Skip to content
BasetenBaseten

Security Engineer

Security Engineer builds and maintains security for ML infrastructure platform, designing secure cloud/container systems, managing vulnerabilities/incidents, IAM, compliance, and integrating DevSecOps. Requires 3+ years experience in cloud security and security tools.

About the job

Responsibilities

  • Security architecture and design: Collaborate with engineering teams to design and implement secure systems and infrastructure, including cloud (AWS/GCP) environments and container orchestration platforms.
  • Vulnerability management: Lead proactive vulnerability assessments, pen tests, and remediation efforts to ensure our products and infrastructure remain secure.
  • Incident response: Develop and maintain incident response processes, including detection, analysis, containment, eradication, and post-incident reviews.
  • Identity and access management (IAM): Oversee IAM strategies and tools to ensure the right people have the right level of access to our systems and data.
  • Security compliance and audits: Work closely with operations to ensure compliance with relevant standards (e.g., SOC 2, ISO 27001) and assist with audits, policy creation, and risk assessments.
  • Employee security training: Develop and deliver security training programs and documentation to keep our team informed about best practices, social engineering threats, and secure coding standards.
  • DevSecOps integration: Partner with DevOps teams to embed security into the CI/CD pipeline, automating security checks and fostering a culture of “security as code.”

Requirements

  • 3+ years of experience in a Security Engineer or similar security-focused role, preferably in a fast-paced startup environment.
  • Strong knowledge of cloud security (AWS/GCP), container security, and infrastructure-as-code best practices.
  • Hands-on experience with security tooling (SIEM, IDS/IPS, vulnerability scanners) and scripting languages to automate security tasks.
  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, and GDPR, and the ability to translate requirements into actionable security controls.
  • Incident response expertise, including forensic analysis and root cause investigation.
  • Excellent communication skills and the ability to collaborate with cross-functional teams to promote a security-first culture.

Benefits

  • Competitive compensation, including meaningful equity.
  • 100% coverage of medical, dental, and vision insurance for employee and dependents.
  • Generous PTO policy including company wide Winter Break (our offices are closed from Christmas Eve to New Year's Day!).
  • Paid parental leave.
  • Company-facilitated 401(k).
  • Exposure to a variety of ML startups, offering unparalleled learning and networking opportunities.

Skills

AWS, GCP, Container Security, SIEM, Ids/Ips, Vulnerability Scanners, SOC 2, ISO 27001, GDPR, Infrastructure As Code, CI/CD, Scripting

Modal

Modal

New York, NY

Detection And Response Engineer
$150k+/yrOn-siteSecurity Engineering

Build automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.

Figma

Figma

United States

Federal Compliance Manager
$153k+/yrRemote5+ YOESecurity Engineering

Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.

Motive

Motive

Canada

Red Team Security Engineer
CA$146k+/yrRemote5+ YOESecurity Engineering

Conduct cloud-focused red team operations, adversary simulations, and offensive security assessments while validating detection coverage and driving remediation. Requires at least five years of offensive security experience and familiarity with attacker techniques, cloud environments, and MITRE ATT&CK.

Coinbase

Coinbase

Canada

Product Security Engineer
CA$154k+/yrRemote3+ YOESecurity Engineering

Develop AI-augmented offensive security tooling, red-team internal AI systems, and automate vulnerability workflows. The role requires at least three years of application or offensive security experience, programming ability, and hands-on experience with LLM security.

Motive

Motive

Toronto, Canada

Security Engineer, Hardware/Device
CA$146k+/yrHybrid5+ YOESecurity Engineering

The Security Engineer will establish hardware and embedded security practices for connected devices, covering secure boot, firmware, manufacturing, architecture reviews, threat modeling, and lifecycle controls. The role requires at least five years of hardware security, product security design, and hands-on Python and C/C++ development experience.