Senior Security Software Engineer
Build and own core security services including auth, identity, and secrets management. Partner with engineering teams to embed secure-by-design practices across a Ruby/TypeScript/GCP stack.
About the job
Responsibilities
- Design and build core security services (permissions management, secrets orchestration, secure MLOps)
- Develop secure-by-default libraries and frameworks
- Enhance CI/CD pipeline with automated self-serve security controls (SAST, supply chain security)
- Conduct secure code and architecture reviews, enforce secure-by-design principles, lead threat modeling
- Build and maintain resilient cloud infrastructure with network isolation, automated vulnerability detection, and defense-in-depth strategies
- Run security incident response, document risks, support audits
- Advise teams on security best practices and bring security awareness to engineering
Requirements
- 5+ years of hands-on software engineering experience
- 3+ years of hands-on security-focused engineering experience
- Proficient in at least one programming language (Ruby, TypeScript, Python, C++, etc.)
- Experience building scalable security systems (secret management, service authorization, data encryption) in production
- Experience with threat modeling, security design reviews, or security incident response
- Experience integrating security directly into the SDLC
- Meticulous attention to detail
- Excellent communication and collaboration skills
- Ability to mentor and train engineers on secure development processes
Nice-to-Haves
- Willingness to ramp up in additional programming languages
- Proactive approach to continuous learning and staying current with emerging security trends
Benefits
- Competitive salary and meaningful equity
- Comprehensive medical, dental, and vision coverage
- Unlimited and flexible vacation policy
- Generous paid parental and new child bonding leave
- Mandatory self-care days each month
- Remote wellbeing resources (fitness classes, meditation tools, virtual therapy, family planning assistance)
- Support for continued education, management training, conferences, workshops, or certifications
Skills
Ruby, TypeScript, Python, C++, SAST, CI/CD, Kubernetes, GCP, Terraform, Docker, Threat Modeling, Secret Management, RBAC, SCIM, SOC 2
Similar jobs
Security Engineering jobsSenior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.
Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.