Latest Security Engineering jobs
Job results
Leads end-to-end fraud and abuse incident response, investigating high-risk accounts, coordinating cross-functional mitigation, and improving detection and response capabilities. Requires 10+ years of security or fraud incident response experience, strong Python and SQL expertise, and experience with forensics and automated workflows.
Investigates high-risk accounts and leads incident response for fraud and product-abuse events, using behavioral analysis and threat intelligence to identify root causes and improve detection. Requires 3+ years of incident response and fraud-data analysis experience, plus strong Python and SQL skills.
Investigates and leads response to high-risk fraud and product-abuse incidents, analyzes threat patterns, and drives root-cause and prevention improvements. Requires 3+ years of incident response and fraud-oriented data analysis, plus Python, SQL, and security investigation expertise.
Owns technology compliance and security assurance controls across corporate and business systems, aligning evidence for SOX, SOC 2, ISO, regulatory, and contractual obligations. The role requires 5+ years in compliance, audit, security, or IT, strong control-testing experience, and a bachelor's degree or equivalent.
The Staff Software Security Engineer will secure large-scale AI clusters and multicloud infrastructure through network controls, identity management, secure development workflows, and threat modeling. The role requires 8+ years of software engineering experience, strong systems programming skills, and deep cloud and Kubernetes security expertise.
Build and lead a Security Quality Management System for agentic and human-led SOC investigations, establishing quality standards, sampling, validation, reporting, and corrective actions. The role requires 5+ years in quality, governance, operational excellence, or controls, plus security operations and people-management experience.
The Security Engineer will implement and improve security controls across SaaS applications and AWS infrastructure, strengthen monitoring and incident response, and support compliance audits. The role also leads enterprise customer security reviews and requires at least three years of security experience with hands-on AWS expertise.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Build and operate the infrastructure, telemetry pipelines, and automation powering a scalable detection and response program. The role requires 5+ years of infrastructure, SRE, software, or security engineering experience, strong Python skills, cloud operations expertise, and knowledge of security detections.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Own GitLab’s global security awareness and human-risk program, leading phishing simulations, behavior-change initiatives, training platforms, vendor strategy, and audit support. Requires 10+ years scaling enterprise awareness programs and strong stakeholder influence in a distributed organization.
Senior Security Engineer responsible for scaling vulnerability detection, prioritization, remediation, and verification across multi-cloud products. The role combines hands-on engineering, AI and automation, risk analysis, and cross-functional security collaboration.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Leads ZoomInfo’s enterprise security governance, risk, and compliance strategy for Ireland, including continuous compliance, third-party risk, AI-enabled automation, and executive reporting. Requires 10+ years in information security or GRC, senior leadership experience, and strong knowledge of NIST, ISO, and SOC 2 frameworks.
Build security into embedded vehicle platforms through security assessments, secure boot implementation, and HSM integration. This new-grad role requires a relevant computer or electrical engineering degree, foundational cryptography knowledge, and proficiency in C, C++, or Python.
Hands-on security engineer responsible for security operations, bug bounty and vulnerability management, DevSecOps pipeline hardening, cloud security, and identity management. Requires 5+ years of software and security engineering experience and strong coding fundamentals.
Lead technical response to security incidents across Twilio's global cloud infrastructure, including triage, containment, remediation, documentation, and post-incident improvements. Requires 5+ years incident response experience, expertise with SIEM/SOAR, cloud platforms, and AI-driven security tools.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
The Application Security Engineer will lead an engineering-driven vulnerability management program, validating and prioritizing findings, automating workflows, and partnering with development teams on remediation. The role requires strong application security fundamentals, coding ability, and experience with modern scanning, cloud, container, and CI/CD environments.
The Senior Security Engineer partners with engineering teams on application, cloud, infrastructure, detection, vulnerability, and incident security. The role requires at least five years of security engineering experience, strong software review skills, and hands-on expertise across AWS, Kubernetes, CI/CD, monitoring, and incident response.
The Staff Information Systems Security Officer will secure and accredit classified information systems by implementing RMF and NIST controls, managing vulnerabilities, supporting audits and incident response, and overseeing Cross Domain Solutions. The role requires 8 years of classified-environment cybersecurity experience and expertise in DoD and IC requirements.
Senior security engineer who red teams formally verified systems, assesses proof and threat-model boundaries, and builds AI-driven vulnerability discovery and exploit-generation tooling. Requires hands-on offensive security, formal methods, systems expertise, software development, and rigorous technical reporting.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.
