Skip to content
DISQODISQO

Senior Security Engineer

Senior Security Engineer owns AWS cloud and endpoint security posture, leads SecOps including detection, incident response, and vulnerability management, while building AI-enabled automations in a high-throughput environment.

About the job

Responsibilities

AWS Cloud Security

  • Own the security posture of our AWS environment: IAM, networking, encryption, KMS, secrets management, and multi-account governance.
  • Operate AWS-native security services: GuardDuty, Security Hub, Config, IAM Access Analyzer, Macie, Inspector, CloudTrail, and Control Tower.
  • Design and review secure-by-default patterns for new services. Provide security guidance on Terraform, CloudFormation, and CDK changes.
  • Drive identity, network, and data perimeter strategy. Reduce blast radius and enforce least privilege across accounts.
  • Harden container, serverless, and Kubernetes (EKS) workloads where they touch sensitive data.

Security Operations

  • Run day-to-day SecOps: detection engineering, alert triage, threat hunting, and incident response.
  • Tune and operate the SIEM, SOAR, and EDR stack (e.g., CrowdStrike). Author and maintain detections as code.
  • Drive the implementation of Zero Trust principles and manage endpoint security for employee devices, including local admin removal for employees handling customer data.
  • Lead incident response end-to-end: containment, forensics, root cause, customer comms, and blameless postmortems.
  • Run vulnerability management and patching cadence; track and drive remediation SLAs.
  • Build runbooks, on-call playbooks, and tabletop exercises that keep the team sharp.

AI-Enabled Engineering

  • Use AI coding agents (Claude Code, Cursor, Copilot, or similar) daily to accelerate security engineering work.
  • Build automations and small services that turn manual security work into repeatable, code-defined workflows.
  • Apply AI to scale Tier-1 triage, alert enrichment, IR draft communications, and detection content authoring.
  • Help shape security guardrails for AI tooling and AI-related workloads as they emerge in our stack.

Governance, Risk & Compliance

  • Support SOC 2 Type I/II and similar audits: evidence collection, control mapping, and customer questionnaire response.
  • Run third-party and vendor security assessments.
  • Manage security awareness training and the anti-phishing program.
  • Manage relationships and contracts with security vendors (MSSP, EDR, WAF, vulnerability management, etc.).

Cross-functional Partnership

  • Champion the DevSecOps mindset and foster a security-first culture across engineering teams.
  • Be the go-to technical reviewer for new product surfaces, infrastructure designs, and data flows.
  • Partner with Legal and Privacy on regulatory requirements, control implementation, and audit readiness.
  • Mentor engineers on secure coding, threat modeling, and cloud security best practices.

Requirements

Required:

  • 6+ years in cloud security, security operations, or infrastructure security, with hands-on production experience.
  • Strong working knowledge of AWS security: IAM, VPC, KMS, GuardDuty, Security Hub, CloudTrail, Config, and multi-account governance.
  • Hands-on security incident response experience. Led real investigations, written postmortems, and tuned detections in a SIEM/SOAR.
  • Comfortable scripting and building small services in Python, Go, or similar.
  • Use AI coding agents (Claude Code, Cursor, Copilot) as part of default workflow.
  • Working knowledge of NIST CSF, CIS Controls, OWASP Top 10, and MITRE ATT&CK.
  • Experience implementing cloud-native detection and monitoring.
  • Audit experience: SOC 2, ISO 27001, PCI, or similar.
  • Hands-on experience with endpoint security, including EDR (e.g., CrowdStrike), local admin removal, and device management/hardening.

Nice to have:

  • Detection engineering and SOAR/automation experience at scale.
  • IaC security: Terraform, CDK, or CloudFormation, plus CI/CD security gates and policy-as-code (OPA, Cedar).
  • Container and Kubernetes (EKS) security.
  • Multi-cloud exposure (GCP or Azure) in addition to AWS.
  • Familiarity with AI/LLM security (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF).
  • Certifications: AWS Security Specialty, CISSP, CCSP, GCIH, GCIA, GCFA, or OSCP.
  • Built custom MCP servers, agent frameworks, or in-house security tooling.
  • Open-source contributions to cloud security or detection engineering tooling.

Skills

AWS, IAM, Guardduty, Security Hub, Cloudtrail, Kubernetes, EKS, Crowdstrike, Python, Go, Terraform, SIEM, Soar, Edr, Zero Trust

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Valon

Valon

United States

Senior Security Engineer, Threat & Offensive Security
$180k+/yrRemote5+ YOESecurity Engineering

Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.

Anyscale

Anyscale

India
Senior Product Security Engineer
$180k+/yrOn-site8+ YOESecurity Engineering

Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.

Anyscale

Anyscale

San Francisco, CA

Compliance Manager
$180k+/yrOn-site7+ YOESecurity Engineering

Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.

Siftstack

Siftstack

Marina Del Rey, CA

Senior Application Security Engineer
$180k+/yrHybrid5+ YOESecurity Engineering

The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.