Staff Security Engineer
Job description
About the role
You will lead security architecture and design reviews across applications, infrastructure, and integrations to ensure secure patterns are embedded early in the development lifecycle. You will conduct and coordinate penetration testing, threat modeling, and security reviews for critical services, new features, and third-party integrations. You will design and implement security automation within CI/CD pipelines to ensure secure coding practices and infrastructure policies are enforced at scale. You will partner with infrastructure and DevOps teams to secure cloud platforms, specifically AWS, and improve identity, network, and workload security. You will build security observability and detection capabilities, including security data pipelines, SIEM integrations, and threat intelligence signals. You will think like an attacker to identify systemic weaknesses and design controls that protect against entire classes of attacks, not just individual vulnerabilities. You will work closely with developers to improve security practices through secure architecture guidance, code review support, and developer enablement.
Key facts
What you'll do
- Orchestrate security architecture assessments and design validation for new products and platform changes, ensuring alignment with industry standards and regulatory expectations.
- Execute complex penetration testing campaigns and coordinate strategic threat modeling sessions to uncover hidden risks before they reach production environments.
- Engineer and maintain security automation workflows embedded within CI/CD pipelines to enforce policy as code and secure configuration benchmarks across all environments.
- Collaborate with infrastructure and DevOps specialists to harden AWS cloud environments, focusing on identity management, network segmentation, and workload protection.
- Construct and evolve security observability frameworks, including SIEM data pipelines, threat intelligence integrations, and anomaly detection mechanisms.
- Analyze adversarial tactics and techniques to model sophisticated attackers, designing layered defenses that mitigate broad classes of infrastructure and application vulnerabilities.
- Partner with software development teams to integrate secure coding practices, providing guidance during code reviews and architecture refinement sessions.
- Lead incident response investigations from initial detection through containment and remediation, driving improvements in detection and response playbooks.
- Manage the bug bounty program end-to-end, including triage, vendor communication, and optimization of vulnerability management processes.
- Author security standards, operational playbooks, and training curricula to enable engineering teams to adopt secure practices efficiently.
- Define and prioritize the security roadmap, identifying high-impact initiatives that improve risk posture while increasing engineering productivity.
- Evaluate and integrate security tooling, ensuring platforms, pipelines, and monitoring systems operate effectively at scale.
Requirements
You possess a deep understanding of application security, cloud security, and modern threat landscapes, including common vulnerabilities and attack techniques such as OWASP Top 10 and MITRE ATT&CK frameworks. You have a strong software engineering background with experience writing production-grade code or automation using languages such as Python, Typescript, or similar. You have hands-on experience securing cloud-native infrastructure, particularly within AWS, including identity and access management, networking controls, and containerized workloads. You have experience building or integrating DevSecOps pipelines, utilizing SAST, DAST, Infrastructure as Code scanning, and container security tooling to enforce security at every stage. You have practical experience designing security telemetry pipelines using SIEM platforms, observability systems, or data lakes to derive actionable insights. You have experience running or participating in penetration testing, threat modeling, or architectural security reviews to validate system designs. You collaborate effectively with engineering, DevOps, and product teams, influencing secure design decisions and fostering cross-functional alignment. You communicate complex security risks and trade-offs clearly to both technical and non-technical stakeholders, ensuring alignment across diverse audiences. You understand SaaS architectures, distributed systems, and internet-facing platforms, allowing you to design security controls appropriate for scalable, resilient environments. You have experience developing security frameworks aligned with CIS benchmarks, NIST, or SOC2 / PCI / HIPAA compliance requirements to support audit and risk management processes. You have experience building security detections, threat intelligence pipelines, or runtime protection mechanisms to detect and respond to malicious activity. You have hands-on experience with Kubernetes, container security, and infrastructure-as-code tools such as Terraform and Ansible to automate and secure cloud environments.
Practical notes
The role is fully remote with no specified hours, travel requirements, visa restrictions, or application deadlines provided in the source material.