Talent.com
Sr. Security Engineer

Sr. Security Engineer

Veza Technologies, Inc.San Francisco, CA, United States
13 hours ago
Job type
  • Full-time
Job description

Overview

As a Sr. Security Engineer, you will play a key role in advancing our secure-by-design and privacy-by-design practices. You will collaborate closely with Engineering, DevOps, and SRE teams to embed security throughout the development lifecycle, manage security tooling, identify and mitigate risks, and ensure compliance with industry standards. This is a hands-on technical role requiring both depth in security engineering and strong collaboration across teams.

Key Responsibilities

Application & Cloud Security

  • Define and monitor standards for the operation, administration, and continuous improvement of AppSec and CloudSec tools, including WAFs, SAST, DAST, SCA, IaC / container scanners, and CNAPP platforms.
  • Perform threat modeling, architecture reviews, and source code assessments to identify and mitigate risks.
  • Drive secure-by-design patterns across services, APIs, and infrastructure - including encryption, key management, secrets handling, and secure protocol design.
  • Partner with product and engineering teams to review plans, designs, and code for security considerations.
  • Guide cloud hardening across AWS (and optionally Azure / GCP) environments using IaC templates, guardrails, and CSPM / CNAPP controls.
  • Maintain and update dependencies, container images, and libraries to reduce exposure.

DevSecOps Enablement

  • Integrate and automate security tooling (SAST, DAST, SCA, IaC scanning, SBOM generation) within CI / CD pipelines.
  • Develop scripts and automations (e.g., Python, Bash, Terraform, REST APIs, GitHub Actions, or GitLab CI) to streamline scanning, reporting, and provisioning.
  • Establish security metrics, KPIs, and dashboards to measure program maturity and remediation progress.
  • Support the design and implementation of secure pipelines and infrastructure automation in collaboration with DevOps teams.
  • Vulnerability & Incident Management

  • Triage vulnerabilities across multiple sources (SAST / DAST / SCA / IaC / API / CSPM), manage false positives, and ensure clear audit trails for exceptions.
  • Serve as first-line triage for Responsible Disclosure submissions - reproduce issues, assign owners, and track SLAs to closure.
  • Support compliance and audit activities with documentation of logging, monitoring, SBOMs, and vulnerability reporting.
  • Continuously monitor emerging threats, maintain a security issue register, and report status to leadership.
  • Security Architecture & Program Maturity

  • Collaborate across teams to establish and maintain a roadmap for the Application and Cloud Security programs, continuously evolving capabilities and controls.
  • Influence engineers and architects to adopt consistent security patterns, frameworks, and templates.
  • Develop and maintain documentation, threat models, and diagrams (data flow, network) for technical and business stakeholders.
  • Evaluate new security tools and technologies for alignment with organizational needs.
  • Qualifications

    Minimum

  • 3+ years of experience in Security Engineering, Cloud, or App Security roles.
  • Proficiency with modern SDLC and DevSecOps practices in cloud-native environments (microservices, containers / Kubernetes, serverless, IaC).
  • Hands-on experience operating and tuning AppSec tools (SAST, DAST, SCA, IaC / container scanning, CNAPP, WAF).
  • Strong understanding of cloud architecture, networking, and security (Strong AWS experience require).
  • Experience with IaC (Terraform, CloudFormation) and CI / CD tools (GitHub, GitLab, CircleCI).
  • Familiarity with frameworks and standards such as OWASP Top 10, ASVS, NIST SSDF, CIS Benchmarks, ISO 27001, SOC 2.
  • Scripting / automation skills (Python preferred).
  • Excellent communication and collaboration skills with the ability to simplify technical risk for diverse audiences.
  • Preferred

  • WAF engineering experience (policy tuning, bot mitigation, blue / green rollout).
  • Familiarity with software supply chain security (SBOMs, signing, provenance).
  • Experience securing APIs and containerized workloads.
  • Certifications such as CISSP, CSSLP, GWAPT, GCSA, or Cloud Security certifications (AWS / GCP / Azure).
  • Bachelor's degree in Computer Science, Engineering, or related field.
  • The compensation for this role depends on several factors such as the candidate's skills, qualifications, experience, and work location. For candidates offered a position at the posted job level, the provided range is the expected base salary. This does not include any additional variable compensation, such as commission.

