Security Engineer
Security Engineer enhances AWS serverless infrastructure security, develops playbooks, improves compliance with SOC/HIPAA/HITRUST, and collaborates on secure CI/CD and app design. Requires 4+ years AWS experience and TypeScript proficiency.
About the job
Responsibilities
- Develop playbooks and address security-related tasks in AWS serverless environments.
- Drive improvements in broader security posture, including application security, endpoint security, access management/just-in-time access, email and web gateways, browser security, and data loss prevention.
- Collaborate with product engineering teams to raise security standards, supporting CI/CD pipelines, dependency management, and secure application design reviews.
- Secure and improve AWS organization using infrastructure as code (CDK), enforcing security controls, and ensuring strong tenant isolation.
- Continuously assess vulnerabilities and perform regular risk assessments.
Requirements
- 4+ years of experience in engineering, working as a security engineer or in security-adjacent roles.
- Familiarity with compliance frameworks such as SOC, HIPAA, and/or HITRUST.
- 4+ years working with AWS services, including compliance and governance services like AWS Organizations, AWS CloudTrail, AWS Config, Security Hub, and GuardDuty.
- Proficiency in TypeScript.
- Ability to prioritize work based on business and customer needs.
- High bandwidth; thoughtful attention to many areas simultaneously.
- Ability to context switch as priorities shift.
- Philosophical alignment with Stedi Standards and Unwritten laws of engineering.
Skills
AWS, TypeScript, Cdk, AWS Lambda, Api Gateway, SQS, Sns, DynamoDB, Aurora Serverless, Aws Organizations, Aws Cloudtrail, Aws Config, Security Hub, Guardduty, HIPAA
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.
Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.