Skip to content
CommureCommure

Senior Software Engineer, Information Security

Senior Software Engineer architects scalable detection frameworks, integrates threat intelligence into automated security pipelines, and builds AI-driven security operations using Python, Java, and tools like Splunk and AWS. Requires 6+ years experience, bachelor's in CS/cybersecurity, and expertise in SIEMs, cloud security, and compliance.

About the job

What You'll Do

  • Design high-fidelity detections and correlation logic in Splunk Enterprise Security and AWS OpenSearch — tuning for coverage and signal-to-noise.
  • Build AI-powered detection tooling that ingests threat intel and recommends new use cases using ML and NLP techniques.
  • Write production Python, Java, and Bash to automate workflows, build internal tooling, and integrate with cloud and third-party APIs.
  • Engineer ETL pipelines for log ingestion, normalization, and routing across AWS, multi-cloud, and on-prem environments.
  • Translate red team findings, threat hunts, and pentest results into durable detection improvements and control enhancements.
  • Drive detection standards and reusable patterns across endpoint, network, identity, and cloud domains.
  • Mentor engineers and analysts on detection methodology, secure software practices, and architecture.

What You Have

  • Bachelor's degree in Computer Science, Cybersecurity, or a closely related technical field (Master's a plus).
  • 6+ years in software and/or security engineering, with 2+ years building detections on enterprise SIEMs (Splunk, OpenSearch, Securonix, or equivalent).
  • 2+ years hands-on experience developing security automation or AI/ML-based security applications in Python, Java, or similar.
  • Strong command of AWS (SageMaker, OpenSearch, Lambda, IAM), EDR platforms (CrowdStrike, Carbon Black), and modern identity tooling.
  • Fluency with MITRE ATT&CK, NIST CSF, Zero Trust, and CIS Controls; comfort integrating STIX/TAXII and MISP feeds.
  • Track record supporting compliance audits (SOC 2, FedRAMP, ISO 27001, HIPAA, or SOX) from a hands-on engineering seat.

Nice to Have

  • Splunk Certified Architect or Developer; CISSP, CEH, or GIAC GCED.
  • Experience applying ML to anomaly detection, behavioral analytics, or security NLP.
  • Background in healthcare, financial services, or other regulated industries.
  • Enterprise vulnerability management experience — authenticated scanning, CVSS prioritization, automated reporting.

Skills

Python, Java, Bash, Splunk, AWS, Opensearch, SageMaker, AWS Lambda, IAM, Crowdstrike, Carbon Black, Mitre Att&Ck, Machine Learning, NLP, ETL

Pinterest

Pinterest

United States

Senior Security Software Engineer, Security Operations
$156k+/yrRemote5+ YOESecurity Engineering

Provides technical leadership for Security Operations by building cloud security platforms, automated controls, vulnerability-management workflows, and developer-facing security capabilities. Requires senior-level production systems experience, AWS security architecture, Terraform, and strong cross-functional technical ownership.

Upstart

Upstart

United States

Senior Application Security Engineer
$167k+/yrRemote5+ YOESecurity Engineering

Leads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.

GitLab

GitLab

United States
Senior Manager, Product Security Engineering
$168k+/yrRemote5+ YOESecurity Engineering

Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.

Juicebox

Juicebox

San Francisco, CA

GRC Lead
$150k+/yrOn-site3+ YOESecurity Engineering

Build and own Juicebox’s governance, risk, compliance, and customer trust function, leading audits, enterprise security reviews, policies, and AI governance initiatives. Requires 3+ years in GRC or security compliance and experience with SOC 2, ISO 27001, and customer security questionnaires.

Censys

Censys

United States

Research Systems Analyst
$170k+/yrRemote6+ YOESecurity Engineering

Build and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.