Senior Security Engineer
Job description
About the role
The team seeks a Senior Security Engineer to define and execute security strategy. This role strengthens Levelpath security posture and protects customer trust.
Security professionals protect systems, data, and users. They review code, run tests, monitor threats, and respond to incidents. The field spans application security, infrastructure security, and governance. Security work is careful, evidence based, and constantly evolving. Security teams work in a landscape of constant change, with new threats and new rules every year. Most companies invest heavily in training and tooling for their teams.
Key facts
What you'll do
Frameworks are established and internal policies are shaped to guide security and compliance expectations.
Incident response efforts are driven and investigations of potential breaches are led to contain impact.
Vulnerability assessment workflows are managed and mitigation planning is overseen to reduce exposure.
Security architecture is reviewed and data flows are mapped from a risk and compliance perspective to align with business objectives.
The bug bounty program is managed and coordination with external researchers is handled to improve platform integrity.
Requirements
Experience in leading cybersecurity programs at a tech-focused organization is required to provide strategic direction.
Understanding of security operations, tooling, and secure development life cycles must be demonstrated in practice.
Knowledge of regulatory frameworks and audit practices (SOC 2, ISO 27001, GDPR, etc.) is necessary for compliance alignment.
Hands-on experience with industry-standard tools and platforms (e.g., Vanta, CrowdStrike, Splunk, Rapid 7, Snyk) is required to perform investigations and monitoring.
Communication during customer security reviews must be clear and complex concepts need to be conveyed effectively.
The ability to collaborate effectively within a team and also drive initiatives to completion independently is required.
English communication skills, both verbal and written, must be excellent to ensure clarity across stakeholders.
Collaboration within a team is expected while supporting each other to maintain a strong security culture.
Practical notes
The team currently uses Slack, Zoom, Github, AWS, and allows tools that enable high-quality work. Typical interview steps
Security interviews usually include a technical assessment, a threat modeling exercise, and behavioral rounds. Candidates may be asked to review a code sample for vulnerabilities or design a secure system. Practical knowledge and clear risk communication are the core skills. Interviewers often ask how you triage and communicate risk. Showing calm judgment under pressure matters as much as technical depth.
Good to know
Security professionals operate with frameworks, tools, and audits to protect digital assets. Teams rely on shared responsibility and continuous learning to keep systems resilient. Clear communication and structured risk assessments help stakeholders make informed decisions.
Questions to ask
Useful questions for the interview: what a typical week looks like, how work is assigned, what tools the team uses, and how feedback works. Asking how the role has changed recently and what the team wishes it had known when joining is also reasonable. Questions about the manager's priorities are especially valued.
Career growth
Security careers grow from analyst or engineer to senior, staff, and leadership roles. Specializations include cloud security, application security, and security operations. Certifications help early; demonstrated impact matters later. Security careers reward specialization and a track record of finding and fixing real issues. Written communication of risk is a core skill at senior levels.
About the company
Founded in 2022 and backed by some of the top venture capital firms in the Silicon Valley, Levelpath is on a mission to revolutionize the modern procurement software industry and make it delightful. No matter the business size or needs, our platform simplifies the procurement process for everyone in the organization, making enterprises faster, safer, and more transparent.