Senior SecOps Engineer
Job description
About the role
Showpad security operations teams integrate protection into product and cloud infrastructure. This role enables and collaborates with Engineering, Product, and other business units to manage cybersecurity risks for Showpad. The position reports to the Engineering Manager and strengthens security outcomes across the organization.
Software engineers turn product ideas into working code. Engineers work in small teams, review each other's work, and ship in small batches. Most teams follow agile practices such as sprints and daily standups. Engineers also write tests, fix bugs, and improve performance. The field values clear communication as much as technical skill. Engineers spend part of every week on planning, code review, and debugging, not just writing new code. The ability to explain a technical decision in plain words separates strong engineers from the rest.
Key facts
What you'll do
Management of cybersecurity operations addresses application, hardware, and cloud infrastructure security to reduce organizational risk. Security tooling integrates within CI/CD processes so development teams can deliver changes securely and efficiently. Monitoring and improvement of the CNAPP solution maintain coverage for cloud assets, workloads, and responses to evolving threats. Monitoring, vulnerability assessment, and implementation of security measures protect digital assets.
Requirements
Professionals bring proven experience in information security, with a background in security operations, application security, or related roles to guide strategy and protect assets. Candidates handle identifying, analyzing, and responding to phishing attempts and other social engineering threats to protect people and data. Knowledge of modern web application security practices and frameworks designs protections for applications. Teams work with the Secure Software Development Life Cycle (SSDLC) throughout the software lifecycle to embed security into each phase of delivery. Engineers implement security automation for testing, monitoring, or orchestration workflows using TypeScript or similar languages to scale defenses and improve reliability. Engineers work with container technologies such as Docker and Kubernetes and serverless environments like AWS Lambda, securing cloud-based applications in AWS when feasible to reduce exposure. Architectures secure microservices-based systems effectively and consistently to support resilient deployments and operations. Practitioners conduct security assessments using Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) to find weaknesses and guide remediation. Teams manage vulnerabilities through bug bounty programs, penetration testing, and automated security scanning to address issues proactively and protect infrastructure. Understanding of security and privacy frameworks such as GDPR, ISO 27001, and SOC 2 is an asset to align with global regulations and compliance requirements. Communicators explain complex security concepts to both technical and non-technical audiences with strong English skills to enable clear decisions and effective coordination.
Practical notes
Onsite engagement expectations apply, and travel may be required occasionally for the role. Typical interview steps
Hiring for engineering roles usually starts with a recruiter screen, followed by one or two technical rounds. Candidates often solve a coding problem, discuss past projects, and answer system design questions. Some loops include a take-home task. Final rounds typically cover team fit and give candidates a chance to ask questions. Interviewers look for how you break down an unfamiliar problem, not just whether you reach the answer. Practicing a few problems aloud and reviewing your own past projects are the best preparation.
Career growth
Engineering careers usually progress from individual contributor to senior, staff, and principal levels. Some engineers move into management and lead teams of five to twenty people. Others stay on the technical track. Growth follows demonstrated impact, not tenure alone. A typical engineering ladder has clear levels with defined expectations for scope, quality, and mentorship. Moving up usually requires owning outcomes end to end rather than completing assigned tickets.