Senior Security Engineer
Job description
About the role
Everlaw seeks a Senior Security Engineer to safeguard customer data and make secure design choices default across the platform. In this capacity, you own the design and execution of security controls that protect sensitive legal and investigative data throughout the software lifecycle. You will build and maintain the tools that embed security directly into platform delivery, ensuring that secure development becomes the default mode of operation for every engineering team. Your work will guide architects and engineers toward resilient designs that reduce future rework and technical debt. You will expand and tune security controls to proactively reduce risk exposure and enforce a stronger security posture across distributed systems. You will prioritize security outcomes so that remediation aligns precisely with business needs and risk tolerance. You will contain threats, drive recovery of normal operations, and prevent recurrence through triaged security events and managed incident response with clear communication to stakeholders.
Key facts
What you'll do
Built tools and integrated workflows embed security into platform delivery, scaling the secure software development lifecycle (SSDLC).
A team of security engineers is led to design, implement, and maintain these tools, ensuring consistent and efficient protection of customer data.
Findings from these activities guide architects and engineers toward designs that reduce future rework and technical debt.
Controls are expanded and tuned to reduce risk exposure and enforce stronger security postures across cloud and on-premises environments.
Implementation of these standards is driven to streamline secure operations and remove friction from development workflows.
Security outcomes are prioritized to align remediation with business needs, risk appetite, and regulatory obligations.
Threats are contained, normal operations are recovered, and recurrence is prevented through triaged security events and managed incident response.
Clear communication keeps stakeholders informed of status, remediation plans, and outcomes in a language that non-technical audiences can understand.
You will conduct threat modeling and security reviews to identify weaknesses before adversaries can exploit them.
You will evaluate new technologies and third-party services to ensure they meet security standards before integration.
You will collaborate with compliance stakeholders to ensure that security controls satisfy legal, regulatory, and contractual requirements.
You will analyze telemetry and logs to detect indicators of compromise and drive improvements to detection rules.
You will mentor junior engineers and developers on secure coding practices and operational security hygiene.
You will participate in on-call rotations to respond to security incidents and provide timely guidance during critical events.
Requirements
The posting states a pay range of $215000 to $272000.
You have at least 4 years of professional experience in dedicated security engineering roles.
You possess strong programming and automation skills in at least one scripting language, such as Python.
You have a keen analytical eye for identifying software and cloud infrastructure vulnerabilities and a drive to resolve them.
You communicate technical security concepts clearly without jargon and partner collaboratively to solve problems without blocking development velocity.
You understand effective operational security processes and how to design practical safeguards for distributed systems.
You are authorized to work in the United States without restrictions, noting Everlaw is not sponsoring F-1 visas, including OPT, for this role.
You hold a Bachelor's degree or equivalent professional experience that demonstrates mastery of the required skills.
You are capable of managing multiple priorities in a fast-paced environment while maintaining a high standard of accuracy.
You are comfortable working with stakeholders across engineering, product, and compliance organizations.
Nice to have
Experience securing SaaS platforms, distributed systems, or large-scale data architecture is valued.
Proficiency in a compiled language such as Java is a bonus.
Hands-on experience with AWS infrastructure and modern DevOps and automation tools like Terraform, Ansible, and Git is beneficial.
Practical notes
Everlaw is an equal opportunity employer and respects requests for pronouns.
Typical interview steps
Security interviews usually include a technical assessment, a threat modeling exercise, and behavioral rounds. Candidates may be asked to review a code sample for vulnerabilities or design a secure system. Practical knowledge and clear risk communication are the core skills. Interviewers often ask how you triage and communicate risk. Showing calm judgment under pressure matters as much as technical depth.
Good to know
Security engineers commonly design and implement controls to protect customer data in regulated environments.
The role involves working with cloud platforms, secure software development, and incident response.
Automation and scripting skills help streamline security workflows and reduce manual effort.
Collaboration with engineering and compliance teams is typical to align on risk and remediation.
Understanding of SaaS security and modern DevOps practices supports effective protection of cloud-based services.
Career growth
Security careers grow from analyst or engineer to senior, staff, and leadership roles. Specializations include cloud security, application security, and security operations. Certifications help early; demonstrated impact matters later. Security careers reward specialization and a track record of finding and fixing real issues. Written communication of risk is a core skill at senior levels.
About the company
Looking for a remote job? Remote OK® is the #1 Remote Job Platform and has 1,131,503+ remote jobs as a Developer, Designer, Copywriter, Customer Support Rep, Sales Professional, Project Manager and more! Find a career where you can work remotely from anywhere.