Skip to content
LyftLyft

Senior Software Engineer, CorpSec

Build and automate security services, identity infrastructure, and code-security controls while conducting reviews, penetration testing, and breach-readiness work. The role requires at least five years of software engineering experience, security expertise, and familiarity with IAM platforms and identity protocols.

About the job

Responsibilities

  • Architect and build scalable security services while minimizing unnecessary friction.
  • Partner with IT and infrastructure teams to design, build, and maintain performant authentication and authorization systems.
  • Own the security posture of identity infrastructure, including SSO implementations, MFA strategies, access provisioning workflows, and identity lifecycle management.
  • Share knowledge through brown bags and tech talks, and promote appropriate engineering best practices.
  • Collaborate across the company to apply security best practices as new features and services are rolled out.
  • Conduct penetration testing, code reviews, and breach readiness activities across online and mobile infrastructure.
  • Research new attack vectors that may affect the organization.
  • Research and implement automated code-security quality gates.
  • Build and maintain relationships with internal and external partners.

Requirements

  • 5+ years of software engineering experience with a high-level programming language.
  • 3+ years of computer security experience, or a deep interest in the field.
  • Experience with Identity and Access Management (IAM) platforms such as Okta, Duo Security, Microsoft Entra ID (Azure AD), or similar identity providers.
  • Experience securing OAuth 2.0, OIDC, SAML, SCIM, and JWT protocols and standards.
  • Ability to learn quickly and solve poorly defined or unfamiliar problems.
  • Strong communication skills, including the ability to advocate for proposals while empathizing with teammates’ goals and priorities.
  • Good judgment when prioritizing security work and balancing competing resources.
  • Self-motivated and able to work independently with minimal supervision.
  • Experience with threat modeling, code review, and penetration testing against cloud environments and/or mobile platforms.
  • Ability to conduct code reviews in one or more of the following languages:
    • Python
    • Go
    • Java
    • Swift / Objective-C
  • Development skills for automating code-security assessments.
  • Knowledge of computer networking concepts and protocols, application security, and network security methodologies.
  • Understanding of network security architecture, including topology, protocols, components, and defense-in-depth principles.
  • Ability to present findings, recommendations, and results to leadership.
  • Ability to communicate complex information confidently and clearly through verbal, written, and/or visual means.
  • Ability to manage multiple tasks and priorities.

Compensation and Benefits

  • Compensation and benefits information was not provided in the posting.

Skills

Python, Go, Java, Swift, Objective-C, Okta, Duo Security, Microsoft Entra Id, Oauth 2.0, OIDC, SAML, SCIM, Jwt, Threat Modeling, Penetration Testing

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.

Lyft

Lyft

Mexico City, Mexico

Security Assurance Analyst, Security and Privacy
No salary listedHybridSecurity Engineering

Supports third-party risk assessments, security questionnaires, and compliance program reporting for Lyft’s Privacy and Compliance team. Requires 1–3 years of relevant program management experience, security framework knowledge, strong organization, and familiarity with GRC tools.

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.