Skip to content
OktaOkta

Staff Security Engineer

Staff Security Engineer embedded in TDI to build centralized security posture analytics, automate issue tracking and remediation, and drive AI-powered risk management across AWS, SaaS apps, and enterprise systems.

About the job

Security Posture Management

  • Up-level Security Posture Management program to handle issues identified by security tooling across the ecosystem.
  • Leverage dashboards and visualization tools to showcase vulnerability and issue management progress and status.
  • Manage Security Posture Management program, including integrating data ingestion pipelines, coding logic to prioritize vulnerability fixes, supporting teams remediating issues from tools (ISPM, DSPM, Qualys, etc.), and developing automated systems at scale.
  • Configure and operationalize tools such as Snyk, Semgrep, and Qualys to expand scanning coverage for all TDI assets.
  • Collaborate with teams to troubleshoot and remediate findings; provide technical mentorship to developers and admins.
  • Develop and maintain metrics, reporting, and executive visibility based on findings from ISPM/SSPM, Snyk, Semgrep, Qualys, Cyera, and other security platforms to drive ownership, accountability, prioritization, and measurable risk reduction.
  • Partner with Security and GRC to communicate risk posture and remediation status.

Secure Development & DevSecOps Enablement

  • Partner with product and engineering teams to advise on secure coding, build pipelines, and deployment best practices.
  • Support and enforce ProdSec SDL adoption across business units, standardizing design reviews and requirements gathering.
  • Implement secrets rotation automation and best practices for secrets management across TDI systems.
  • Lead “shift left” security efforts to build security into the SDLC.

Baseline Image & Environment Security

  • Collaborate with SRE to manage update pipelines and enforce compliance with baseline standards.
  • Conduct light Security Architecture Reviews (SARs) for lower environments to confirm proper controls and data handling.

Automation, AI Development & Continuous Improvement

  • Develop agentic automation to scale security posture scanning, reporting, issue remediation, and patch validation.
  • Architect E2E automation flows and system design for an AI agent and its subagents (e.g., remediation agent, security posture management triage agent).
  • Identify and close gaps across CSPM, CI/CD pipeline security, and endpoint hardening.
  • Provide technical guidance for integrating security into business and productivity platforms (Salesforce, ERP, Google Workspace, Slack, Zoom).

Requirements

  • 10+ years of experience in Security Engineering, DevSecOps, Infrastructure Security, or SaaS apps within a SaaS or enterprise environment.
  • Hands-on technical expertise in scanning, patching, and remediation of issues across cloud and SaaS ecosystems.
  • Experience deploying and managing Snyk, Semgrep, and Qualys tools.
  • Strong knowledge of AWS security practices, SRE principles, and securing business technology stacks (Salesforce, ERP, Google, Slack, Zoom).
  • Proven ability to coach, mentor, and collaborate with development teams to improve remediation velocity.
  • Practical understanding of secure SDLC/PDLC, supply chain security, and secrets management.
  • Experience building security tools/applications and automated tools.
  • Proficient with visualization/BI tools to create dashboards and provide reporting to leadership and stakeholders.
  • Experience driving remediation across issues raised by posture management solutions.
  • Excellent troubleshooting and communication skills with a proactive, solution-oriented mindset.

Skills

Snyk, Semgrep, Qualys, AWS, DevSecOps, Cspm, CI/CD, Ispm, Sspm, Cyera

Shield AI

Shield AI

Washington, DC

Staff Information Systems Security Officer
$120k+/yrOn-site8+ YOESecurity Engineering

The Staff Information Systems Security Officer will secure and accredit classified information systems by implementing RMF and NIST controls, managing vulnerabilities, supporting audits and incident response, and overseeing Cross Domain Solutions. The role requires 8 years of classified-environment cybersecurity experience and expertise in DoD and IC requirements.

Twilio

Twilio

United States

Staff Security Engineer
$156k+/yrRemote7+ YOESecurity Engineering

Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.

Twilio

Twilio

United States

Staff Enterprise Security Engineer, AI Security
$156k+/yrRemote7+ YOESecurity Engineering

Leads enterprise AI security architecture and develops security systems, automation, and agentic AI identity strategies at scale. Requires 7+ years in security or infrastructure security, enterprise technical leadership, cloud and container security expertise, and strong programming skills.

Okta

Okta

Bellevue, WA
Staff Identity Governance and Access Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.

Okta

Okta

Bellevue, WA
Staff Identity Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.