Latest Security Engineering jobs
Job results
Develops machine-level safety cases, hazard analyses, and safety requirements for autonomous mining and industrial equipment. The role requires hands-on system safety experience, knowledge of ISO 26262, and collaboration across hardware, software, controls, and validation teams.
The engineer conducts web, network, Active Directory, cloud, and container penetration tests, develops offensive security automation, and drives remediation with engineering and external testing partners. The role requires at least four years of offensive security experience plus scripting or programming proficiency.
Leads vulnerability disclosure operations at scale, including novel vulnerability measurement, CVE assignment, embargo coordination, and industry collaboration. The Staff individual contributor provides technical leadership and requires extensive software security or open source experience.
Leads detection engineering and incident response across corporate, production, and AI-agent environments. The role requires 8+ years of relevant experience, strong detections-as-code expertise, cloud and telemetry knowledge, and proven leadership of high-severity security incidents.
Leads infrastructure security strategy and implementation across cloud, identity, runtime, and software supply chains. The role requires 8+ years of infrastructure or cloud security experience, staff/principal-level leadership, and hands-on expertise with major cloud and security platforms.
Leads security architecture, assessments, automation, and security-by-design practices for the Walrus team and broader ecosystem. The role requires 8+ years of security engineering experience, broad technical expertise, and Staff-level leadership.
Analyzes insureds’ cybersecurity posture, investigates incidents and claims, and recommends prioritized risk-reduction measures. The role requires 2–4 years of security experience, strong network and threat knowledge, familiarity with assessment tools and security frameworks, and a bachelor’s degree or equivalent experience.
The Senior Threat Engineer designs scalable threat-detection, decisioning, and response workflows, using investigation, automation, and operational data to improve accuracy and reduce manual review. The role requires significant cybersecurity operations experience and strong analytical, communication, and cross-functional collaboration skills.
Leads technical response to security events across cloud infrastructure, services, and applications, covering triage, containment, remediation, automation, and post-incident improvements. Requires 3+ years of cloud security incident response experience and expertise with SIEM, SOAR, and major cloud platforms.
Owns insider-risk investigations and advances data-loss prevention capabilities across people, devices, identities, and data movement. The role requires 4+ years of security investigations or DLP experience, strong case-management judgment, and familiarity with governance frameworks and SIEM tooling.
The Senior Security Engineer will build and operate EU/UK security GRC programs for regulated fintech products, automating controls and evidence collection while partnering with engineering, privacy, auditors, and regulators. Requires substantial regulated-environment experience and hands-on knowledge of DORA, EU/UK regulations, cloud security, and compliance automation.
Leads day-to-day threat management through detection engineering, threat hunting, incident response, security automation, and vulnerability analysis. Requires at least two years of information security experience, strong Python skills, and knowledge of operating systems, networking, and cloud security.
Leads company-wide information security, data governance, compliance, and risk programs while driving AI security strategy and executive-level governance. The role requires board presentation experience, enterprise customer engagement, vendor and supply chain risk expertise, and multiple security certifications.
Leads customer incident response and digital forensics engagements, investigating breaches, containing threats, and recommending remediation. Requires 5+ years of experience, strong knowledge of forensic and EDR tools, AWS, security frameworks, and German and English communication.
Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.
Leads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.
Owns secure container image pipelines and automates vulnerability remediation for regulated, on-premises, and air-gapped deployments. The role requires deep container expertise, Kubernetes and Helm knowledge, Go or Python automation skills, and strong technical writing for auditors and customer security teams.
Secures Datadog’s cloud infrastructure, platform building blocks, and SaaS applications by implementing scalable solutions across a multi-cloud Kubernetes environment. The role requires hands-on software engineering, application and cloud security experience, and expertise with modern security frameworks and technologies.
The Senior Security Engineer will build and operate detection and response capabilities across Mixpanel’s product, cloud, corporate, and identity environments. The role requires deep detection-as-code expertise, Google Cloud and Python proficiency, and the ability to lead EMEA incident response.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Build scalable security controls and services for MongoDB Atlas multi-cloud infrastructure, spanning runtime protection, cloud security posture, identity, observability, and secure infrastructure automation. The role requires 5+ years of software or SRE experience, strong Linux and networking fundamentals, cloud expertise, and Kubernetes security experience.
Leads product security strategy and assessments for MongoDB’s server products, partnering with engineers on threat modeling, secure architecture, vulnerability research, and remediation. The role requires 7+ years of security experience and strong C++ expertise with low-level codebases.
Leads AI security strategy, architecture, governance, and defensive controls across the organization while mentoring security engineers. Requires 9+ years of security engineering experience and deep knowledge of AI, AWS security services, identity protocols, and emerging AI attack frameworks.
Secures Glean's software supply chain by managing vulnerabilities, hardening images, protecting open-source dependencies, and embedding trusted release controls in CI/CD. Requires 3+ years in application security or vulnerability management, strong cloud-native and container security knowledge, and experience with FedRAMP audits.
Owns frontline security alert triage, incident response, detection coverage, and automation across cloud, SaaS, container, and Web3 environments. Requires at least three years of hands-on security operations experience and proficiency with scripting, SIEM platforms, and threat intelligence tooling.
Leads product security architecture and builds security-critical services, frameworks, and controls across engineering teams. The role requires 10+ years of software engineering experience, deep expertise in secure distributed systems, and strong cross-team technical leadership.
