Latest Security Engineering jobs
Job results
Staff-level security engineer leading enterprise IAM, cloud identity, AI platform access, and non-human identity governance. The role requires deep Okta, infrastructure-as-code, Python, GCP or AWS, and regulated-environment experience.
Conduct end-to-end security research on emerging threats, CVEs, misconfigurations, and cloud attack surfaces, then turn findings into scalable detection capabilities. Requires at least five years of security research or related experience, strong scripting skills, and expertise in network and application security.
Own the security posture of a fast-growing developer product across application, infrastructure, cloud, and internal systems. The role requires at least three years of relevant engineering or security experience, strong vulnerability judgment, and hands-on JavaScript or TypeScript expertise.
Leads cyber-focused AI misuse enforcement, managing analysts and contractors while developing detection and mitigation strategies for attacks, malware, and exploitation. Requires people management, cybersecurity expertise, high-volume abuse enforcement, data analysis with SQL or Python, and cross-functional risk communication.
Develop AI-augmented offensive security tooling, red-team internal AI systems, and automate vulnerability workflows. The role requires at least three years of application or offensive security experience, programming ability, and hands-on experience with LLM security.
Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.
Build and operate automated continuous security control monitoring, AWS evidence collection, and AI-enabled GRC workflows. The role requires at least five years of GRC experience, hands-on automation and AWS expertise, and the ability to defend automated controls and evidence to auditors.
Leads Fetch’s end-to-end information security program, including application security, vulnerability management, incident response, architecture, GRC, AI risk, and third-party risk. The role requires 7+ years of security experience, incident command capability, and people leadership.
Leads end-to-end response to sophisticated compromises, account takeovers, device threats, and related financial fraud for high-profile clients. Requires 5–8+ years of incident response or DFIR experience, broad device forensics expertise, strong client communication, and fraud-remediation experience.
Early-career cybersecurity professional implementing and monitoring security controls across Linux, Kubernetes, database, and AI infrastructure. Requires 1–3 years of hands-on technical experience, Linux and scripting skills, and interest in federal authorization and security engineering.
Investigates cyber incidents and insurance claims, assesses security controls, and advises customers and security leaders on prioritized risk improvements. The role requires 2–4 years of security experience, strong network threat knowledge, and familiarity with major security and compliance frameworks.
The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.
Build and operate browser, workflow, and AI-assisted automation for Cloudflare’s distributed data center security compliance processes. The role focuses on portal extraction, ACL reconciliation, audit evidence generation, anomaly detection, and operational tooling ownership.
The Senior GRC Analyst will manage security governance, risk, and compliance programs, including SOC 2 controls, risk assessments, vendor reviews, audits, and data governance. The role requires 8+ years of GRC experience, a bachelor’s degree, and familiarity with compliance platforms and SaaS environments.
Develop and maintain secure platform software spanning authentication, authorization, communications, data access, and automated security testing. The role requires 5+ years of security-focused software development experience, strong coding skills, and expertise in cloud and container security.
Leads vulnerability management and application-security initiatives across the technology stack, securing operating-system images, open-source dependencies, CI/CD pipelines, containers, and cloud-native systems. Requires 5+ years of application-security experience, coding ability, and expertise in vulnerability-scanning practices.
The Security Engineer will secure cloud infrastructure, engineering systems, APIs, model-training environments, and GPU clusters while supporting rapid delivery. The role requires hands-on cloud security, IAM, secrets and certificate management, compliance ownership, vulnerability monitoring, and incident response experience.
Own end-to-end security detection engineering, incident response, automation, and threat hunting across endpoint, identity, SaaS, and cloud environments. The role requires substantial hands-on experience with production detection logic, incident response, programming, and modern SIEM or detection pipelines.
Lead Cloudflare's CCCS CSP ITS assessment and maintain CCCS requirements in the Common Control Framework. Requires 5+ years in security compliance, deep CCCS knowledge, and cross-functional collaboration with engineering, legal, and product teams.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Leads and scales the product security program for cloud-native, AI-powered SaaS products, combining strategy, team leadership, secure architecture, vulnerability management, and hands-on technical execution. Requires 8+ years in application or product security and significant people-management or technical-leadership experience.
The Senior Information Security Engineer will lead threat hunting, detection engineering, incident response, vulnerability management, and security-platform ownership across cloud and enterprise environments. The role requires 5+ years of security experience, strong attacker-TTP knowledge, and hands-on expertise with enterprise security technologies and automation.
