Senior Security Engineer
Job description
Senior Security Engineer at Seesaw
About the role
Seesaw is seeking a seasoned security professional with a strong software engineering background to guide our security strategy and implementation. This role involves hands-on coding, architectural review, and embedding security best practices across our product and infrastructure. You will be a key partner, ensuring security is a shared responsibility throughout the organization.
Key facts
What you'll do
Shape and advance the company's overall security strategy and posture.
Act as the primary internal resource for security best practices and risk assessment.
Collaborate across engineering, product, IT, and legal departments to integrate security into all aspects of the business.
Lead threat modeling, secure code evaluations, and architectural reviews.
Establish and enforce secure coding standards and manage vulnerability remediation.
Drive the adoption of security tools such as SAST, DAST, and SCA.
Develop and maintain security automation, tooling, and infrastructure as code.
Implement security measures for applications, APIs, and infrastructure.
Work with engineering teams on authentication, authorization, and data protection.
Manage vulnerability scanning, patching, and incident response procedures.
Enhance cloud security controls, including IAM, networking, secrets management, and monitoring.
Integrate security into CI/CD pipelines and automate security checks.
Assist Legal in creating and updating security policies and standards.
Support compliance initiatives like SOC 2 and ISO 27001.
Stay informed about evolving regulatory requirements.
Requirements
A minimum of 7 years of experience in hands-on software engineering.
Substantial experience in application security, including threat modeling, code review, and SDLC integration.
Proven experience securing cloud environments (AWS, GCP, or Azure), with expertise in IAM and networking.
Demonstrated ability to contribute strategically while also performing hands-on technical work.
Excellent communication skills, with the ability to explain complex security concepts clearly and provide actionable guidance.
Nice to have
Experience with compliance frameworks such as SOC 2 and ISO 27001.
Familiarity with security technologies including SAST, DAST, SCA, SIEM, and vulnerability management tools.
Experience building security programs within startup or rapidly growing companies.
Relevant security certifications like CISSP, CCSP, CSSLP, or OSCP.
Skills & tools
AWS, GCP, or Azure
IAM
Networking
SAST, DAST, SCA
SOC 2, ISO 27001
CI/CD
Infrastructure as Code
Practical notes
Benefits include medical, dental, vision coverage, 401k match, flexible paid time off, monthly technology stipend, home office setup stipend, professional development stipend, paid parental leave, charitable donation matching, and volunteer days. The company participates in E-Verify.