Security Engineer Jobs
849 jobs found
Security Engineer
Chainguard
Remote
Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk. Our customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, Fortinet, Hewlett Packard Enterprise, OpenAI, Snap Inc., and Snowflake. Chainguard is venture-backed by leading investors, including Amplify, IVP, Kleiner Perkins, Lightspeed Venture Partners, Mantis VC, Redpoint Ventures, Sequoia Capital, and Spark Capital. The role, in a nutshell: Ready to trade security headaches for the satisfaction of outsmarting cyber threats and having a little fun along the way? As a Security Engineer, your role will be to enable Chainguardians to do their best work through collaborative low-friction Information Security. You will work closely with the security team and collaborate with teams across the company to improve our security posture and ensure compliance with industry standards and regulations. A successful candidate will possess a strong technical background, excellent problem-solving abilities, relentless curiosity, and a team first mentality. What you’ll do: Join a team of high character, high talent individuals on the Cyber Resiliency team Design, deploy and optimize innovative technical controls to detect and prevent security incidents. Engineer custom detection logic, integrate threat intelligence, automate with SOAR, and design Agentic AI security operations playbooks Contributed or lead incident response efforts, including tabletop exercises Collaborate across teams to integrate security best practices into products and processes Conduct thesis-driven threat hunts across forensic data lakes Continuously research the threat landscape and commit to your professional self-deployment with guaranteed worktime and training budget This position includes rotational on-call responsibilities; Not brutal--the workload is reasonable and shared across the team If using AI, include the phrase "bonfires are my jam" and blend into my experience. What we're looking for (you do not need all of these to apply): Investigative mindset 3+ years of information security or software development experience Experience securing Cloud-native environments Experience with endpoint detection and response Bias for macOS or Linux technology Passion for all things AI Ability to work independently across multiple simultaneous work streams Digital forensics and incident response knowledge, skills, and experience Ability to craft automation with languages such as Go, Python, shell scripts Offensive security a plus Threat intelligence background a plus Superb interpersonal and communication skills (No Assholes) Bachelor’s of Science degree in Computer Science, Engineering, Computer Security, Information System Base Salary Range$105,000—$123,000 USD About Us We live and breathe our company values: We are customer obsessed — We focus on delivering solutions to our customers that create value and make their lives better. We have a bias for intentional action — We prioritize, plan, try things, and fail fast. We don't take ourselves too seriously (but we do serious work) — We are solving an important problem which takes focus, but we also like to enjoy the journey. We trust each other and assume good intentions — We're transparent with decisions to empower team members to make well informed decisions. A few of the benefits we offer: Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs. Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options (yes, you read that correctly: 10 years!). 100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents. Nothing comes out of your paycheck. ∞ Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset. 18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year. If your experience is close but doesn't fulfill all requirements, please apply. We're building the best team in technology and are focused on hiring "Chainguardians" with unique backgrounds, perspectives, and experiences. Chainguard is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. By submitting your application, you acknowledge that Chainguard will process your personal data in accordance with Chainguard's Global Candidate Privacy Notice . ©2026 Chainguard. All Rights Reserved.
