Senior Security Engineer
Job description
About the role
Later is the world's most intelligent influencer marketing company, built to give brands the confidence to create unforgettable campaigns. By combining real creator relationships, trusted intelligence, and expert guidance, Later removes fear and guesswork from one of marketing's most visible investments. The Senior Security Engineer will own the design and implementation of security initiatives that protect Later's platforms, data, and operations while enabling business growth. This role requires a blend of deep security expertise and strong software engineering skills to build practical, scalable, and auditable security solutions. You will own key security programs including application security, cloud and infrastructure security, vulnerability management, and compliance enablement across corporate systems and business operations. You will partner closely with teams across Engineering, Infrastructure, Product, IT, Legal, People, Finance, and other business functions to embed security into Later's systems, tools, workflows, and operating practices.
Key facts
What you'll do
Assess and continuously improve Later's overall security posture across applications, infrastructure, cloud environments, corporate systems, vendor tooling, and business workflows.
Define and implement scalable security standards, best practices, and guardrails that support SOC 2 readiness through practical, automated, and auditable solutions.
Partner with Engineering, Infrastructure, IT, Product, Legal, People, Finance, and business leaders to align security priorities with company goals, risk reduction, and delivery timelines.
Translate SOC 2 and related compliance requirements into sustainable technical and operational controls, procedures, and evidence collection practices.
Identify security gaps across the company, prioritize remediation efforts, and help teams make pragmatic, risk-based decisions.
Support company-wide security awareness, secure operating practices, and adoption of security controls across business teams.
Build and maintain internal security tools, automation, and services that support secure development, compliance workflows, vulnerability management, corporate security operations, and operational visibility.
Design and implement security controls within CI/CD pipelines, including secure build and deploy patterns, security scanning, dependency management, container scanning, and secret management.
Support application security efforts, including secure design reviews, threat modeling, code review guidance, API security, microservices security patterns, and remediation planning.
Improve cloud infrastructure and corporate systems security through hardening, monitoring, configuration review, Infrastructure-as-Code security scanning, access reviews, and secure operational patterns.
Collaborate with technical and business teams to identify vulnerabilities and control gaps, explain impact clearly, and drive effective remediation.
Strengthen security observability and response readiness through logging, alerting, monitoring, and incident response playbooks that support timely detection and resolution.
Contribute to security architecture decisions for new and existing systems, ensuring that security is considered throughout the lifecycle from design to operation.
Serve as a subject matter expert and advocate for security practices, mentoring other engineers and stakeholders to build a strong security culture at Later.
Requirements
Demonstrate experience as a security engineer, application security engineer, or similar role with a strong track record of improving security posture in a SaaS or technology environment.
Bring proven experience in application security, including secure coding practices, threat modeling, code review, and common web application vulnerabilities.
Showcase deep knowledge of cloud and infrastructure security, including Identity and Access Management (IAM), network security, monitoring, logging, and hardening of cloud environments.
Illustrate experience with vulnerability management programs, including discovery, assessment, prioritization, and remediation tracking and verification.
Provide evidence of working with compliance frameworks such as SOC 2, ISO 27001, or similar, including translating requirements into technical controls and evidence collection.
Exhibit strong collaboration and communication skills, with the ability to influence both technical and non-technical stakeholders across a global organization.
Display proficiency with security tools and workflows, including static and dynamic application security testing, dependency scanning, container security, SIEM or log analysis, and security orchestration.
Have a strong software engineering background, with the ability to design, build, and maintain security tooling and integrations using modern development practices.
Nice to have
Experience with modern cloud platforms such as AWS, Azure, or GCP and their security services.
Familiarity with infrastructure-as-code tools such as Terraform or CloudFormation with a focus on security and compliance.
Knowledge of container orchestration platforms such as Kubernetes and related security controls.
Experience with security observability, incident response, and security monitoring practices.
Understanding of marketing technology ecosystems and influencer marketing domain concepts.
Practical notes
This is a full-time position eligible for remote work within the United States and Canada.
Travel is not required for this role.
Visa sponsorship may be considered for eligible candidates in locations where Later sponsors visas.
The compensation range for this role is $180,000.00 - $220,000.00, subject to location and experience.