Security Engineer
Secure Raindrop’s application and cloud platform through scalable controls, threat modeling, audits, and incident response while partnering with customer security teams. The role requires startup security engineering experience, compliance familiarity, and strong communication.
About the job
Responsibilities
- Secure the platform end-to-end, from application code through cloud infrastructure.
- Design and implement security controls that scale to millions of requests per day.
- Conduct threat modeling, security audits, and incident response.
- Communicate directly with customers’ security teams.
Requirements
- Experience in security engineering at a fast-growing startup.
- Familiarity with compliance frameworks and requirements, including SOC 2 and HIPAA.
- Contributions to the security community, such as exploits or open-source projects.
- Interest in AI products and tools; experience building them or being an avid user is preferred.
- Growth mindset and willingness to take ownership of challenging problems.
- Strong written and verbal communication skills.
- Must work in person in San Francisco or be willing to relocate.
Skills
Threat Modeling, Security Audits, Incident Response, Cloud Infrastructure, Application Security, SOC 2, HIPAA, Open Source
Similar jobs
Security Engineering jobsProtects a cloud-native fintech environment by building detections, investigating threats, operating vulnerability management, and automating security workflows. Requires 5+ years in security operations or related fields, strong Python skills, cloud experience, and expertise in telemetry-driven threat detection.
Designs and operates identity and access management systems covering federation, governance, privileged access, automation, and Zero Trust controls. Requires hands-on scripting and IAM engineering experience, including production automation and AI/LLM usage.
Build and operate automated corporate security controls across endpoint devices, identity, network access, and enterprise AI tooling. The role requires 3–5 years of endpoint, identity, or corporate security experience, strong macOS and Okta expertise, and scripting skills.
Owns hands-on GRC operations for the public-sector business, including FedRAMP/GovRAMP continuous monitoring, POA&M management, vulnerability remediation, audit readiness, and customer-facing compliance content. Requires 4+ years of cybersecurity or compliance experience and direct FedRAMP, GovRAMP, or comparable experience.
Build and improve security analytics, detection, and incident response capabilities by analyzing telemetry, investigating threats, and developing scalable behavioral models and pipelines. Requires 3+ years of security analytics experience, strong Python and SQL skills, and expertise in incident response and forensics.