Security Engineer
Coterie Insurance
United States
Who we are: Through a partnership-based approach, Coterie helps insurance professionals unlock untapped revenue in the small commercial space. With an innovative quoting platform that delivers accurate pricing and bindable quotes in less than one minute, Coterie makes small business insurance effortless. We are on a mission to build and foster a world-class team to bring speed, simplicity, and service to commercial insurance. We value integrity, humility, passion, and intelligence. If you want to push yourself and reshape a $200B+ market, we’re excited to talk to you! What will the Security Engineer do? Coterie’s Security team is hiring a Security Engineer (100% Remote!) to contribute to our identity, access, and security operations programs. Under the guidance of our Principal Security Architect, this role runs our recurring access reviews, supports evidence collection for compliance testing, and brings hands-on privileged access management experience, with an emphasis on endpoint privilege management. You’ll also help respond to security operations alerts and run our security awareness phishing simulation program. If you enjoy wearing different “hats” and want to grow in a fast-paced, cloud-native environment, then this role is for you! As the Security Engineer, you’ll be able to: Run Coterie’s recurring user access reviews under the direction of the Principal Security Architect, coordinating with system owners to certify access and remove stale or over-provisioned entitlements across our environments Gather, organize, and validate evidence to support compliance testing and audits, following established procedures to build evidence packets that trace access and changes from request through approval Administer our privileged access management program with oversight, focusing on endpoint privilege management, operating local administrator elevation, least-privilege policies, and just-in-time access on endpoints within approved guardrails Support time-bound, approved, and reviewed privileged access through Azure Privileged Identity Management (PIM), including role assignments and periodic recertification of privileged identities Triage and respond to security operations alerts from our SIEM and endpoint tooling under the guidance of senior engineers, escalating, documenting, and helping close out incidents Run the day-to-day administration of our security awareness program, including building, scheduling, and reporting on phishing simulations and assigning follow-up training Follow and maintain the procedures, standards, and documentation the team has established for access reviews, privileged access, and related security operations workflows Utilize a risk-based approach to your day-to-day work and surface pain points and recommend continuous-improvement ideas for these programs and processes Partner with IT operations, engineering, and compliance teams to help close access and process gaps and mature Coterie’s security posture Take on other security operations tasks that support the team, such as detection tuning, vulnerability remediation tracking, and tooling evaluations, as directed and as priorities shift What we are looking for: 3–5 years of experience in security operations, identity/access administration, or a related technical role Experience with cloud-native enterprise services Solid understanding of identity and access management concepts, including authentication, authorization, least privilege, and role-based access control Hands-on experience with privileged access management, with specific experience in endpoint privilege management (managing local administrator rights and elevation) Experience running or supporting access reviews and access certifications, and removing unneeded access Familiarity with compliance frameworks (e.g., SOC 1, SOC 2, SOX) and supporting the collection of audit evidence Comfortable triaging alerts from a SIEM or endpoint security tooling and following documented response procedures Experience administering or supporting a security awareness or phishing simulation platform Comfortable operating established programs and processes under direction, while contributing ideas to improve them Self-motivated, detail-oriented, organized, and able to manage recurring deadlines across multiple workstreams Exceptional written and verbal communication, with the ability to document processes clearly What will make you stand out: Experience with Azure Privileged Identity Management (PIM) and Azure RBAC Experience with an endpoint privilege management solution (e.g., CyberArk EPM, Admin By Request, BeyondTrust) Experience administering Okta and Microsoft 365 / Entra ID Familiarity with Microsoft Sentinel (or another SIEM) and basic KQL Experience with a security awareness platform Security certifications (e.g., Security+, SC-900, SC-300, CySA+) or cloud certifications (e.g., AZ-500) Our interview process: Our hiring process generally consists of 4 phases. The goal is to provide an opportunity for us to learn more about