Skip to content
CapeCape

Security Engineer, Product Security

Security Engineer specializing in product security designs and implements AWS security controls, performs vulnerability assessments, integrates security into DevOps, and mentors engineers to protect cloud, mobile core, and app infrastructure. Requires 5+ years experience with 3+ in AWS.

About the job

Responsibilities

  • Design, implement, and manage robust security controls and policies within AWS, focusing on the confidentiality, integrity, and availability of data and services.
  • Perform comprehensive security assessments of cloud environments to identify vulnerabilities, assess risks, and recommend actionable mitigation strategies.
  • Lead the integration of security practices into the DevOps lifecycle, promoting secure development, deployment, and operational processes.
  • Utilize and optimize AWS security tools (Amazon GuardDuty, Amazon Inspector, AWS IAM, AWS KMS, AWS WAF, AWS Shield) and explore third-party solutions.
  • Assist in running penetration tests and security audits, ensuring prompt remediation.
  • Stay informed about latest security threats, vulnerabilities, and compliance mandates; provide strategic guidance.
  • Provide expert mentorship to junior security team members and engineers.
  • Collaborate with stakeholders to integrate security requirements into engineering projects.

Preferred Experience

  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent); advanced degrees or certifications (CISSP, AWS Certified Security Specialty) advantageous.
  • Minimum 5 years in information security, with 3+ years in AWS cloud security.
  • Deep understanding of AWS architecture, security services, and best practices.
  • Proficiency in IaC tools (Terraform, AWS CloudFormation) and automating security tasks.
  • Skilled in scripting (Python, TypeScript, Go).
  • Familiarity with containerization, microservices, network security, encryption, secure coding.

Competencies

  • Security expertise: finding/resolving vulnerabilities, bug bounties, secure by design.
  • Strong analytical, collaboration, communication, decision-making, dependability, customer-centric, flexibility, planning skills.

Compensation & Benefits

  • Competitive geo-adjusted compensation with equity.
  • 401(k) match.
  • 100% coverage of medical, dental, vision premiums for you and dependents.
  • 12 weeks paid parental leave.
  • Stipends for family-forming, gender-affirming care.
  • Unlimited PTO.

Skills

AWS, Amazon Guardduty, Amazon Inspector, Aws Iam, Aws Kms, Aws Waf, Aws Shield, Terraform, Aws Cloudformation, Python, TypeScript, Go, Iac, Kubernetes, DevOps

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

hud

hud

San Francisco, CA

Security Engineer
No salary listedOn-siteSecurity Engineering

Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.

Stripe

Stripe

United States

Abuse Research Engineer
No salary listedRemote5+ YOESecurity Engineering

Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Offensive Security
$300k+/yrHybrid5+ YOESecurity Engineering

Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.