Senior Security Engineer
Remote
We are seeking a Senior Security Engineer with deep expertise in vulnerability management, incident response, and cloud security to join our growing InfoSec team. This role is ideal for someone who thrives in complex, cross-functional environments and is ready to take ownership of threat detection strategy, security architecture design, and risk reduction efforts at scale. You’ll partner closely with engineering, IT, compliance, and executive stakeholders to build and maintain a security-first culture.
Responsibilities :
- Own and evolve our enterprise vulnerability management and threat detection programs across cloud and on-prem environments.
- Design and implement scalable cloud security architecture (AWS / GCP / Azure), ensuring alignment with compliance frameworks such as SOC 2, FedRAMP, PCI DSS, and NIST.
- Lead incident response efforts—from triage and investigation to root cause analysis and long-term remediation.
- Integrate and optimize SIEM platforms (Splunk or equivalent), including custom rule development and threat correlation logic.
- Collaborate across teams to support secure SDLC practices, product security reviews, and infrastructure hardening.
- Contribute to and mentor others in threat intelligence research, including malware analysis, TTP tracking, and vulnerability exploitation trends.
- Evaluate new security tools, manage vendor relationships, and drive budget-conscious tooling decisions.
- Champion automation of security operations using scripting languages (Python, Ruby, etc.).
What You Bring :
5+ years of experience in information security with direct, hands-on experience in enterprise environments.Expertise in cloud platforms (AWS required; GCP and Azure a plus), Linux environments, and network security.Strong working knowledge of frameworks such as NIST 800-53, ISO 27001, and SOC 2.Proficiency in scripting (Python, Ruby, Perl) and use of common security tools (e.g., Splunk, Qualys, Burp Suite, Wiz).Experience leading cross-functional security projects with clear, measurable impact.Familiarity with threat intelligence sharing platforms and tools like MISP.Effective communication and project management skills, with an ability to influence technical and non-technical stakeholders.Bonus Points :
Experience in a startup or hyper-growth environment.Background in economics or data analytics to support risk quantification strategies.Contributions to open-source security projects or published security research.