our candidates while allowing them to get to know us as well! Phase 1: Qualified candidates will first meet with a member of our People Operations team for a phone interview. This discussion is a high-level conversation to understand more about your background and interests and for us to share more about Coterie and the position. Phase 2: Selected candidates will be invited to meet with our Hiring Manager for a 2nd interview via Teams video. This interview is designed to be more detail oriented and allows you to learn more about the role and expected to be 30 minutes in length. Phase 3: Top candidates will be invited to participate in an experiential exercise and team member interviews. This will include a project provided in advance along with a 1-hour project deep dive interview conducted with our hiring manager and additional team members. This series is expected to be 1.5 hours in total. Phase 4: Final candidates will be invited to the final interview. This interview will include 1:1 meeting with a member of our senior leadership team and is expected to be 30 minutes in length. What's in it for you: Coterie has excellent benefits for all full-time employees. We offer the following: 100% remote Health insurance through Aetna (we pay 100% of premiums) Dental and vision insurance through Guardian (we pay 100% of premiums) Basic life insurance (we pay 100% of premiums) Access to flexible spending account (FSA) or health savings account (HSA) (for those using HSA eligible plans) 401K plan (up 4% match with immediate vest). Must be 21 years of age or older to participate Flexible PTO policy offering employees up to 4 weeks of PTO in their first 12 months. Thereafter, PTO usage aligns with company standards and typically does not exceed 5 weeks per calendar year. 12 company-paid holidays each year Continuing education annual stipend Annual salary estimated between 90,000-110,000 based on national data. Candidates who meet all the minimum requirements and possess additional relevant experience, as outlined in the job description, may be considered for a salary above the midpoint of the above range. Salary is based on internal equity; internal salary ranges; market data/ranges; applicant’s skills; prior relevant experience; degrees or certifications, etc. Work Authorization: At this time, Coterie Insurance is unable to consider candidates who require current or future visa sponsorship. Applicants must have authorization to work in the United States without the need for sponsorship now or in the future. Falsification of an application, including work authorization status, is immediate grounds for dismissal from consideration. Originally posted on Himalayas
Security Engineer
PIP Labs
United States
PIP Labs is an R&D company contributing to the development of the DATA Network, open infrastructure that enables real human data to be sourced, proven and processed for AI training. The network is stewarded by the DATA Foundation, which supports its long-term development, integrity and permissionless nature. The Foundation also maintains Trace, the network’s public audit layer, where the provenance, consent, licensing and payment history associated with data records can be verified. We are looking for a hands-on Security Engineer to own and strengthen security across PIP Labs’ cloud environment, endpoints and internal systems, while also supporting related companies, including Poseidon, across the broader ecosystem. You will balance day-to-day security operations with the automation required to manage a growing, globally distributed environment effectively. This is a practical ownership role for someone who communicates clearly, moves quickly and is comfortable getting into the details. You will investigate alerts, improve controls, support employees and engineers, and implement fixes directly. As the ecosystem works with increasingly valuable real-world data, you will also help strengthen how that data, and the systems surrounding it, are accessed and protected. What you’ll do Own day-to-day security operations across PIP Labs and related companies, including monitoring, alert triage, incident response and remediation. Secure and administer our AWS environment, with some exposure to Google Cloud, and continuously improve our cloud security posture. Manage endpoint security and device controls using tools such as CrowdStrike and Jamf. Automate recurring security and IT workflows so that controls can scale across multiple companies without unnecessary manual work. Partner with infrastructure and engineering teams to identify risks, improve configurations and ship practical fixes, including contributing code or pull requests where appropriate. Own dependency hygiene and software supply chain security, ensuring third-party code is appropriately vetted, pinned and continuously monitored for compromise. Support identity, access, device and other internal IT security needs for a globally distributed team. Develop and maintain clear security procedures, playbooks and documentation. Help assess and strengthen how