Latest Security Engineering jobs
Job results
Staff Security Engineer embedded in TDI to build centralized security posture analytics, automate issue tracking and remediation, and drive AI-powered risk management across AWS, SaaS apps, and enterprise systems.
Build and mature AWS cloud security program and infrastructure for a cardiology platform company. Own security architecture, detection/response, HIPAA compliance, and infrastructure decisions balancing security, cost, and reliability.
Lead end-to-end security strategy and build a high-performing team to defend Cape's carrier-grade mobile network against nation-state threats while enabling rapid innovation. Requires 10+ years in information security including 5+ years in senior leadership building programs from early stage.
Staff-level product security engineer leading security reviews, threat modeling, penetration testing, and LLM/AI security assessments for Okta's identity platform. Requires deep manual security expertise and strong communication skills.
The Threat Intelligence Specialist investigates identity fraud and threat-actor activity, conducts pivot-based OSINT, and supports urgent law enforcement operations across APAC hours. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.
Senior Product Security Engineer partnering with engineering and product teams to secure distributed cloud services through threat modeling, vulnerability management, security tooling, incident response, and automation. Requires substantial security engineering, cloud, Kubernetes, and development experience.
Leads application security strategy and implementation for an AI-powered conversational platform, partnering with engineering teams on secure development, testing, code reviews, vulnerability remediation, and incident response. Requires 5+ years of application security experience and strong software engineering expertise.
Lead day-to-day physical security operations and vendor-managed armed/unarmed guard teams at OpenAI's Mountain View site. Develop policies, deliver FTO-style training, manage vendor performance, and coordinate with law enforcement while building cross-functional relationships. Requires 15+ years law enforcement or corporate security experience with frontline supervisory background.
GRC Analyst responsible for authoring security policies, managing company-wide security awareness training programs, establishing AI governance frameworks, conducting risk assessments on AI tools and models, and ensuring compliance with frameworks like SOC 2 and PCI-DSS. Requires 3+ years in information security GRC or compliance plus a Bachelor's degree.
Own the architecture and implementation of Onebrief's GRC framework for defense/government compliance (FedRAMP, CMMC, RMF, SOC 2). Translate regulatory requirements into technical security controls in close partnership with engineering teams.
Operates and improves cybersecurity detection, response, identity, and cloud security controls across corporate, product, and R&D environments. The role requires cybersecurity operations experience, cloud and on-premises security expertise, and strong communication skills.
Builds and maintains security detections, monitoring, automation, and incident response capabilities across SaaS, endpoint, identity, and Google Cloud environments. The role requires hands-on Google SecOps experience, scripting ability, and strong knowledge of attack techniques and security frameworks.
GRC Security Engineer building Compliance-as-Code, automated controls, and continuous compliance for fintech/payments (PCI DSS, NYDFS, FFIEC). Partners with engineering to embed regulatory requirements into systems while enabling business velocity in a regulated AI/fintech environment.
Lead Confluent's Detection & Response organization in Infrastructure Security. Define vision and roadmap for threat detection, investigation, and response across multi-cloud environments while building and mentoring a global distributed engineering team.
Senior Security Engineer responsible for architecting and securing Chainguard's multi-cloud infrastructure (primarily GCP), embedding security into developer platforms, and hardening environments for AI/agentic workflows using IaC and Kubernetes. Requires strong GCP expertise, DevOps background, and staff-level cloud security experience.
Support engineers in Identity and Access Management, AI, and Cloud security at Chainguard. Ideal for those with strong IT admin or software development foundations seeking to grow into security roles, with hands-on experience in at least one focus area.
Lead the build-out of Plenful's Security organization from the ground up as a strategic executive partner. Own end-to-end security strategy across product, cloud (AWS), compliance (HIPAA/SOC 2), incident response, and customer trust for a high-growth healthcare AI platform.
Security & Compliance Engineer owning end-to-end security posture and compliance programs (SOC 2, CJIS) for public safety AI tools. Blend of hands-on cloud security engineering (Azure, IAM, logging) and compliance ownership, including questionnaires, policies, and automation.