    Compensation Disclosure

    $154,000-$210,000 USD

    Our Culture

    We're driven to build a strong company culture and are looking for individuals with solid alignment with the following :

  • Ownership Mindset
  • Act with Integrity
  • Guardians of our Customers
  • Opinionated Humility
  • Build Trust, Earn Trust
  • At Veza, your base pay is one part of your total compensation package. For this position, the reasonably expected pay range can be discussed with your recruiter for the level at which this job has been scoped. Your base pay will depend on several factors, including your experience, qualifications, education, location, and skills. In the event that you are considered for a different level, a higher or lower pay range would apply. This position is also eligible for equity and a competitive benefits package.

    Veza is proud to be an equal opportunity employer. We are committed to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, veteran status, or other applicable legally protected characteristics. We also consider qualified applicants according to applicable federal, state, and local laws. If a candidate with a disability requires an accommodation during the recruitment process, please email recruiting@veza.com

    About Veza

    Veza is the identity security company. Identity and security teams use Veza to secure identity access across SaaS apps, on-prem apps, data systems, and cloud infrastructure. Veza solves the blind spots of traditional identity tools with its unique ability to ingest and organize permissions metadata in the Veza Authorization Graph. Global enterprises like Blackstone, Wynn Resorts, and Expedia trust Veza to visualize access permissions, monitor permissions activity, automate access reviews, and remediate privilege violations. Founded in 2020, Veza is headquartered in Redwood City, California, and is funded by Accel, Bain Capital, Ballistic Ventures, GV, Norwest Venture Partners, and True Ventures. Visit us at veza.com and follow us on LinkedIn, Twitter, and YouTube.

    Create a job alert for this search

    Sr Security Engineer • San Francisco, CA, United States

    Related jobs
    • Promoted
    • New!
    Senior / Staff Enterprise Security Engineer

    Senior / Staff Enterprise Security Engineer

    AbridgeSan Francisco, CA, United States
    Full-time
    Senior Or Staff Enterprise Security Engineer.Want to work on building out security from the ground up at the leading edge of AI in healthcare globally? We're looking for a very experienced and high...Show moreLast updated: 13 hours ago
    • Promoted
    • New!
    Offensive Security Engineer, Hardware

    Offensive Security Engineer, Hardware

    OpenAISan Francisco, CA, United States
    Full-time
    Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI's technology, people, and products.We are...Show moreLast updated: 14 hours ago
    • Promoted
    • New!
    Sr. Security Engineer - GTM Partnership

    Sr. Security Engineer - GTM Partnership

    ZapierSan Francisco, CA, United States
    Full-time
    Were humans who simply think computers should do more work.At Zapier, were not just making softwarewere building a platform to help millions of businesses globally scale with automation and AI.Our ...Show moreLast updated: 14 hours ago
    • Promoted
    • New!
    Sr. Security Engineer

    Sr. Security Engineer

    IBM ComputingSan Francisco, CA, United States
    Full-time
    A career in IBM Software means you'll be part of a team that transforms our customer's challenges into industry-leading solutions. We are an infinitely curious team, always seeking new possibilities...Show moreLast updated: 14 hours ago
    • Promoted
    Principal Cyber Security Engineer

    Principal Cyber Security Engineer

    Cloud Software Group, Inc.San Ramon, CA, United States
    Full-time
    Architectural Leadership : Design, develop, and maintain the comprehensive security architecture for Cloud Software Group's products and corporate infrastructure. Cloud Security Expertise : Lead the s...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Sr. Security Engineer, eero, eero Security

    Sr. Security Engineer, eero, eero Security

    AmazonSan Francisco, CA, United States
    Full-time
    At eero, our mission is to serve as the central nervous system of the home.While we began by revolutionizing home WiFi, we now create comprehensive and secure solutions that serve both wireless and...Show moreLast updated: 14 hours ago
    • Promoted
    • New!
    Sr Security and Compliance Engineer

