identity and access, infrastructure changes, cloud configuration, service hardening, and CI/CD security.
- Improve vulnerability identification, prioritization, and remediation by integrating signals, automating triage, and creating accountability.
- Lead complex, cross-functional initiatives from problem definition and technical design through implementation, adoption, and operational maturity.
- Establish engineering standards and provide technical guidance through design reviews and mentorship.
- Apply AI to accelerate engineering and security analysis while defining appropriate validation, data-handling, and accountability practices.
Requirements
- Experience designing, building, and operating complex production systems in security engineering, cloud infrastructure, platform engineering, or a related area.
- Strong experience with AWS security architecture, Terraform, and infrastructure-as-code, ideally in large-scale or multi-account environments.
- Experience in cloud governance, CI/CD security, vulnerability management, security automation, compliance platforms, or developer security tooling.
- Demonstrated ownership of complex or ambiguous technical initiatives, including architecture definition, tradeoff evaluation, and delivery beyond a single team.
- Strong software engineering judgment across system design, APIs, reliability, observability, testing, and safe operation of security-critical systems.
- Ability to influence technical decisions, communicate complex risks clearly, and improve engineering effectiveness.
- Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent experience.
Compensation
- Base salary: $155,584–$320,320 USD annually.
- Eligible for equity.
Skills
AWS, Aws Security Architecture, Terraform, Infrastructure As Code, Policy As Code, Ci/Cd Security, Vulnerability Management, Security Automation, Cloud Governance, Identity And Access Management, APIs, Observability, AI
Similar jobs
Security Engineering jobsBuild and own Juicebox’s governance, risk, compliance, and customer trust function, leading audits, enterprise security reviews, policies, and AI governance initiatives. Requires 3+ years in GRC or security compliance and experience with SOC 2, ISO 27001, and customer security questionnaires.
Own Alex’s information security, compliance, AI governance, and enterprise trust program as its first dedicated Security & Trust hire. The role combines security reviews and customer-facing assurance with audits, regulatory readiness, risk management, and technical control development.
Leads a high-leverage fraud intelligence team while personally investigating complex attacks across identities, devices, accounts, and payments. The role combines people leadership, incident response, threat intelligence, and partnerships with product and ML teams to improve fraud detection and prevention.
Leads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.
Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.