Skip to content
OloOlo

Staff Security Engineer (Blue Team)

Leads Blue Team in information protection, incident detection/response, and security services. Oversees vulnerability management, threat hunting, and cloud security in AWS environments. Requires 5+ years security engineering experience and technical leadership of remote teams.

About the job

What You'll Do

Guide and coach Olo’s Blue Team

  • Guide and coach on Information Protection, Incident Detection and Response and Service Delivery.
  • Provide strategic and technical oversight to the team and the program.
  • Technically lead a team of security engineers and analysts who hunt, detect, and respond to internal and external threats.
  • Collaborate with customers and partners to strengthen their security posture.
  • Drive ongoing optimizations by implementing new technologies, replacing technologies, addressing evolving threats, scaling practices and automating security activities.
  • Keep team member and customers data safe by identifying and mitigating vulnerabilities and risks by providing actionable guidance to product teams.

Information Protection

  • Lead Olo’s Information Protection program including the selection, testing, implementation and maintenance of security tools and services, security awareness, service provider management and the ongoing testing of those controls.
  • Oversee Vulnerability Management program including vulnerability assessments, risk scoring and vulnerability resolution.
  • Oversee Threat Hunting program to detect and mitigate advanced threats.
  • Manage non-event driven security reviews, including concept reviews, design reviews, patching, firewall rules and system configuration checks.
  • Apply Web application and API security principles and techniques, such as zero trust, RBAC, authentication, authorization, auditing, rate limiting, challenges, etc., to protect our cloud-based services from unauthorized access and abuse.

Incident Detection and Response

  • Oversee Incident Detection and Response program including ownership of incident response processes, tools and services and the ongoing continuous improvement of those controls.
  • Coordinate the detection and response to attacks through all incident phases.
  • Ensure incident reports are accurate, detailed and relevant.
  • Monitor, detect, and remediate misconfigurations and security risks across our cloud environments.
  • Participate in a 24/7 on-call rotation.

Security Services

  • Oversee Security Services program including security support requests, risk assessments, vendor assessments, PCI and SOC audit support and service provider management.

What We'll Expect from You

  • 5+ years of Security Engineering, Security Operations or Security Architecture experience.
  • CISSP, GCIH or similar certification preferred.
  • Experience acting as technical lead to distributed teams consisting largely of remote engineers.
  • Experience complying with PCI-DSS and other compliance and regulatory standards.
  • Experience with attacker tactics, techniques and procedures.
  • Knowledge of information technology, evolving threats, attack patterns, incident response and cyber security standards.
  • Experience developing and leading incident response, remediation and mitigation activities, and providing status updates and reports.
  • Experience analyzing security events to discern events that qualify as a legitimate security incident as opposed to non-incidents (ie. incident investigation, implementing countermeasures, and conducting incident response).
  • Deep understanding of operating system, networking and application concepts.
  • Experience hardening Windows, MacOS, Linux Containers and Kubernetes.
  • Familiarity with AWS security best practices and Infrastructure-as-Code.
  • Experience deploying and maintaining security technologies. (e.g. Access Proxies, API Gateway, Anti-Malware, Application Control, Cloud Security Posture, Data Leak Prevention, Data Mapping, Endpoint Detection & Response, Intrusion Detection System, File Integrity Monitoring, Firewalls, Mobile Device Management, Multi Factor Authentication, SIEM, Static Inspection, Vulnerability Assessment, Web Proxies, WAF and Zero Trust).
  • Adept at working with internal Product & Engineering, Legal, People & Culture, Finance and GTM teams and external partners, auditors and customers.
  • Ability to work during critical incidents or to support coverage requirements.

Skills

SIEM, Kubernetes, AWS, Zero Trust, Cissp, Gcih, Pci-Dss, Vulnerability Management, Threat Hunting, Incident Response, Endpoint Detection & Response, Waf, Multi Factor Authentication, Api Gateway, Cloud Security Posture

GitLab

GitLab

United States
Staff Security Researcher
$168k+/yrRemote7+ YOESecurity Engineering

Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.

Okta

Okta

Bellevue, WA
Staff Identity Governance and Access Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.

Twilio

Twilio

United States

Staff Security Engineer
$156k+/yrRemote7+ YOESecurity Engineering

Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.

Ironclad

Ironclad

San Francisco, CA

Staff IAM Engineer
$170k+/yrHybrid4+ YOESecurity Engineering

Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.

Okta

Okta

Bellevue, WA
Staff Identity Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.