Latest Security Engineering jobs
Job results
This role develops detection, incident-response processes, automation, and security tooling for large-scale cloud products and services. Candidates should have hands-on incident response and product security experience, cloud expertise, and strong development skills in Golang or Python.
The Security Engineer will own vulnerability management while hardening AWS environments, improving identity controls, and integrating application security into CI/CD. The role requires 2–4 years of security experience, hands-on AWS security knowledge, remediation workflow expertise, and strong cross-functional communication.
Leads corporate endpoint security architecture and automation, with emphasis on macOS, Terraform, GitOps, and scalable controls across device platforms. The role partners across security and IT, improves detection and auditability, and mentors engineers.
Own and evolve security architecture across cloud infrastructure, applications, and APIs while working hands-on with engineers to remediate vulnerabilities and embed secure development practices. The role also leads audits, customer security reviews, regulatory controls, and incident readiness, with a path to manage a growing security team.
Executive leader responsible for setting strategy and leading Huntress’s global Threat Detection & Response organization across SOC, incident response, detection engineering, threat hunting, and adversary tactics. Requires 10+ years in security leadership and 5+ years managing managers and directors.
Leads ID.me’s Product Security program and security engineering team, partnering with Product and Engineering to reduce risk through practical, developer-aligned controls. Requires strong technical depth across application and cloud security, outcome-based leadership, and experience building security programs in fast-moving cloud-native environments.
Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.
Security Engineer responsible for building detection and prevention controls, automating security operations, conducting threat hunts, and supporting incident response across a remote-first organization. Requires 3+ years of security or software development experience, cloud-native security expertise, and automation skills.
The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.
Build and lead application and product security practices across a 145-engineer organization, embedding secure defaults, CI guardrails, threat modeling, and vulnerability mitigation into product development. The role requires 6+ years of hands-on security experience, strong coding ability, and microservices expertise.
Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.
Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.
Build and operate governed AI-enabled security automation, including agentic workflows, SOAR playbooks, control evidence, GRC processes, and integrations across security platforms. The role requires at least three years of cybersecurity or related experience plus programming, API, security operations, and LLM workflow expertise.
Build and defend enterprise applications by conducting application security reviews, validating controls, and embedding security across the Secure SDLC. The role also develops agentic AI workflows, secure platform integrations, and internal security tooling, requiring software development experience and familiarity with modern application and AI security guidance.
Build and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.
Leads Anthropic’s coordinated vulnerability disclosure and CNA programs, including jailbreak disclosures, external researcher partnerships, public communication, and AI-assisted triage. The role requires disclosure coordination, vulnerability-response operations, and security-community engagement experience.
The analyst develops and evaluates cyber product policies, enforcement guidance, controlled-access frameworks, and launch-review inputs for AI systems. The role requires strong policy writing, cybersecurity or platform-enforcement familiarity, technical security literacy, and cross-functional communication.
Senior hands-on security engineer responsible for endpoint hardening, device trust, identity and SaaS governance, and scalable corporate-security automation across a growing organization. Requires endpoint security expertise, Python scripting, IAM and zero-trust depth, and strong threat-modeling judgment.
The Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.
Investigates and responds to security alerts, intrusions, malware, and suspicious cloud activity while providing remediation guidance. The role requires at least two years of SOC or DFIR experience and knowledge of endpoint telemetry, threat actor techniques, administration, networking, and web security.
Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.
This role defines, builds, and secures the internal platform supporting Front’s engineering, GTM, data, and AI tooling. It owns AWS and Snowflake infrastructure, paved-road delivery, observability, access controls, vulnerability management, incident response, compliance support, and AI-client security.
Build and lead Fireworks AI’s security operations function, owning detection engineering, incident response, threat intelligence, and SecOps workflows. The role requires 7+ years of security experience, hands-on EDR and cloud security expertise, strong Python automation skills, and the ability to grow an IC function into a team.
The Threat Intelligence Specialist investigates identity fraud and threat actors, conducts pivot-based OSINT, and collaborates with law enforcement agencies across EMEA. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.
Build and operate foundational security services covering identity, authorization, secrets, and privileged access for an AI-powered enterprise platform. The role requires 5+ years of production software engineering experience and hands-on security infrastructure expertise.
