Senior Security Engineer (GRC)
Designs and improves secure cloud-native architectures, CI/CD pipelines, and infrastructure security on AWS and Kubernetes. Conducts threat modeling, security reviews, automates controls, and drives compliance programs like SOC2.
About the job
Responsibilities
- Leverage extensive experience in Cloud Security to design, implement, and improve secure cloud-native architectures and CI/CD pipelines.
- Apply deep expertise in cloud infrastructure security to proactively identify risks, enforce best practices, and harden systems across the entire technology stack.
- Automate security controls and educate developers for future-proofing against vulnerabilities.
- Play an active part in designing and evolving the company’s overall information security governance and compliance program through policies, standards, procedures, and awareness.
- Work closely with engineering, infrastructure, and product teams to make sure controls fit both business objectives and technical realities.
Requirements
- 5+ years of experience in a security engineering role.
- Mastery of cloud infrastructure, particularly AWS.
- Prior experience focusing on infrastructure security and Kubernetes.
- Familiarity with secret management tools like Vault or KMS.
- Strong understanding of core information security concepts and major regulatory frameworks/standards (e.g. SOC2, ISO 27001, NIST CSF).
- Experience conducting security design reviews, threat modelling, and security testing.
- Excellent written and verbal communication skills, with the ability to present complex technical details as clear, risk-focused recommendations.
Perks
- Remote-first global workforce + NY office
- Annual company offsite + team onsites
- Professional reimbursement program (facilitates industry conference attendance, certifications, and more)
- Medical, dental & vision coverage (US + some other countries)
- 401k retirement plan + company match (US only)
- Wellness stipend
- Home office set up / ergonomic equipment program
Skills
AWS, Kubernetes, Vault, Kms, Soc2, ISO 27001, Nist Csf, CI/CD, Threat Modeling, Security Testing
Similar jobs
Security Engineering jobsLeads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.
Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.
Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.