    Sr Security and Compliance Engineer

    Broadcom CorporationPalo Alto, CA, United States
    Full-time
    If you are a first time user, please create your candidate login account before you apply for a job.If you already have a Candidate Account, please Sign-In before you apply.Broadcom seeks an experi...Show moreLast updated: 13 hours ago
    • Promoted
    • New!
    Sr. Security Research Engineer

    Sr. Security Research Engineer

    ProofpointSan Francisco, CA, United States
    Full-time
    We are the leader in human-centric cybersecurity.Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to stay ahead...Show moreLast updated: 13 hours ago
    • Promoted
    • New!
    Security Engineer - Hybrid

    Security Engineer - Hybrid

    Workers' Compensation Insurance Rating Bureau of CaliforniaSan Francisco, CA, United States
    Full-time
    For over a century, the Workers' Compensation Insurance Rating Bureau of California (WCIRB) has been California's trusted, objective provider of actuarially based information and research, advisory...Show moreLast updated: 12 hours ago
    • Promoted
    • New!
    Senior Security Engineer

    Senior Security Engineer

    Arta FinanceMountain View, CA, United States
    Full-time
    Arta is on an audacious and incredibly rewarding mission : to pave the way for people everywhere to lead more successful financial lives. Arta leverages AI and sophisticated digital toolsonce reserve...Show moreLast updated: 14 hours ago
    • Promoted
    • New!
    Security Engineer

    Security Engineer

    Modular ServicesLos Altos, CA, United States
    Full-time
    At Modular, we're on a mission to revolutionize AI infrastructure by systematically rebuilding the AI software stack from the ground up. Our team, made up of industry leaders and experts, is buildin...Show moreLast updated: 14 hours ago
    • Promoted
    Security Engineer

    Security Engineer

    Mercor IncSan Francisco, CA, United States
    Full-time
    Mercor is at the intersection of labor markets and AI research.We partner with leading AI labs and enterprises to provide the human intelligence essential to AI development.Our vast talent network ...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    JobotDaly City, CA, US
    Full-time
    Senior Security Engineer Opportunity.This Jobot Job is hosted by : Charles Simmons.Are you a fit? Easy Apply now by clicking the "Apply Now" button and sending us your resume.Salary : $120,000 - $160...Show moreLast updated: 9 days ago
    • Promoted
    Sr. Security Engineer, Kuiper Security, Kuiper Security

    Sr. Security Engineer, Kuiper Security, Kuiper Security

    AmazonSan Francisco, CA, United States
    Permanent
    We are open to hiring candidates to work out of one of the following locations : .Arlington, VA, USA | Redmond, WA, USA | San Francisco, CA, USA | Sunnyvale, CA, USA. Project Kuiper is an initiative t...Show moreLast updated: 30+ days ago
    • Promoted
    Sr. Security Manager

    Sr. Security Manager

    SupermicroSan Jose, CA, United States
    Full-time
    Supermicro is a Top Tier provider of advanced server, storage, and networking solutions for Data Center, Cloud Computing, Enterprise IT, Hadoop / Big Data, Hyperscale, HPC and IoT / Embedded customers...Show moreLast updated: 20 days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Hayden AISan Francisco, CA, United States
    Full-time
    At Hayden AI, we are on a mission to harness the power of computer vision to transform the way transit systems and other government agencies address real-world challenges.From bus lane and bus stop...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Security Engineer II (ML)

    Senior Security Engineer II (ML)

    Moveworks.aiMountain View, CA, United States
    Full-time
    Are you passionate about leveraging machine learning to scale-up security and privacy efforts? Do you have a keen understanding of security risks and a desire to innovate with cutting-edge ML solut...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Senior Security Engineer in San Francisco

    Senior Security Engineer in San Francisco

    Energy Jobline ZRSan Francisco, CA, United States
    Full-time
    Energy Jobline is the largest and fastest growing global Energy Job Board and Energy Hub.We have an audience reach of over 7 million energy professionals, 400,000+ monthly advertised global energy ...Show moreLast updated: 14 hours ago