Skip to content
Scale AIScale AI

Security Engineer, Infrastructure & Security

Product Security Engineer focused on securing infrastructure and services for public sector customers. Conduct code reviews, SAST/DAST, implement secure CI/CD and Terraform, influence security strategy, and explain vulnerabilities. Requires product security experience, proficiency in TypeScript/Python/Kubernetes, and strong problem-solving/communication skills.

About the job

Responsibilities

  • Conduct in-depth code reviews to identify and remediate security vulnerabilities.
  • Evaluate and enhance the security of product offerings through RFC and service review.
  • Implement and maintain CI/CD pipelines with a strong focus on security.
  • Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify vulnerabilities in production code.
  • Utilize Terraform orchestration to ensure secure and efficient infrastructure management.
  • Guide engineering teams to build robust long-term solutions that consider security and privacy.
  • Clearly explain the mechanics and significance of security vulnerabilities, including their exploitability and potential impact.
  • Influence the security strategy and direction of the team, advocating for best practices and continuous improvement.

Requirements

  • Proven experience as a Security Engineer with a focus on product security.
  • Proficiency in NodeJS, TypeScript, Python, and/or Kubernetes.
  • Strong understanding of modern Javascript application design.
  • Production experience with Kubernetes backed services.
  • Hands-on experience with SAST and DAST tools and methodologies.
  • Familiarity with Terraform orchestration for infrastructure management.
  • Ability to structure complex problems and diagnose root causes independently, providing actionable insights without requiring manager input.
  • Excellent communication skills, with the ability to clearly present technical concepts and their implications to both technical and non-technical stakeholders.
  • Demonstrated ability to influence security strategies and drive improvements within a team.

Nice-to-Haves

  • At least a Secret level government security clearance.
  • Relevant security certifications (e.g., CISSP, CEH, OSCP).

Skills

TypeScript, Python, Kubernetes, CI/CD, SAST, DAST, Terraform, Node.js, JavaScript

Modal

Modal

New York, NY

Detection And Response Engineer
$150k+/yrOn-siteSecurity Engineering

Build automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.

Figma

Figma

United States

Federal Compliance Manager
$153k+/yrRemote5+ YOESecurity Engineering

Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.

Ramp

Ramp

New York, NY

Systems Engineer, Corporate Security
$144k+/yrHybrid3+ YOESecurity Engineering

Build and operate automated corporate security controls across endpoint devices, identity, network access, and enterprise AI tooling. The role requires 3–5 years of endpoint, identity, or corporate security experience, strong macOS and Okta expertise, and scripting skills.

OnePay

OnePay

United States

Security and Threat Operations Engineer
$140k+/yrRemote5+ YOESecurity Engineering

Protects a cloud-native fintech environment by building detections, investigating threats, operating vulnerability management, and automating security workflows. Requires 5+ years in security operations or related fields, strong Python skills, cloud experience, and expertise in telemetry-driven threat detection.

Datadog

Datadog

New York, NY

Security Engineer 2 - Cyber Threat Intelligence
$140k+/yrHybridSecurity Engineering

Security Engineer on the Cyber Threat Intelligence team responsible for developing threat intel tooling, conducting threat hunting, analyzing malware, and operationalizing intelligence into detections and response workflows.