Security Engineer
The Security Engineer will implement and improve security controls across SaaS applications and AWS infrastructure, strengthen monitoring and incident response, and support compliance audits. The role also leads enterprise customer security reviews and requires at least three years of security experience with hands-on AWS expertise.
About the job
Responsibilities
- Partner with Engineering to design, implement, and improve security controls across software, application architecture, and AWS infrastructure.
- Strengthen security monitoring, detection, and incident response capabilities.
- Integrate security controls into CI/CD pipelines and software development workflows.
- Support SOC 2 and ISO audits.
- Lead technical portions of enterprise customer security reviews and architecture discussions.
- Advise Sales and Legal on customer security questions.
- Communicate security risks, requirements, and recommendations to technical teams, business partners, and customers.
- Identify opportunities to improve product and infrastructure security and compliance controls.
Requirements
- 3+ years of experience in security engineering, information security, compliance, or a related role.
- Hands-on experience securing AWS environments.
- Experience with AWS security services, including IAM, VPC, KMS, WAF, Security Hub, GuardDuty, and Macie.
- Knowledge of identity and access management, encryption standards, cloud infrastructure, and security tooling.
- Experience integrating security into CI/CD pipelines and software development workflows.
- Experience supporting SOC 2 and/or ISO audits.
- Experience supporting application security, cloud security, or incident response programs.
- Experience participating in customer security reviews and explaining technical concepts to varied audiences.
- Experience leading technical security or architecture discussions with enterprise customers.
- Strong analytical, project management, organization, and prioritization skills.
- Collaborative and adaptable approach across technical and business teams.
Compensation and Benefits
- Competitive base salary and company-wide bonus program.
- Flexible time off and parental leave.
- Medical, dental, vision, and life insurance fully paid for employees.
- 401(k) with company match.
- Rewards and incentives.
- Community service opportunities.
- Career development through the Learning & Development team.
Skills
AWS, Aws Iam, Amazon Vpc, Aws Kms, Aws Waf, Aws Security Hub, Amazon Guardduty, Amazon Macie, CI/CD, Cloud Security, Application Security, Incident Response, SOC 2, ISO 27001
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.
Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.