Skip to content
LobLob

Staff Security Engineer, Cloud and Product Security

Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.

About the job

Responsibilities

  • Own security engineering across AWS cloud infrastructure, detection and response, application and product security, incident response, penetration testing, and security automation.
  • Lead AWS security posture management, CNAPP initiatives, cloud misconfiguration risk reduction, infrastructure security reviews across Terraform and Nomad, and Cloudflare edge/WAF strategy.
  • Build and operate a high-signal detection engineering practice on the SIEM, including alert triage ownership, runbooks, severity criteria, and false-positive reduction.
  • Lead security incident response, escalation paths, tabletop exercises, and post-incident reviews; partner with IT on endpoint detection and vulnerability coverage.
  • Own vulnerability management across SCA, SAST, DAST, and container scanning.
  • Manage and mentor an application security contractor and route remediation work effectively into engineering teams.
  • Conduct threat modeling and security architecture reviews for new products and significant changes.
  • Improve secure SDLC practices and apply AI to security operations where it provides leverage.
  • Own technical execution of the annual independent penetration test, including scope, findings triage, remediation routing, and retest coordination.
  • Produce technical evidence supporting SOC 2, HIPAA, and Microsoft SSPA requirements without owning the audit or compliance program.
  • Build security tooling and automation and ship security improvements through collaboration with Platform, Logistics, IT, and engineering teams.

Requirements

  • 8+ years of security engineering experience with meaningful depth in cloud security.
  • Hands-on expertise with AWS security services, IAM design, and infrastructure as code.
  • Demonstrated detection engineering experience, including writing and tuning detections and reducing false positives.
  • Real incident response experience as a responder or lead.
  • Application security fluency sufficient to review findings, assess severity, and evaluate exploitability with engineers.
  • Track record of delivering security improvements through other teams by building trust.
  • Ability to serve as the senior technical security voice in an organization without a large security team.

Nice-to-haves

  • Experience supporting SOC 2 Type 2, HIPAA, or Microsoft SSPA from the engineering side.
  • Container and orchestration security experience, particularly with Nomad or Kubernetes.
  • Cloudflare experience, including Zero Trust and WAF.
  • Experience working with regulated or consumer-identifiable data at scale.
  • Prior experience mentoring or managing engineers or contractors.

Compensation

  • Annual base salary: $197,500–$220,000, plus RSUs.
  • Remote working opportunities are available in specified U.S. states.

Skills

AWS, IAM, Terraform, Nomad, Cloudflare, Waf, SIEM, SAST, DAST, Kubernetes, Incident Response, Threat Modeling, Container Security, Vulnerability Management, Infrastructure As Code

Illumio

Illumio

Sunnyvale, CA

Staff Engineer - Container Security
$194k+/yrOn-site8+ YOESecurity Engineering

Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.

Upside

Upside

Washington, DC
Staff Application Security Engineer
$210k+/yrRemote6+ YOESecurity Engineering

Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.

Grow Therapy

Grow Therapy

Seattle, WA
Senior/Staff Engineer, Application & Product Security
$182k+/yrRemote6+ YOESecurity Engineering

Build and lead application and product security practices across a 145-engineer organization, embedding secure defaults, CI guardrails, threat modeling, and vulnerability mitigation into product development. The role requires 6+ years of hands-on security experience, strong coding ability, and microservices expertise.

Mysten Labs

Mysten Labs

United States

Staff Security Engineer, Walrus
$180k+/yrRemote8+ YOESecurity Engineering

Leads security architecture, assessments, automation, and security-by-design practices for the Walrus team and broader ecosystem. The role requires 8+ years of security engineering experience, broad technical expertise, and Staff-level leadership.

Reddit

Reddit

United States

Staff Software Engineer - Site Defense
$217k+/yrRemote7+ YOESecurity Engineering

Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.