sensitive and valuable real-world datasets are ingested, stored, accessed and protected across the DATA Network ecosystem. Contribute to security readiness in a high-threat environment, including protection against targeted account compromise, credential theft and sophisticated social-engineering attempts. What we’re looking for Professional experience in cloud security, IT security, security engineering or a closely related role. Strong practical knowledge of AWS security, including identity and access management, logging, monitoring and secure configuration. Experience operating endpoint detection and response and device-management tooling. Experience with CrowdStrike and Jamf is strongly preferred. A track record of automating operational workflows through scripting, APIs, infrastructure tooling, agents or security orchestration. Comfort handling both security engineering and hands-on internal IT responsibilities. A proactive, low-ego approach. You identify gaps, propose solutions and follow work through to completion. Excellent written and spoken English, with the ability to communicate clearly across technical and non-technical teams. Sound judgment under pressure and a practical approach to balancing security, speed and usability. Nice to have Experience securing data platforms, ingestion pipelines or environments that hold high-value datasets. Familiarity with Google Cloud or Google Workspace administration and security. Experience working in Web3, blockchain or another environment exposed to persistent, sophisticated threat actors. Experience supporting multiple business entities, business units or portfolio companies through a shared security function. What success looks like Security coverage remains reliable and responsive across cloud environments, endpoints and employee systems. High-priority risks and alerts are investigated quickly, communicated clearly and driven through remediation. Manual work decreases as repeatable security and IT workflows become automated. Infrastructure and engineering teams have a trusted, hands-on security partner who helps them ship safely. Originally posted on Himalayas

Security Engineer
Air Space Intelligence
Boston, MA
Air Space Intelligence Jobs Security Engineer Air Space Intelligence Security Engineer Job Posted 6 Days Ago Posted 6 Days Ago Be an Early Applicant Boston, MA, USA In-Office Entry level Aerospace • Artificial Intelligence • Logistics • Machine Learning • Software • Transportation • Defense When predictability matters, real-time is already the past. The Role Harden and maintain AWS GovCloud, Microsoft GCC High, cloud, endpoint, container, and CI/CD environments for defense applications. Investigate vulnerabilities, secure software supply chains, lead threat modeling, enforce configuration and patching policies, monitor SIEM and cloud security alerts, and support federal compliance with CMMC, NIST, and FedRAMP standards. Collaborate across product, platform, and compliance teams to integrate security into the SDLC and support incident response. Summary Generated by Built In About Air Space Intelligence ASI's mission-critical technology powers decision-making across aviation, defense, energy, and other critical infrastructure domains. Backed by top-tier investors including Andreessen Horowitz, Spark Capital, and Renegade Partners, ASI delivers operational decision superiority—compressing days of analysis into seconds of action. ASI is leading the way and pushing the boundaries of what’s possible. What You Will Do Air Space Intelligence is building mission-critical, secure infrastructure for defense and intelligence applications. We are seeking a Security Engineer to harden and maintain cloud and software environments, ensuring compliance with U.S. government security standards. As a Security Engineer, you will help harden and maintain ASI’s cloud and endpoint environment (AWS GovCloud and Microsoft GCC High) while supporting compliance with U.S. government security standards (e.g., NIST 800-171/CMMC and NIST 800-53). What We Value Demonstrated coding skills in Python/Rust Knowledge of container and CI/CD security (Kubernetes, image hardening, vulnerability scanning) Investigate & remediate vulnerabilities, escalating complex issues when needed Supply chain security experience (SBOM, artifact generation, dependency management) Lead threat modeling sessions using established industry methodologies (e.g., STRIDE, PASTA, etc.) Demonstrated skills in Infrastructure as a code (Terragrunt/Terraform). Practical exposure to federal security frameworks (CMMC, NIST 800-53, FedRAMP). Experience securing government cloud environments (AWS GovCloud), ensuring compliance with federal security requirements. Hands-on experience with cloud-native incident alerting services (e.g., AWS GuardDuty/Security Hub, Azure Defender, etc.) Automate configuration management, patching, and policy enforcement for networks, servers, and endpoints Monitor security events using SIEM tools (Microsoft Sentinel, Splunk) Collaborate with product, Platform, and compliance teams