Own product security end-to-end at Wispr: prioritize threats, architect defenses, participate in early design reviews, and embed security into the platform for a voice AI product handling highly sensitive user data. Ideal for pragmatic security experts who enjoy finding vulnerabilities and improving team practices.
GRC Manager responsible for building and managing Baseten's security governance, risk assessment, compliance programs (SOC 2, ISO 27001, FedRAMP, HIPAA), audits, vendor risk, and customer assurance in a fast-growing AI infrastructure startup. Requires 5+ years in GRC or security compliance, preferably in SaaS/cloud environments.
Senior/Staff Security Researcher building scalable detection systems that combine program analysis, taint tracking, and LLMs to find and validate real vulnerabilities with minimal false positives. Requires strong appsec expertise, coding fluency in multiple languages, and experience with applied AI for security-critical automation.
Design and own Northwood's identity and endpoint security architecture with deep focus on Okta administration, SSO, RBAC, MDM, and privileged access controls. Ensure compliance with CMMC Level 2, NIST, ITAR and other government standards in a hybrid environment.
Senior Security Engineer building security architectures and controls from the ground up for Northwood's global phased array ground station network enabling real-time satellite communications. Requires 5+ years IaC experience, deep knowledge of FedRAMP/NIST 800-171, ability to obtain TS/SCI clearance, and ownership of incident response, compliance automation, and government liaison duties.
Senior Detection and Response Engineer building and operating a SOC for a global satellite ground station network. Lead incident response, threat hunting, detection engineering, and forensics for mission-critical space infrastructure and national security systems.
Security Engineer building high-precision detections, incident response automation, and telemetry pipelines for cloud and SaaS platforms in the Public Sector. Requires active Top Secret clearance, 5+ years in detection engineering or incident response, and production coding skills.
Infrastructure Security Engineer securing large-scale cloud environments, Kubernetes clusters, and infrastructure-as-code (Terraform) for the Public Sector team. Requires active Top Secret clearance, infrastructure security experience, and proficiency in cloud, Kubernetes, and scripting languages.
The Senior Infrastructure Security Engineer will secure cloud and on-premises infrastructure through posture management, IaC guardrails, identity controls, certificate lifecycles, and network security. The role requires 5–8 years of infrastructure, SRE, or security engineering experience plus strong Terraform, cloud, Kubernetes, networking, and cryptography expertise.
Leads global Security Operations and Incident Response, shaping SOC architecture, cyber defense strategy, automation, and threat mitigation across enterprise and cloud environments. The role requires deep defensive security expertise, technical team leadership, and strong executive communication.
Serve as the dedicated senior security partner to OpenAI's Marketing team, identifying secrecy risks in launches, events, creative production, and external partners while embedding practical controls that protect sensitive information without slowing execution. Requires 12+ years protecting major product launches and building trusted relationships with executives and creative teams.
Security Engineering Intern at Labelbox supporting vulnerability management, IAM workflows, cloud access controls, SIEM optimization, and CI/CD security. Requires current pursuit of a CS/Cybersecurity degree, interest in cloud/data security, and basic cloud platform knowledge.
Corporate Security Automation Engineer leading design, implementation, and optimization of security infrastructure using IaC (Terraform), automation, endpoint protection, DLP, and ZTNA in a fast-scaling fintech. Requires 5+ years IT experience with 3+ in enterprise cloud security, scripting, and security frameworks.
Senior Security Researcher driving offensive security insights at Censys using large-scale Internet scan data. Conduct original research on attack techniques and agentic AI, publish at top conferences, translate findings into product scanning/fingerprinting capabilities, and collaborate cross-functionally. Requires 5+ years hands-on pentesting/red teaming experience plus agentic AI tooling expertise.
Product Security Engineer focused on securing infrastructure and services for public sector customers. Conduct code reviews, SAST/DAST, implement secure CI/CD and Terraform, influence security strategy, and explain vulnerabilities. Requires product security experience, proficiency in TypeScript/Python/Kubernetes, and strong problem-solving/communication skills.