Leads product security incident response for Snowflake’s AI products and infrastructure, developing detection, containment, and remediation capabilities for LLM and agentic threats. Requires 5+ years in security, incident command experience, cloud-native expertise, and strong knowledge of AI attack surfaces.
Leads product security incident response for Snowflake’s AI and agentic products, developing detection, containment, remediation, and automation capabilities. Requires 5+ years in security, incident command experience, cloud expertise, and knowledge of AI/ML attack surfaces.
Manages Decagon’s governance, risk, and compliance program, including enterprise certifications, audit evidence, vendor risk, customer security assessments, and RFP responses. Requires 3–5 years of GRC experience, strong communication and project management skills, and familiarity with technical security controls and privacy regulations.
Maintains Mozilla’s information security management system and leads ISO 27001 and SOC 2 compliance activities, including audit readiness, policy governance, remediation tracking, and stakeholder coordination. Requires at least five years in information security, GRC, or compliance and strong audit experience.
The Senior Security Engineer will investigate, contain, and perform forensics on security incidents while supporting distributed on-call operations. The role also builds AI-enabled response automation and requires cloud security expertise, broad incident response skills, and experience with SIEM, SOAR, and security tooling.
Build and operate OpenRouter’s third-party risk program, assessing model providers, subprocessors, and SaaS vendors across security, privacy, and AI regulatory requirements. The role requires 4+ years of vendor security risk experience, technical fluency, and strong independent judgment.
Leads infrastructure security strategy and execution across GitLab’s cloud platforms and self-managed offerings. The role requires deep cloud, Kubernetes, Infrastructure-as-Code, security tooling, threat modeling, and technical leadership experience.
Leads security assurance, governance, risk, and compliance programs across ISO 27001, PCI DSS, SOC 2, HIPAA, and international frameworks. The role manages audits, policies, risk treatment, automated evidence collection, customer questionnaires, and cross-functional advisory work.
Designs and governs enterprise identity architecture across workforce, customer, partner, non-human, and AI agent identities. The role requires 8+ years in IAM, deep CIAM and Auth0 experience, federation expertise, and the ability to implement secure, auditable controls in regulated environments.
Conducts AI-focused security research, agent and LLM testing, adversary simulation, and detection-efficacy validation. The role requires 4+ years of offensive or application security experience, strong penetration-testing or cloud-security fundamentals, and knowledge of AI attack vectors and MITRE ATT&CK.
Leads NexHealth’s security governance, compliance, IT operations, vendor security, privacy, and incident response programs while building the security function and team. Requires 8+ years of security experience, leadership building programs from the ground up, audit ownership, and a software engineering background.
This foundational privacy engineering role designs privacy-preserving architectures, infrastructure, governance systems, and compliance controls for large-scale AI training and inference. It requires substantial software engineering experience, privacy expertise, and technical leadership across engineering, research, legal, and product teams.
Build and operate secure-by-default cloud infrastructure, including AWS security controls, secrets management, IAM, and authentication systems. The role requires production software development, security architecture expertise, threat modeling, and pragmatic cross-functional communication.
Develop and maintain compliance frameworks, control libraries, automations, and product improvements that help customers meet security requirements efficiently. The role requires hands-on security program experience, knowledge of major compliance standards, and strong technical fluency with JSON and scripting.
Software engineer responsible for identifying, triaging, and coordinating remediation of vulnerabilities across company systems. The role requires at least two years of industry software engineering experience in security and strong collaboration and problem-solving skills.
Own cloud security posture across AWS, Azure, and GCP by triaging CNAPP findings, enforcing Terraform policy-as-code guardrails, and hardening Kubernetes environments. The role requires 4–6 years of cloud or platform security experience, strong expertise in at least one major cloud, and hands-on remediation leadership.
The SOC Analyst owns alert triage, investigates cloud, identity, and endpoint activity, and escalates incidents with actionable context. The role requires 2–3 years of SOC or blue-team experience, hands-on SIEM and EDR work, strong incident documentation, and English communication skills.
The SOC Engineer will build detection and response capabilities, including SIEM log pipelines, ATT&CK-mapped detections, alert investigation, automation, and runbooks. The role requires 3–5 years of SOC or detection-engineering experience plus strong cloud, identity, scripting, and SIEM expertise.
As Odyssey's first Security Engineer, own the company's security posture by building programs from the ground up, assessing risks, implementing controls across the tech stack, maintaining SOC 2 compliance, and embedding security into development workflows. Requires 6+ years software engineering experience focused on security, cloud, or DevOps, plus hands-on compliance and tooling expertise.
Security Engineer responsible for securing AI agent execution, infrastructure, and product surfaces at an applied AI lab building Devin and Windsurf. Requires deep security engineering, software engineering fundamentals, and cloud/web security expertise.
Leads the architecture and evolution of enterprise identity systems, including SSO, SCIM, tenant models, permissions, and shared identity primitives across products. Requires senior-staff experience guiding large-scale distributed platforms, setting multi-year technical direction, and aligning multiple teams on secure, reliable solutions.
Investigates sophisticated threat actors and executes large-scale disruption operations involving platform abuse, account compromise, influence campaigns, and fraud. The role requires strong SQL, scripting, analytical, communication, and urgent incident-response skills.
Leads the design, automation, and operation of enterprise endpoint security across multi-cloud and SaaS environments. The role requires 5+ years of information security experience, software development skills, and expertise across Windows, macOS, and Linux endpoint platforms.