Own network engineering and government cybersecurity compliance for on-site and field-deployed aerospace systems. The role requires 5+ years of experience, end-to-end IATT/ATO experience, strong networking skills, and familiarity with DoD security frameworks and tactical communications.
Leads architecture, technology integration, scanning, risk prioritization, and remediation strategy for a global vulnerability management program. The role requires senior-level vulnerability management experience, security framework expertise, audit support, and the ability to automate workflows with AI.
Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
The intern will support identity and access security through access-review dashboards, group analysis, documentation, and RBAC implementation. The role requires Google Sheets proficiency, strong communication, analytical thinking, and an ability to work in Cloudflare’s Austin office three to five days weekly.
Investigates and assesses physical security threats involving personnel, executives, events, travel, and operations. The role requires at least five years of relevant intelligence or threat-assessment experience, strong analytical communication, and familiarity with OSINT, behavioral threat methodologies, and technology-enabled investigations.
The Security Engineer will lead application security across the SDLC, integrating DevSecOps controls, conducting threat modeling and secure code reviews, and managing application vulnerabilities. The role requires 3+ years of application security experience plus hands-on expertise with AWS, Kubernetes, IaC, CI/CD, and mobile or web security.
Leads enterprise Zero Trust and secure-access networking, owning Zscaler architecture and operations while supporting Palo Alto, wireless, LAN/WAN, and multi-cloud infrastructure. The role requires 10+ years of network experience, deep ZIA/ZPA expertise, automation skills, and major-incident leadership.
Leads the maturation of an AWS cloud security program by designing and automating controls, integrating security into CI/CD workflows, and developing continuous compliance evidence. The role requires AWS security expertise and experience with infrastructure as code, automation, regulated SaaS, and cloud compliance initiatives.
The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
The engineer researches and operationalizes threat intelligence by building machine-learning detection capabilities, security-tool integrations, and SOAR automation. The role requires 4+ years of security, cyber threat intelligence, or security automation experience, strong scripting skills, and deep knowledge of adversary behavior and cloud security.
Owns corporate security across identities, endpoints, SaaS, email, and workplace AI tools. The role requires 5+ years of corporate, enterprise, or endpoint security experience, strong IAM and MDM expertise, coding ability, and practical risk-based security judgment.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Leads a high-leverage fraud intelligence team while personally investigating complex attacks across identities, devices, accounts, and payments. The role combines people leadership, incident response, threat intelligence, and partnerships with product and ML teams to improve fraud detection and prevention.
Leads technical security, compliance (SOC 2, GDPR, ISO 42001), vulnerability management, and infrastructure hardening for a fast-growing fintech. Requires 3-7 years in security engineering with hands-on AWS, vuln tooling, and audit experience.
Build automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.
Build detection, investigation, and incident-response systems protecting LangChain’s production platform, cloud infrastructure, and agentic workloads. The role requires 5+ years of security engineering experience, strong Python or Go skills, cloud and Kubernetes detection expertise, and hands-on incident response experience.
Build and maintain scalable authorization infrastructure, libraries, frameworks and policy-driven solutions at Stripe. Requires 2+ years software development experience in security domain, strong collaboration skills, and preference for simple, scalable designs. Go/Java/Ruby and authorization experience preferred.
Build the GRC platform at Anthropic by designing data pipelines, integrations, and agentic LLM workflows that automate compliance evidence collection, policy-as-code, and real-time risk reporting across cloud, identity, HR, and CI/CD systems.
Leads technology risk audits spanning IT SOX/ITGC, financial-reporting systems, and consumer trust domains such as security and privacy. The role partners with Engineering, manages audit projects and remediation, and applies AI automation to strengthen testing and monitoring.
The Security Engineer will establish hardware and embedded security practices for connected devices, covering secure boot, firmware, manufacturing, architecture reviews, threat modeling, and lifecycle controls. The role requires at least five years of hardware security, product security design, and hands-on Python and C/C++ development experience.
Owns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.
Owns security, privacy, compliance, and data-residency conversations for EMEA enterprise opportunities. The role designs secure cloud and BYOC architectures, leads threat modeling and readiness work, and enables field teams while engaging CISOs and security architects.