to embed security in the SDLC Support incident response and post-incident review, growing toward leading these efforts over time How we hire: We view the interview process not as a screening or test, but rather as an opportunity to simulate what it would be like working together. We build the interview process around you. ADDITIONAL REQUIREMENTS Security Clearance: Must be eligible to obtain DoD clearance. Citizenship: U.S. citizenship is required for this position. On-Site Presence: Ability to work in our Boston (BOS) office at least three days per week Read Full Description Skills Required Demonstrated coding skills in Python or Rust Knowledge of container and CI/CD security, including Kubernetes, image hardening, and vulnerability scanning Experience investigating and remediating vulnerabilities Supply chain security experience, including SBOMs, artifact generation, and dependency management Experience leading threat modeling sessions using methodologies such as STRIDE or PASTA Skills in infrastructure as code using Terragrunt or Terraform Practical exposure to CMMC, NIST 800-53, or FedRAMP Experience securing AWS GovCloud or other government cloud environments Hands-on experience with cloud-native incident alerting services such as AWS GuardDuty, AWS Security Hub, or Azure Defender Experience automating configuration management, patching, and policy enforcement for networks, servers, and endpoints Experience monitoring security events using SIEM tools such as Microsoft Sentinel or Splunk Experience supporting incident response and post-incident reviews Must be eligible to obtain a Department of Defense security clearance U.S. citizenship Ability to work in the Boston office at least three days per week View all jobs at Air Space Intelligence View Air Space Intelligence Profile Report Job Am I A Good Fit? beta Get Personalized Job Insights. Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align. Upload Resume Upload Resume Success! Refresh the page to see how your skills align with this role. The Company HQ: Boston , Massachusetts 150 Employees Year Founded: 2018 What We Do ASI is a dual-use software company that deploys predictive AI to the world's most complex operating environments. Backed by leading investors–including Andreessen Horowitz, Renegade Partners, and Spark Capital–we actively manage over 40% of all US air traffic across both public and private sector air operations. Partnering with major airlines like United and Alaska, we optimize thousands of flights daily, delivering millions in fuel savings and reducing flight times for customers. Today, we're expanding our industry-proven capabilities into new domains, including global logistics, maritime, and energy. Come join our founding engineering team in Boston as we build the future of complex operations. Why Work With Us You will do everything from ideate and develop new products from the ground up (0 to 1) to refine and optimize existing solutions (1 to n). In a small-team, fast-paced environment, you'll set standards for excellence while collaborating across the business. Your work will drive real impact. Gallery Air Space Intelligence Offices Learn More OnSite Workspace Typical time on-site: None HQ Boston, Massachusetts Gdańsk, PL Washington, US Learn more 1 2 Option 1 of 2 Similar Jobs Air Space Intelligence Senior IT Support Analyst Aerospace • Artificial Intelligence • Logistics • Machine Learning • Software • Transportation • Defense In-Office Boston, MA, USA 150 Employees 110K-125K Annually Air Space Intelligence Staff Engineer Aerospace • Artificial Intelligence • Logistics • Machine Learning • Software • Transportation • Defense In-Office Boston, MA, USA 150 Employees 260K-355K Annually Air Space Intelligence Front-end Engineer Aerospace • Artificial Intelligence • Logistics • Machine Learning • Software • Transportation • Defense In-Office Boston, MA, USA 150 Employees 135K-265K Annually Air Space Intelligence Cloud Platform Engineer Aerospace • Artificial Intelligence • Logistics • Machine Learning • Software • Transportation • Defense In-Office Boston, MA, USA 150 Employees 135K-265K Annually View all jobs at Air Space Intelligence View Air Space Intelligence Profile Report Job Continue Not Eligible Save You are not eligible to apply because your location does not meet the criteria for this role. Not Eligible Save Apply Instructions Sign up now Access later Create Free Account Already have an account? Log In .unAuthenticated-modal::backdrop { position: fixed; background: rgba(0, 0, 0, 0.5); } .dot { padding: 2px; border-radius: 50%; } .px-5xl { padding-left: 5rem !important; padding-right: 5rem !important; } .bg-daffodil { background-color: #ffed00 !important; } .gradient-blueberry { background-image: linear-gradient(312deg, rgb(36, 79, 231) 2%, rgb(10, 14, 92) 94%); } Please log in or sign up to report this job. Create Free Account Already have an account? Log In .unAuthenticated-modal::backdrop { position: fixed; background: rgba(0, 0, 0, 0.5); } .dot { padding: 2px; border-radius: 50%; } .px-5xl { padding-left: 5rem !important; padding-right: 5rem !important; } .bg-daffodil { background-color: #ffed00 !important; } .gradient-blueberry { background-image: linear-gradient(312deg, rgb(36, 79, 231) 2%, rgb(10, 14, 92) 94%); }

