Skip to content
CohereCohere

Senior Security Engineer

The Senior Security Engineer leads application and product security operations across CI/CD and cloud-native environments, integrating security into the software lifecycle and automating controls. The role requires 5+ years of security experience, strong vulnerability and cloud security knowledge, and hands-on security tooling expertise.

About the job

Responsibilities

  • Serve as a trusted advisor to team leadership and partner teams by clearly articulating business risks associated with security issues.
  • Lead security operations functions—including vulnerability management, SAST, DAST, detection engineering, and incident response—in CI/CD and cloud-native production environments.
  • Integrate security into applications throughout the software development lifecycle.
  • Collaborate with product and development teams on larger projects to ensure software is built and deployed securely without compromising agility and speed.
  • Drive and support the bug bounty program, application security reviews, and threat modeling, including code review and dynamic testing.
  • Assess and integrate security tools to automate and scale security processes, including evaluating open-source and vendor solutions.
  • Gather and analyze security metrics to address security issues involving cross-team dependencies.
  • Build innovative solutions using a constructive, flexible, and developer-empathetic approach.

Requirements

  • 5+ years of experience in application/product security or security operations, with a strong focus on security tool onboarding and optimization.
  • Understanding of vulnerability management, network security, cloud security concepts, and security industry best practices.
  • Comfortable operating with ambiguity and making informed decisions with limited data.
  • Ability to make build-versus-buy trade-offs, build solutions, and evaluate available tools.
  • Understanding of secure engineering best practices, with the ability to articulate problem statements and propose solutions to technical and non-technical audiences.
  • Deep technical understanding of common security vulnerabilities, risks, countermeasures, and compensating controls.
  • Hands-on interest in automating security controls.

Compensation and Benefits

  • Weekly lunch stipend of $75, £75, or equivalent in local currency.
  • Full health and dental benefits, including a separate mental health budget.
  • RRSP matching, 401(k), or pension scheme.
  • 100% parental leave top-up for up to 6 months for either parent.
  • Annual enrichment benefits for arts and culture, fitness and wellness, quality time, and workspace improvements.
  • Education and learning stipend for conferences, courses, and coaching.
  • Six weeks of paid vacation (30 working days).
  • Travel budget for remote employees to visit other offices and an annual company offsite.
  • Coworking benefit for employees not near an office.
  • $500 home office stipend.

Skills

Vulnerability Management, SAST, DAST, Detection Engineering, Incident Response, CI/CD, Cloud Security, Network Security, Application Security, Threat Modeling, Bug Bounty, Code Review, Dynamic Testing, Security Automation, Cloud-Native Security

Idme

Idme

McLean, VA

SOC Lead
$96k+/yrOn-site8+ YOESecurity Engineering

Leads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.

ConductorOne

ConductorOne

San Francisco, CA
Senior Security Engineer
$100k+/yrRemote5+ YOESecurity Engineering

Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.

Mercor

Mercor

San Francisco, CA

Security GRC Lead
$350k+/yrOn-site7+ YOESecurity Engineering

Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.

Anthropic

Anthropic

San Francisco, CA
Lead, Security Controls Assurance - SOX
$410k+/yrHybridSecurity Engineering

Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.

Discord

Discord

United States

Senior Platform Security Engineer
$196k+/yrOn-site5+ YOESecurity Engineering

Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.