Skip to content
AgoraAgora

Senior Security Engineer

The Senior Security Engineer partners with engineering teams on application, cloud, infrastructure, detection, vulnerability, and incident security. The role requires at least five years of security engineering experience, strong software review skills, and hands-on expertise across AWS, Kubernetes, CI/CD, monitoring, and incident response.

About the job

Responsibilities

  • Partner with Engineering and Product throughout the development lifecycle, from threat modeling and design through launch and operation.
  • Review system designs, application code, APIs, infrastructure as code, cloud environments, Kubernetes workloads, deployment pipelines, and production configurations.
  • Identify vulnerabilities and design weaknesses; communicate impact and drive pragmatic remediation.
  • Provide security expertise across application, cloud, container, identity and access management, secrets, API, data protection, and secure software development.
  • Develop reusable security guidance, secure patterns, checklists, and engineering standards.
  • Administer and improve SAST, DAST, software composition analysis, container and infrastructure-as-code scanning, CSPM, AI-assisted security tools, and security monitoring.
  • Integrate security controls into developer workflows and CI/CD pipelines; tune rules, reduce noise, and improve coverage.
  • Define telemetry and detection requirements, implement and tune alert rules, and investigate security events.
  • Work with the SOC on alert quality, escalation criteria, investigation procedures, and response runbooks.
  • Participate in incident response, including investigation, containment, eradication, recovery, coordination, and evidence preservation.
  • Lead post-incident reviews and implement durable improvements.
  • Own vulnerability management, including intake, validation, prioritization, assignment, remediation tracking, exceptions, verification, and reporting.
  • Support penetration tests, code reviews, architecture assessments, vendor evaluations, and other independent security engagements.
  • Build automation and metrics to improve security visibility and reduce investigation and remediation time.
  • Contribute to product security, platform security, detection engineering, vulnerability management, and incident-readiness roadmaps.

Requirements

  • 5+ years of hands-on experience in product security, application security, cloud security, or a closely related security engineering role.
  • Strong software engineering fundamentals and application code review experience; TypeScript, Node.js, JavaScript, or another modern language is especially relevant.
  • Experience reviewing web applications, backend services, REST APIs, authentication and authorization systems, and relational database designs.
  • Practical knowledge of application and API vulnerabilities, threat modeling, secure design, and modern identity patterns.
  • Experience securing AWS environments, containerized workloads, Kubernetes, infrastructure as code, and CI/CD or GitOps workflows.
  • Hands-on experience with SAST, DAST, SCA, CSPM, container scanning, secrets detection, infrastructure-as-code scanning, SIEM, or cloud-native detection platforms.
  • Experience developing or tuning security detections using application, cloud, identity, network, and infrastructure telemetry.
  • Strong investigation skills, including log and system-activity analysis, hypothesis testing, timeline development, and scope and impact assessment.
  • Experience working with a SOC, including alert escalation, investigation handoffs, runbook development, and detection-quality improvement.
  • Experience participating in security incident response and coordinating with engineering and operations teams under time pressure.
  • Experience operating a vulnerability management process and driving remediation across multiple engineering teams.
  • Ability to evaluate findings and detections based on risk and business impact.

Nice to Have

  • Experience with TypeScript and Node.js security reviews.
  • Experience with Pulumi, Argo CD, GitOps, Cloudflare, blockchain infrastructure, or AI-assisted security tooling.
  • Experience supporting third-party penetration tests and independent security assessments.
  • Familiarity with financial infrastructure or crypto-native environments.

Work Arrangement

  • Remote within the United States, with preference for candidates near Eastern Time and substantial overlap with Eastern Time business hours.

Skills

AWS, Kubernetes, TypeScript, Node.js, JavaScript, REST APIs, Docker, Pulumi, Argo Cd, GitOps, SAST, DAST, SIEM, Threat Modeling, Vulnerability Management

Idme

Idme

McLean, VA

SOC Lead
$96k+/yrOn-site8+ YOESecurity Engineering

Leads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.

ConductorOne

ConductorOne

San Francisco, CA
Senior Security Engineer
$100k+/yrRemote5+ YOESecurity Engineering

Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.

Mercor

Mercor

San Francisco, CA

Security GRC Lead
$350k+/yrOn-site7+ YOESecurity Engineering

Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.

Anthropic

Anthropic

San Francisco, CA
Lead, Security Controls Assurance - SOX
$410k+/yrHybridSecurity Engineering

Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.

Discord

Discord

United States

Senior Platform Security Engineer
$196k+/yrOn-site5+ YOESecurity Engineering

Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.