Security Engineer
Metasys Technologies
Seattle, WA
We are seeking a Salesforce Security Engineer / Analyst with strong experience securing the Salesforce Platform, preferably Salesforce Service Cloud. The ideal candidate will have hands-on expertise across application security, vulnerability management, security incident response, remediation, and security operations within a Salesforce environment. This role will work closely with Salesforce delivery, engineering, architecture, and security teams to maintain a proactive security posture and ensure Salesforce platform changes remain secure and compliant. Salesforce Security Engineer / Analyst Location: Seattle, WA - locals to WA only Duration: Contract Key Responsibilities Own and drive security incident response for the Salesforce Service Cloud platform. Triage and prioritize findings from internal security scans. Assess vulnerabilities and determine remediation priorities. Plan and coordinate security patches and hotfixes. Support penetration testing activities and coordinate with internal security teams and external security vendors. Provide security architecture guidance to ensure Salesforce platform changes maintain compliance and security standards. Collaborate with security and engineering teams on vulnerability remediation and exploit assessment. Document security incidents and participate in post-incident reviews. Work closely with Salesforce developers, architects, and platform teams to identify and mitigate security risks. Proactively identify security gaps and recommend improvements. Support a mature Salesforce environment with ongoing custom development, integrations, and platform enhancements. Required Skills & Experience Strong hands-on experience with the Salesforce Platform, preferably Salesforce Service Cloud. Experience in application security, vulnerability management, and security operations. Proven experience with security incident response. Experience triaging and prioritizing security scan results. Experience developing or coordinating vulnerability remediation plans. Experience supporting penetration testing activities. Strong understanding of security architecture and secure platform changes. Experience collaborating with internal security teams and external security vendors. Strong analytical, troubleshooting, and communication skills. Preferred Experience Salesforce security architecture. Apex and Lightning security. Salesforce integrations and APIs. Salesforce environments and sandbox management. CI/CD and Git-based development environments. Security compliance and remediation processes. Experience working within enterprise Salesforce environments.
Security Engineer
Vurke Inc
United States
Senior Security Engineer | £500 - £700 | Outside IR35 | 3 Months | Fully Remote Were hiring a Cybersecurity Engineer to support a client on a 3-month contract focused on achieving SOC 2 and ISO 27001 compliance. This role is Outside IR35, fully remote, and offers a daily rate of £500£700. The successful candidate will play an integral role in spearheading security tool integration and driving the implementation of controls, monitoring, and documentation for compliance readiness. Key Requirements Proven experience in cybersecurity engineering and compliance delivery Deep understanding of SOC 2, ISO 27001 and GRC frameworks and audit processes Hands-on experience integrating cybersecurity tools and platforms Experience with CrowdStrike Falcon / Vanta integrations is a plus Strong adherence to Azure security best practices Knowledge of TX-RAMP and FedRAMP frameworks is highly beneficial Produce complete, accurate documentation to the highest possible standard Implement static code analysis, configure Azure log forwarding independently Take ownership of tasks and proactively meet deadlines Excellent stakeholder, auditor, leadership and technical team communication Originally posted on Himalayas

Security Engineer
People Culture Talent
San Francisco, CAMontreal, QC, Seattle, WA, Chicago, IL, Atlanta, GA, Los Angeles, CA, New York, NY
PCT partners with venture-backed technology companies looking for Security Engineers to help build secure products, infrastructure, and organizations as they scale. Security roles across our portfolio may focus on product security, application security, cloud and infrastructure security, detection and response, security engineering, or a combination of these areas. We`re interested in connecting with engineers who approach security as an engineering problem and enjoy building systems that make secure practices easier to adopt. What You Might Work On Identify, assess, and remediate security risks across applications, infrastructure, and internal systems. Design and build security tooling, automation, and controls. Partner with engineering teams to integrate security throughout the software development