Build data pipelines, integrations, policy-as-code, and agentic AI workflows that automate security governance and continuous compliance. The role requires 7+ years of production software engineering experience plus expertise in LLMs, APIs, distributed data, and cloud infrastructure.
Build and operate evaluations for cyber capabilities and safeguard robustness in AI models, analyze adversarial data, and develop cyber-abuse detection probes. The role requires hands-on cybersecurity experience, Python proficiency, evaluation expertise, and strong cross-functional communication.
Build and automate technical security controls, compliance workflows, and audit evidence for enterprise readiness. The role requires strong scripting or programming skills, security fundamentals, and the ability to collaborate across engineering, security, legal, and customer-facing teams.
Senior Product Security Engineer who partners with developers to secure web applications and APIs throughout the SDLC. The role leads threat modeling, security reviews, penetration testing, secure code review, and security-tooling programs.
This hands-on security engineer will research sophisticated threat actors, build intelligence pipelines, conduct threat hunts, analyze malware and infrastructure, and translate findings into durable detections. The role requires at least five years of cyber threat intelligence or related experience, strong Python engineering, and malware and detection-analysis expertise.
The Technical GRC Analyst evaluates technical controls, validates evidence, performs risk assessments, and advances AI governance, compliance automation, and assurance reporting. The role requires 8+ years in technical security, Security GRC, or regulatory compliance, with cloud and enterprise technology experience.
Provides technical leadership for Security Operations by building cloud security platforms, automated controls, vulnerability-management workflows, and developer-facing security capabilities. Requires senior-level production systems experience, AWS security architecture, Terraform, and strong cross-functional technical ownership.
Leads security, privacy, audit, vendor-risk, and AI governance programs while setting long-term GRC strategy and executing cross-functional controls. Requires 10+ years of GRC, information security, and privacy compliance experience, with deep SOC 2, privacy, and emerging AI governance expertise.
Own Coinbase’s privacy incident management program, leading investigations, response coordination, remediation, retrospectives, and process improvements. The role requires 3+ years in privacy, security, incident response, or technology risk, plus SQL, Python, automation, and privacy regulatory knowledge.
Build and operate foundational security services spanning identity, access, secrets, privileged access, and secure AI-agent infrastructure. The role requires at least two years of production software engineering experience, cloud expertise, and experience translating security requirements into reliable automated systems.
The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.
Design and lead security architecture for Replit’s autonomous AI agents, including runtime guardrails, sandboxing, threat modeling, least-privilege delegation, and observability. Requires 6+ years in security engineering or architecture and specialized experience securing AI/ML or agentic systems.
Leads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.
The Response Engineer monitors and investigates security alerts, analyzes traffic, and applies attack mitigations while improving monitoring tools and supporting high-value customers. The role requires at least two years of technical and customer support experience plus strong networking, systems, scripting, and security expertise.
Build and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.
Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.
Corporate Security Engineer responsible for identity, endpoint, SaaS, and security automation controls across the company. The role requires 2–5 years of security engineering experience, hands-on endpoint and EDR expertise, identity protocol knowledge, and scripting ability.
Build and operate corporate security controls across identity, endpoints, SaaS applications, and automation. The role requires 2–5 years of security engineering experience, hands-on endpoint and EDR expertise, identity protocol knowledge, and scripting ability.
The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.
Leads continuous offensive security validation across cloud, mobile, corporate, and hardware environments. Requires 8+ years in offensive security, deep AWS and application-security expertise, advanced scripting ability, and leadership in red teaming and vulnerability research.
The Product Security Engineer will establish application and infrastructure security, build security tooling, remediate vulnerabilities, and lead incident response for a blockchain platform. The role requires 5–8 years of hands-on product or application security experience and strong coding, infrastructure, and application security expertise.
Senior Security Engineer on the Red Team performing offensive security, adversarial testing, and red team operations against GenAI/LLM systems, deepfake defenses, cloud infrastructure, and SaaS products. Requires 3+ years of hands-on pen testing/red team experience plus demonstrable GenAI attack experience.
The Senior Security Analyst will manage security governance, risk, and compliance activities, including audits, risk assessments, remediation, vendor reviews, and operational security. The role requires 5+ years of relevant experience, a bachelor’s degree, cloud-security knowledge, and hands-on AI-assisted GRC automation experience.
Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.
Own and strengthen Onebrief’s corporate security stack across endpoints, identity, SaaS, Zero Trust, and monitoring. The role emphasizes security automation, configuration-baseline enforcement, telemetry integration, and continuously validated compliance controls.