Security Engineer
Senior Security Engineer owns security across infrastructure (GKE, GCP) and application stack, builds tooling/automation for secure-by-default development, leads threat modeling, red teaming, bug bounty, and incident response in a fast-paced startup. Requires 6+ years security engineering experience.
About the job
What You’ll Do
- Own the Stack: Secure everything from our Kubernetes clusters on the cloud to our SaaS integrations and developer workflows.
- Usher in the Future: Articulate and execute on a vision for what security should be in the age of LLMs giving both us and attackers increasing leverage.
- Engineer for Security: Build internal tooling and CI/CD automations that catch vulnerabilities before they ever hit production.
- Architect & Model: Lead threat modeling sessions and secure code reviews, ensuring we design "secure-by-default" APIs and deployments.
- Harden the Perimeter: Take a first-principles approach to hardening authentication and access control across all internal and external surfaces.
- Red Team: Proactively probe for vulnerabilities and lead the remediation.
- Lead the Bug Bounty: Primary owner for standing up, launching, and managing our Bug Bounty Program, triaging reports, and driving remediation.
- Respond & Remediate: Investigate vulnerabilities, lead incident response, orchestrate pen testing, and run blameless postmortems that result in systemic change.
- Evangelize: Translate complex security risks into actionable engineering tasks for peers.
Who You Are
- Startup Native: Thrive in fast-paced 100–300 person environments, prioritize when urgent, comfortable "failing forward".
- Security-First Engineer: 6+ years in software/infrastructure engineering with deep security focus; write code to plug holes.
- Cloud Savvy: Deeply familiar with Google Cloud (GCP), Kubernetes, containerized environments.
- Systems Thinker: Analyze systems for weaknesses in business logic, IAM, codebase.
- Action-Oriented: Track record responding to incidents and leading remediation without being the "no" person.
Technical Stack
- Cloud: Google Cloud Platform (GCP)
- Orchestration: Kubernetes (GKE)
- Infrastructure: Terraform / Infrastructure-as-Code
- Pipeline: Modern CI/CD workflows and SaaS integrations
Compensation
Target salary: $165,000-$200,000. Generous perks including $4000/yr travel stipend, $350/mo productivity stipend, $350/mo AI tools stipend, $150/mo team lunch stipend, $500 one-time home office stipend, up to 100% health insurance coverage, equity.
Skills
Kubernetes, GKE, GCP, Terraform, CI/CD, Threat Modeling, Secure Code Review, IAM, Bug Bounty, Pen Testing, Incident Response
Similar jobs
Security Engineering jobsLeads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.
Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.
Build and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.
Build and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.