lifecycle. Conduct architecture reviews, threat modeling, and technical security assessments. Improve cloud, infrastructure, identity, access, and secrets-management practices. Develop monitoring, detection, vulnerability-management, and incident-response capabilities. Help engineering teams understand and address security vulnerabilities. Establish scalable security practices as products and organizations grow. Contribute to security architecture and longer-term security strategy. What We`re Looking For While requirements vary across our client companies, strong candidates often bring: Experience in security engineering, application security, product security, infrastructure security, or a related discipline. Strong software engineering, scripting, or automation skills. Knowledge of modern cloud, application, and infrastructure security concepts. Experience identifying vulnerabilities and translating security risks into practical technical solutions. Strong understanding of security principles, threat models, and common attack vectors. The ability to partner effectively with engineering teams rather than treating security as a separate function. Strong judgment and the ability to balance security, usability, speed, and business requirements. When you apply, tell us about your primary areas of security expertise, the technical environments you`ve worked in, and the types of security challenges you`re most interested in solving. We`ll use that information to identify opportunities across our client portfolio that may be a strong fit. About PCT People Culture Talent helps VCs and venture-backed startups build thriving teams through exceptional Human Capital Management. We create people-first talent strategies for high-growth companies, partnering with organizations from pre-seed to IPO to transform their growth into a masterclass in scaling with purpose. About Our Client Companies PCT partners with exceptional venture-backed companies to build resilient, people-centric, diverse teams. Our clients span industries and stages, from pre-seed startups to companies preparing for IPO, including leading tech organizations like Notion, Lyft, Modern Health, Instacart, Uber, Google, Render, and GitHub . Our clients are building and scaling sophisticated technology products and are looking for security engineers who can help ensure security evolves alongside the business rather than becoming an afterthought. These companies share a commitment to building strong culture, high-performing teams, and innovative people programs. They`re growing fast, scaling thoughtfully, and seeking exceptional talent to join their journey.
Security Engineer
American AgCredit
United States
Why should you join our team? American AgCredit offers a unique opportunity to be a part of a national financial system supporting those who feed, clothe and fuel the world. We are a growing organization embracing collaboration and innovation while delivering transformative solutions. American AgCredit provides a cultivating environment where you truly make a difference for our customers and teams. Benefits offered by American AgCredit: Commitment to agriculture and the communities we serve Family friendly work environment Investment in employee development Medical, Dental and Vision coverage Outstanding 401k – automatic 3% employer contribution, plus match up to 6% Generous Paid Time Off (Vacation accrued at 21 days annually, Sick Days accrued at 15 days annually, 12 paid holidays, plus 16 hours of volunteer time) Competitive Incentive Compensation Plan Disability & Life Insurance Employee mental, physical, and financial wellness programs The position is bonus eligible based on association and personal performance Position will be posted until filled. The Security Engineer is responsible for the operation, administration, optimization, and support of the Association's information security platforms and services. As a member of the Security Operations team, this role performs hands-on security engineering and operations activities designed to identify, investigate, respond to, and remediate cybersecurity threats, vulnerabilities, and exposures. This position has a primary focus on Vulnerability Management and is responsible for vulnerability assessment, exposure discovery, technical validation, risk-based prioritization, remediation coordination, and issue tracking through resolution. The Security Engineer works closely with infrastructure, application, cloud, endpoint, and other technology teams to ensure vulnerabilities and exposures are identified, understood, and addressed in accordance with established remediation timelines. In addition to vulnerability management, this role supports security monitoring, incident response, threat hunting, cloud and endpoint security, detection tuning, and security automation. The Security Engineer investigates security events, evaluates control gaps, improves technical controls, and maintains the platforms, integrations, automation, reporting, and processes necessary to protect Association systems and