# Security Engineer, Infrastructure & Security

**Company:** [Scale AI](https://hotfix.jobs/companies/scale-ai)
**Location:** New York, NY, St. Louis, MO, Washington, DC
**Role:** Security Engineering
**Salary:** $149k – $342k/yr
**Experience:** 5+ years
**Skills:** TypeScript, Python, Kubernetes, CI/CD, SAST, DAST, Terraform, Node.js, JavaScript
**Posted:** 2026-07-23

> Product Security Engineer focused on securing infrastructure and services for public sector customers. Conduct code reviews, SAST/DAST, implement secure CI/CD and Terraform, influence security strategy, and explain vulnerabilities. Requires product security experience, proficiency in TypeScript/Python/Kubernetes, and strong problem-solving/communication skills.

## Job Description

## Responsibilities
- Conduct in-depth code reviews to identify and remediate security vulnerabilities.
- Evaluate and enhance the security of product offerings through RFC and service review.
- Implement and maintain CI/CD pipelines with a strong focus on security.
- Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify vulnerabilities in production code.
- Utilize Terraform orchestration to ensure secure and efficient infrastructure management.
- Guide engineering teams to build robust long-term solutions that consider security and privacy.
- Clearly explain the mechanics and significance of security vulnerabilities, including their exploitability and potential impact.
- Influence the security strategy and direction of the team, advocating for best practices and continuous improvement.

## Requirements
- Proven experience as a Security Engineer with a focus on product security.
- Proficiency in NodeJS, TypeScript, Python, and/or Kubernetes.
- Strong understanding of modern Javascript application design.
- Production experience with Kubernetes backed services.
- Hands-on experience with SAST and DAST tools and methodologies.
- Familiarity with Terraform orchestration for infrastructure management.
- Ability to structure complex problems and diagnose root causes independently, providing actionable insights without requiring manager input.
- Excellent communication skills, with the ability to clearly present technical concepts and their implications to both technical and non-technical stakeholders.
- Demonstrated ability to influence security strategies and drive improvements within a team.

## Nice-to-Haves
- At least a Secret level government security clearance.
- Relevant security certifications (e.g., CISSP, CEH, OSCP).

## Similar roles

- [Infrastructure Security Engineer, Public Sector](https://hotfix.jobs/jobs/71fbcc81-11ef-4bc0-a907-80eca7ee2821) - Scale AI - New York, NY - $149k – $342k/yr
- [Security Engineer](https://hotfix.jobs/jobs/8913deb3-fccc-48ca-84a7-d452d7457cb2) - Figma - Remote - $149k – $350k/yr
- [Cloud Security Engineer](https://hotfix.jobs/jobs/543dd116-127a-4348-a38f-4a5c025af160) - Virta Health - Remote - $149k – $188k/yr
- [Security & Compliance Engineer](https://hotfix.jobs/jobs/0fe396b6-3353-482d-9e15-168119079999) - Aurelian - Seattle, WA - $150k – $215k/yr
- [GRC Manager](https://hotfix.jobs/jobs/68a03d3e-1579-49d0-ab74-5a8e2b7e975b) - Baseten - San Francisco, CA - $150k – $250k/yr

**Apply:** https://hotfix.jobs/jobs/abd9b01b-7d05-4614-b806-f3d6b2ab4a2c
**Canonical:** https://hotfix.jobs/jobs/abd9b01b-7d05-4614-b806-f3d6b2ab4a2c