Latest Security Engineering jobs
Job results
This remote Security Incident Response Engineer detects, investigates, and resolves security incidents while improving automation, documentation, and detection capabilities. The role requires SIEM and cloud experience, Python skills or willingness to learn, and an interest in forensic investigations.
Leads application and AI security assessments across web, API, cloud-native, and LLM-based systems. Requires 8+ years of cybersecurity experience, hands-on penetration testing and secure SDLC expertise, and experience adversarially testing AI applications.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.
Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.
Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.
Build foundational security services and automation protecting Hover’s applications, users, and cloud infrastructure. The role suits an early-career software engineer with strong programming fundamentals, a computer science background, and interest in secure development practices.
Build Greptile’s security product, including code scanning, vulnerability detection and reproduction, security-focused pull-request workflows, and agent infrastructure. The role requires a computer science degree, software or DevOps experience, JavaScript/TypeScript expertise, and hands-on security experience.
Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.
Own end-to-end security incidents and conduct forensic investigations across endpoint, network, cloud, memory, and identity environments. The role requires 6–8 years of hands-on security experience, strong EDR/SIEM and scripting skills, and participation in an incident-response on-call rotation.
Supports third-party risk assessments, security questionnaires, and compliance program reporting for Lyft’s Privacy and Compliance team. Requires 1–3 years of relevant program management experience, security framework knowledge, strong organization, and familiarity with GRC tools.
The Senior Security Engineer will build and operate detection and incident-response capabilities across cloud production and corporate environments. The role requires 7+ years of security engineering experience, AWS expertise, threat hunting, investigations, automation, and SIEM/SOAR proficiency.
Senior Cloud Security Engineer responsible for designing, implementing, and assessing security controls across a multi-cloud environment. The role requires 5+ years of security solution implementation experience, strong cloud and cybersecurity expertise, and proficiency in risk assessment, infrastructure as code, and security technologies.
Leads live fraud and abuse incident response, investigates high-risk accounts, and helps merchants remediate security threats. Requires 10+ years of security or fraud incident-response experience, expert Python and SQL skills, and expertise in forensics, threat intelligence, and network security.
Leads information security governance, compliance, security operations, risk management, and incident response for a healthcare AI company. Requires 5+ years of security experience and hands-on expertise with major compliance frameworks, SIEM, incident response, and third-party risk.
The Information Security Engineer manages security compliance programs, audit readiness, client due diligence, and security questionnaires. The role requires 2+ years of experience with SOC 2, ISO 27001, data privacy frameworks, and compliance tooling.
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.
Leads offensive security research across GitLab’s codebase and AI-powered agentic surfaces, identifying systemic vulnerabilities, developing exploit proofs of concept, and driving remediation. Requires 10+ years of security research or penetration-testing experience and proficiency in multiple programming languages.
Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.
Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.
Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.
Build detection, threat-hunting, and automated incident-response capabilities for AI infrastructure, including GPU clusters, training pipelines, and model deployments. The role requires substantial security operations experience, strong programming skills, and expertise in distributed systems or AI/ML environments.
Build AI-focused detection and response capabilities, investigate incidents, and hunt threats across distributed training and inference infrastructure. The role requires staff-level security engineering experience, including 3+ years securing AI/ML or distributed systems and strong automation and detection skills.
Build and scale application security for an enterprise AI platform, including threat modeling, secure architecture, automated controls, code review, and penetration testing. Requires at least four years of application security experience, programming expertise, and knowledge of DevSecOps and security-testing practices.
Build and scale application security for an enterprise AI platform through threat modeling, secure architecture, automated controls, code review, penetration testing, and AI/ML threat research. Requires 4+ years of application security experience and proficiency in at least two programming languages.
Staff Security Engineer owns security across applications, infrastructure, and workflows at LiveKit. Requires 6+ years software engineering experience, hands-on security expertise in cloud/container environments, threat modeling, and incident response.
