Senior Security Engineer
Senior Security Engineer owning risk identification, threat modeling, vulnerability management, and secure architecture projects. Partners with engineering to build security culture and tools while minimizing operational friction. Requires independent ownership, software development experience, and strong collaboration skills.
About the job
Responsibilities
- Participate in team exercises to identify potential security risks, including threat modeling and tabletop scenarios.
- Contribute to complex prioritization discussions around which risks are the most important to solve next.
- Plan projects to address the risks we prioritize, and coordinate with cross-functional stakeholders across the company to execute those projects.
- Build maintainable programs to implement operational excellence where ongoing work is needed to achieve our goals (e.g. vulnerability management).
- Partner with engineering teams to architect secure software, address security concerns, and build a strong security culture.
- Build, customize, and run tools to increase the maturity of our security program without adding undue friction to the company’s operations.
- Support ongoing bug bounty and penetration testing programs.
- Establish and maintain a network of security champions.
- Understand security knowledge gaps of the development organization and help to deliver training to address gaps.
- Provide input into architectural discussions to enable teams to innovate in a secure and repeatable manner.
Requirements
- A track record of independent ownership of areas of responsibility.
- Experience with threat modeling, red teaming, penetration testing, or other means of identifying security issues.
- Experience with software development and the ability to read code to identify security issues.
- Strong collaboration and communication skills, with deep developer empathy.
- Highly organized project management skills.
- Open to using AI to amplify their skills and strengthen their work - demonstrating curiosity, a willingness to learn, and sound judgment in applying AI responsibly to improve efficiency and impact.
Benefits
- Industry-competitive salary and equity.
- Comprehensive medical, dental, and vision coverage, with 100% of employee-only benefit premiums covered for most medical plans.
- 16 weeks paid Parental Leave for all new parents.
- Health & wellness stipend.
- Remote workspace, internet, and cellphone stipend.
- Commuter benefits for team members who report to the SF and NYC office.
- Family planning benefits.
- Matching 401(k) contribution with immediate vesting.
- Flexible PTO policy, plus 80 hours of Sick Time.
- 11 company-paid holidays.
- Virtual team building activities, lunch and learns, and other company-wide events!
Skills
Threat Modeling, Penetration Testing, Red Teaming, Vulnerability Management, Secure Software Architecture, Security Tools Development, Bug Bounty Programs, Ai For Security
Similar jobs
Security Engineering jobsLeads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Leads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.
Owns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.
Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.