Senior Security Engineer
Job description
About the role
You will define and evolve product security architecture for Valon's multi-tenant SaaS platform, shaping how security is designed, built, and scaled across our infrastructure and customer-facing capabilities. You will support the secure implementation of customer-facing security features such as authentication, authorization, identity integration, access controls, audit and logging, and encryption or key management. In this role, you will build and maintain security reference architectures and standardized secure design patterns that product teams rely on to deliver safe experiences. You will lead threat modeling, security design reviews, and code reviews for new features, services, and major architectural changes across the platform. You will design and build AI-assisted workflows that automate and accelerate product security tasks while evaluating AI risks across internal and external applications. You will collaborate closely with Product, Engineering, Data, Compliance, Legal, and other teams to identify and drive mitigation for product and data security risks. You will support vulnerability triage, remediation strategy, and root cause analysis for product security issues to reduce risk and improve resilience.
Key facts
What you'll do
- Define and evolve product security architecture for Valon's multi-tenant SaaS platform.
- Support secure implementation of customer-facing security capabilities in conjunction with Engineering, including authentication, authorization, identity integration, access controls, audit and logging, encryption, and key management.
- Build and maintain security reference architectures and standardized secure design patterns for product teams.
- Lead threat modeling, security design reviews, and code reviews for new features, services, and major architectural changes.
- Design and build AI-assisted workflows that automate and accelerate product security areas.
- Evaluate AI risks across internal and external applications.
- Collaborate with Product, Engineering, Data, Compliance, Legal, and other teams to identify and drive mitigation for product and data security risks.
- Support vulnerability triage, remediation strategy, and root cause analysis for product security issues.
- Support security compliance and regulatory needs, including SOC 2, CCPA, NYDFS, FTC, and customer-facing security discussions and due diligence.
- Develop, implement, and enforce security policies, standards, and procedures across the organization.
- Support operational activities including security advisory and consultative reviews, incident response, issue remediation, and other security processes.
- Partner with external security auditors, pentesting firms, and partners to continuously evaluate Valon's security posture.
- Leverage AI tools to optimize security and defense capabilities within cloud environments and SaaS platforms.
- Ensure security controls are integrated into CI/CD pipelines and infrastructure as code practices for consistent enforcement.
Requirements
You must have focused experience in product security, application security, or security architecture roles, with ownership of security design for SaaS platforms including multi-tenancy and customer-facing security capabilities. You must possess a strong background in cloud security and modern infrastructure, with hands-on experience securing cloud environments, and GCP experience is preferred. You must have deep expertise in SaaS IAM and tenant security, including authentication and authorization models, identity integration, RBAC, SSO via SAML and OIDC, SCIM, MFA, audit logs, and secure session management. You must demonstrate the ability to build and maintain security reference architectures that are scalable, repeatable, and aligned with industry best practices. You must have strong experience designing secure platform controls, including APIs, service-to-service authentication, encryption, key management, CMEK, logging, and monitoring across distributed systems. You must have a proven track record of collaborating with cross-functional stakeholders to identify, assess, and mitigate security and data risks in fast-paced, regulated environments. You must be comfortable working with compliance frameworks such as SOC 2, CCPA, NYDFS, and FTC, and you must be able to articulate security posture to both technical and executive audiences during customer and audit interactions. You must be able to work fully remote from the United States in the designated locations and comply with Valon's policies for remote work arrangements. You must be available to work during normal business hours to support collaboration across global teams and respond to security incidents as needed.
Practical notes
This role is remote within the United States, and normal business hours are expected for collaboration across global teams.