Build and mature Virta’s application security program by securing GCP and Kubernetes environments, automating vulnerability and compliance processes, and embedding security across engineering. The role requires 5–7+ years of experience, strong cloud and application security expertise, and proficiency with Terraform and Go or Python.
Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.
Security engineer responsible for detection engineering, investigations, incident response, identity and access management, and preventative security controls across corporate and production environments. Requires 2+ years of security engineering experience, programming ability, and familiarity with cloud and defensive security tooling.
Security Engineer focused on application and platform security, security reviews, threat modeling, vulnerability management, and secure development practices. The role requires at least two years of relevant experience, programming ability, and familiarity with cloud security technologies.
Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.
Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.
Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.
The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.
Leads enterprise AI security architecture and develops security systems, automation, and agentic AI identity strategies at scale. Requires 7+ years in security or infrastructure security, enterprise technical leadership, cloud and container security expertise, and strong programming skills.
Leads Chronograph’s information security and IT strategy, combining executive leadership with hands-on oversight of cloud, application, AI, corporate, and compliance security. Requires at least seven years of security experience, broad technical depth, assurance-program leadership, and strong executive communication.
Own Alex’s information security, compliance, AI governance, and enterprise trust program as its first dedicated Security & Trust hire. The role combines security reviews and customer-facing assurance with audits, regulatory readiness, risk management, and technical control development.
Senior individual contributor responsible for improving cyber operations, resolving complex dual-use safety decisions, and building scalable reviewer, quality, vendor, and automation systems. Requires 8+ years of hands-on cybersecurity experience and strong operational judgment.
Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.
A hands-on graduate fellowship focused on identifying, exploiting, analyzing, and defending against cybersecurity vulnerabilities affecting critical infrastructure. Applicants should be final-year students or recent graduates in cybersecurity, IT, or computer science and must work onsite three days per week.
Own Socket’s compliance program as an engineered system, leading SOC 2 Type II, ISO 27001, risk and vendor programs, automated evidence pipelines, and customer assurance. The role requires deep audit ownership, ISO 27001 experience, automation skills, and the ability to build and lead a compliance function.
Own and scale Sardine’s security compliance and GRC function across major security, privacy, and resilience frameworks, including FedRAMP. The role leads audits, risk management, customer assurance, executive reporting, and a growing compliance team while partnering closely with technical and business stakeholders.
Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.
Own and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.
Build and operate Chainguard’s public-sector governance and trust capabilities, translating federal security requirements into automated controls, evidence systems, and risk-based decisions. The role requires hands-on federal, defense, or intelligence experience and strong technical fluency in cloud-native environments.
Build production security automation, CI/CD guardrails, and AI-assisted workflows for Starburst’s Application Security program. The role requires a strong information security foundation, software engineering ability, and 2–4 years of relevant experience.
Own and scale Starburst’s application and product security program through secure-by-default engineering, automated vulnerability management, threat modeling, and autonomous offensive testing. The role requires 5–7 years of security-focused experience, strong software supply chain expertise, and the ability to engage enterprise customers and lead engineers.
Owns DRTM adoption, attestation, and platform hardening across x86 and ARM infrastructure, working across firmware, bootloaders, kernels, hardware, and silicon security. The role requires deep systems-security experience, upstream Linux or firmware contributions, and strong vendor and OEM leadership.
This role creates and tests red-team labs, ranges, and learning content that simulate real-world attacks and teach offensive-security concepts. It requires several years of penetration-testing or offensive-security experience, strong MITRE ATT&CK knowledge, and broad technical cybersecurity skills.
Develop and operate global physical security systems, controls, and compliance processes across data centers and other facilities. The role manages investigations, risk mitigation, audits, vendor deployments, and cross-functional security initiatives, with approximately 35% travel required.
The IT Compliance Manager will lead SOX ITGC and ITAC design, testing, audit coordination, and remediation across complex cloud and SaaS environments. The role requires 7–10 years of IT audit or technology risk experience, strong control-framework expertise, and the ability to influence engineering and finance stakeholders.
The Incident Response Security Engineer will build detection, response, and security automation capabilities for large-scale cloud infrastructure. The role requires hands-on incident response and product security experience, cloud expertise, and strong development skills in Go or Python.