Build and own a portfolio of specialized AI agents that autonomously discover, validate, and drive remediation of vulnerabilities across OpenAI's infrastructure, cloud, Kubernetes, web apps, and attack surface. Requires deep offensive security expertise, agent/systems building experience, and strong production engineering skills at Staff-Principal level.
Senior individual contributor owning end-to-end product security for DoD autonomous systems programs. Leads RMF/ATO processes, defines security architecture and requirements for hardware/software (including air-gapped/embedded), performs threat modeling, STIG compliance, and supply-chain security.
Lead security assessments, threat modeling, and vulnerability operations for Cloudflare's core products. Drive AI-powered automation for triage and workflows while mentoring teams in large-scale distributed environments.
Develop containerized microservices in Go for a multi-tenant cloud security platform that processes real-time cloud telemetry to deliver insights and risk minimization. Own full SDLC, design, operations, and mentoring while partnering with Product on requirements.
Security GRC Program Manager serving as primary interface between Stripe's Security team and external auditors/regulators. Manage audits, maintain evidence repository, perform risk/control assessments across global frameworks, and support compliance initiatives.
Senior Advisor on the Security & Risk team responsible for incident response, operating and tuning detection tooling, applying Zero Trust and identity controls, and enabling secure product development in cloud and on-prem environments. Requires 6+ years cybersecurity operations experience, strong IAM/Zero Trust knowledge, and cloud security hands-on expertise.
The Senior Application Security Engineer builds security tooling and production code, embeds secure-by-design practices, leads threat modeling, and protects AI-integrated features. The role requires strong web application security, software engineering, CI/CD security, AWS, and infrastructure-as-code experience.
Conduct original research on AI security, privacy, and threat modeling for frontier intelligence systems. Translate advances into practical defenses, publish at top venues, and partner with engineering to ship hardened features. Requires PhD and publications in security conferences.
Conducts data-driven research into emerging cloud threats and builds high-fidelity security detections for production. Requires 6+ years of security or threat research experience, strong investigation skills, and proficiency in Python, Go, and query languages.
Leads physical and corporate security operations for the Paris office, supports Brussels, and coordinates regional coverage across Europe. The role requires 8+ years of operational security experience, strong incident management and vendor oversight capabilities, and professional English; French is preferred.
Senior engineer on Trust and Safety team building and maintaining abuse prevention systems, anomaly detection, and agentic AI tools for the GitLab SaaS platform. Requires strong Ruby/Rails software engineering background; security experience preferred but not required.
Early-career SOC Analyst monitoring and triaging security alerts with SIEM, EDR, and IDS/IPS tools in a cloud environment. Requires 1-2 years experience, foundational security knowledge, and strong analytical skills; preferred scripting and certifications.
Staff Security Engineer who owns security problems end-to-end by identifying real risks, building direct controls, secure-by-default libraries, guardrails, and tooling. Requires 7+ years software engineering experience plus deep security expertise in threat modeling, auth, OWASP, cloud, and supply chain security. Healthcare/HIPAA/HITRUST and GCP experience preferred.
Own and scale Mozilla's web bug bounty program as the primary interface with external researchers. Lead triage, validation, remediation of reports, collaborate with SIRT on incidents, perform code reviews, and drive secure development improvements. Requires 3+ years security engineering experience and bug bounty or bug hunting background.
Build and operate customer-facing application security capabilities for a SaaS company, including identity, access control, security tooling, threat modeling, and incident response. The role partners closely with engineering teams and helps secure AI-powered products and development workflows.
Secures AWS cloud environments and production systems by designing controls, building detection and automation capabilities, and leading incident response. The role requires hands-on cloud security, programming, infrastructure-as-code, and investigation experience.
Lead and develop a lean security engineering team as a technical player-coach. Define and drive security strategy, compliance (SOC2, CIS, GDPR), tooling integration, incident response, and AI/ML risk governance in a high-velocity, non-regulated environment.