Security Engineer responsible for hands-on investigation, incident response, building security tooling and automation, and driving remediation across application, infrastructure, and cloud security at Privy. Requires strong software engineering skills (Python/Go/Ruby), experience investigating security incidents, and familiarity with security operations workflows.
Salary not listed
On-site3+ YOESecurity Engineering
About the role
Responsibilities
Own security engineering work end to end: investigate alerts, findings, anomalies, and security requests; identify root causes; drive remediation; and clearly document outcomes.
Participate in Privy’s security on-call rotation, helping respond to incidents, triage alerts, support vulnerability workflows, complete access reviews, and handle security escalations.
Build and maintain production-quality tooling that reduces manual work, including alert enrichment, automated triage and routing, remediation workflows, access-review automation, and detection improvements.
Lead focused investigations into suspected security events or compromises, gathering evidence methodically and coordinating the appropriate response.
Proactively identify recurring sources of operational toil and engineer durable solutions that improve the team’s speed, consistency, and ability to scale.
Partner with product and engineering teams to assess security risks, review lower-complexity designs and implementation plans, and make practical security tradeoffs to deliver quickly with quality and soundness.
Contribute across Privy’s application, infrastructure, cloud, and product-security surface area, developing broad context while building deeper expertise over time.
Minimum Requirements
Experience as a security engineer, detection engineer, or similarly hands-on engineer in a technically demanding environment.
Strong software-engineering skills in Python, Go, Ruby, or a similar language. You can build maintainable tooling and contribute directly to production fixes, not only one-off scripts.
Experience investigating security signals, incidents, vulnerabilities, suspicious activity, or other ambiguous technical problems through to resolution.
Familiarity with security operations, incident response, vulnerability management, detection engineering, access reviews, or related operational-security workflows.
A strong understanding of web, browser, infrastructure, or cloud security, with the ability to apply that understanding across a broad range of problems.
Good judgment under pressure, a methodical approach to investigation, and comfort working independently with agency despite incomplete information.
Strong communication and collaboration skills, including the ability to explain technical findings, risks, and recommended actions clearly to clients and internal stakeholders alike.
A self-directed approach to work: you notice gaps, make progress through ambiguity, and reliably close the loop.
Preferred Qualifications
Experience with AWS, GCP, or other cloud-security environments.
Experience with detection engineering, security automation, incident-response tooling, or remediation pipelines.
Bug-bounty experience, offensive-security exposure, or a strong attacker-minded approach to investigation.
Experience with IAM, secrets management, secure production access, or secure CI/CD.
Background in application security, infrastructure security, cryptography, or privacy engineering.
Experience with fintech, payments, blockchain, or another diligence-forward financial product domain.
Experience helping shape security operations, incident-response practices, vulnerability-management workflows, or a bug-bounty program.
Protects the company’s customers, employees, and platform by leading incident response, improving detection coverage, automating security operations, and hardening cloud, endpoint, identity, and SaaS environments. Requires 5+ years of security operations or related experience and strong cross-functional communication.
180k – 260k/yrHybrid5+ YOESecurity Engineering
Platform Engineer - Identity Infrastructure
PalantirPalo Alto, CA +2
Build and operate secure identity infrastructure, governance, authorization, and token-issuance systems across corporate and customer-facing cloud environments. Requires 3+ years in SRE, DevOps, or software engineering, production service experience, cloud and container expertise, infrastructure-as-code proficiency, and security focus.
Salary not listedHybrid5+ YOESecurity Engineering
Threat Intelligence Researcher (Cloud)
WizUnited States
Researches and tracks sophisticated state-backed and financially motivated threats targeting cloud environments, using telemetry, infrastructure analysis, malware analysis, and threat intelligence techniques. Requires at least five years of security or threat research experience.
160k – 220k/yrRemote5+ YOESecurity Engineering
Product Security Engineer
CloudflareAustin, TX
The Product Security Engineer builds AI-driven security automation, conducts threat modeling and security reviews, manages vulnerability remediation, and triages bug bounty findings. The role requires 5+ years of product or application security experience in cloud or SaaS environments plus hands-on AI/LLM engineering experience.
Salary not listedHybrid5+ YOESecurity Engineering
IT Manager
PaveSan Francisco, CA
Owns corporate security architecture and automation across identity, compliance, endpoint protection, SaaS, and internal IT systems. The role requires 5+ years of security engineering experience, deep IdP design expertise, audit control ownership, and a track record of impactful automation.