Senior Security Compliance Engineer supporting public-sector compliance programs, regulated customers, audits, certifications, and FedRAMP continuous monitoring. Requires 5+ years in GRC or cybersecurity, compliance automation experience, cloud familiarity, and U.S. citizenship and residency.
Build and own Juicebox’s governance, risk, compliance, and customer trust function, leading audits, enterprise security reviews, policies, and AI governance initiatives. Requires 3+ years in GRC or security compliance and experience with SOC 2, ISO 27001, and customer security questionnaires.
Own fraud monitoring, threat hunting, detection rules, scoring logic, and mitigation systems for Ether.fi’s financial products and card program. The role requires strong analytical pattern recognition, cross-functional ownership, and familiarity with payment or crypto fraud as a plus.
Investigates and responds to complex fraud and product-abuse incidents, analyzes high-risk accounts and threat patterns, and improves detection and response at scale. Requires 3+ years of incident response and data analysis experience, strong Python and SQL skills, and expertise in security investigations.
Leads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.
Develops safety requirements, analyses, and fail-operational architectures for autonomous-vehicle sensing and perception systems. The role requires 3+ years analyzing safety-critical systems and familiarity with functional-safety standards, sensing hardware, perception, and cross-functional systems engineering.
Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.
Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.
Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.
Investigates trust and safety issues while managing legal requests, anti-abuse operations, and sensitive escalations. The role requires 3–5 years of relevant ISP or hosting-provider experience, DNS knowledge, and strong collaboration and communication skills.
Analyzes attacker tactics, campaigns, and platform abuse in real time while building detection and mitigation capabilities. The role requires experience with security analysis, threat intelligence, SQL, and Python or other scripting.
Own and improve vulnerability-management operations across cloud, on-premises, network, and endpoint environments, driving risk-based prioritization, remediation, SLA tracking, and closure validation. The role requires 3–5 years of security experience, including direct vulnerability-management responsibility, plus incident support and on-call participation.
Leads security risk identification, prioritization, and remediation across an infrastructure organization while building a security program and advising technical leaders. Requires a bachelor’s degree, 8+ years of software or infrastructure engineering experience, and substantial security experience.
Own and operate Vertex Synapse, integrating and modeling threat intelligence while delivering it to detections, blocklists, data pipelines, and security workflows. Requires at least two years of production threat-intelligence platform or security data-pipeline experience and software development skills in Python, Go, or Storm.
Leads end-to-end fraud and abuse incident response, investigating high-risk accounts, coordinating cross-functional mitigation, and improving detection and response capabilities. Requires 10+ years of security or fraud incident response experience, strong Python and SQL expertise, and experience with forensics and automated workflows.
Investigates high-risk accounts and leads incident response for fraud and product-abuse events, using behavioral analysis and threat intelligence to identify root causes and improve detection. Requires 3+ years of incident response and fraud-data analysis experience, plus strong Python and SQL skills.
Investigates and leads response to high-risk fraud and product-abuse incidents, analyzes threat patterns, and drives root-cause and prevention improvements. Requires 3+ years of incident response and fraud-oriented data analysis, plus Python, SQL, and security investigation expertise.
Owns technology compliance and security assurance controls across corporate and business systems, aligning evidence for SOX, SOC 2, ISO, regulatory, and contractual obligations. The role requires 5+ years in compliance, audit, security, or IT, strong control-testing experience, and a bachelor's degree or equivalent.
The Staff Software Security Engineer will secure large-scale AI clusters and multicloud infrastructure through network controls, identity management, secure development workflows, and threat modeling. The role requires 8+ years of software engineering experience, strong systems programming skills, and deep cloud and Kubernetes security expertise.
Build and lead a Security Quality Management System for agentic and human-led SOC investigations, establishing quality standards, sampling, validation, reporting, and corrective actions. The role requires 5+ years in quality, governance, operational excellence, or controls, plus security operations and people-management experience.
The Security Engineer will implement and improve security controls across SaaS applications and AWS infrastructure, strengthen monitoring and incident response, and support compliance audits. The role also leads enterprise customer security reviews and requires at least three years of security experience with hands-on AWS expertise.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.