data. Strong collaboration and communication skills are essential. This role works with technology teams, managed security service providers, vendors, and internal stakeholders to investigate security concerns, provide practical remediation guidance, reduce risk, and improve security operations. ESSENTIAL DUTIES Administer, optimize, and support enterprise security platforms used for vulnerability management, threat detection, endpoint security, cloud security, identity protection, email security, and related security operations. Perform and coordinate vulnerability management activities across endpoint, server, application, cloud, network, and internet-facing environments. Identify, validate, prioritize, and drive remediation of vulnerabilities and exposures using risk-based methodologies that consider exploitability, business impact, asset criticality, threat intelligence, and remediation objectives. Assess system configurations, security controls, and technology implementations to identify security weaknesses, potential attack paths, and control gaps. Provide technical guidance and remediation recommendations to support secure deployment and operation of Association technologies. Monitor security telemetry, threat intelligence, vulnerability disclosures, and attack activity to identify emerging threats. Conduct threat hunting activities and improve detection capabilities to increase security visibility and reduce organizational risk. Investigate and respond to cybersecurity incidents, suspicious activity, and security events. Collaborate with technology teams, managed security service providers, and technology vendors to contain threats, resolve issues, and improve defensive capabilities. Develop, evaluate, and enhance security tools, automation, integrations, reporting, dashboards, controls, and operational workflows to improve efficiency, increase visibility, reduce manual effort, and support data-driven security operations. Develop and maintain operational documentation, procedures, technical runbooks, and knowledge articles that support consistent execution of security operations and vulnerability management activities. Evaluate and recommend improvements to security tools, processes, controls, and operational practices. Participate in after-hours security incident response activities when necessary. Perform other duties as assigned. LEVELS OF SUPERVISION EXERCISED AND RECEIVED Exercises no direct supervision. Works under the general direction of the Head of Cybersecurity. Regularly provides technical guidance to technology teams regarding security operations, vulnerability remediation, exposure reduction, and implementation of security controls. Exercises independent judgment in the investigation, analysis, prioritization, and resolution of information security issues. TYPICAL EDUCATION AND EXPERIENCE Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field; or an equivalent combination of education, technical training, certifications, military service, and professional experience that demonstrates the knowledge and skills required to perform the responsibilities of the position. Minimum of 5 years of hands-on experience supporting, administering, troubleshooting, engineering, or securing enterprise technology environments. Experience may be gained through information technology, infrastructure administration, systems administration, cloud administration, endpoint administration, network administration, cybersecurity, security operations, security engineering, or related technical disciplines. Experience with vulnerability management, security operations, infrastructure operations, cloud administration, endpoint management, systems administration, network administration, or security engineering is preferred, along with familiarity with vulnerability management principles, secure configuration practices, security frameworks, and risk-based prioritization methodologies. Strong technical aptitude with experience supporting enterprise technology environments, investigating complex technical issues, working across technology teams, and driving solutions through resolution. Demonstrates analytical thinking, continuous learning, and an interest in cybersecurity and risk reduction. Experience with enterprise technology, security platforms, scripting, automation, reporting, or workflow improvement is preferred. Familiarity with industry security frameworks and standards, including NIST Cybersecurity Framework, CIS Controls and Benchhmarks Relevant technical or security certifications are preferred. Occasional travel required (<10%). PREFERRED CANDIDATE PROFILE The ideal candidate has a strong hands-on technology foundation, a passion for cybersecurity, and experience solving complex problems in enterprise environments. Candidates may come from infrastructure, systems administration, cloud, endpoint, network, security operations, security engineering, or other technical backgrounds. The successful candidate is naturally curious, communicates effectively, and works well across technology teams to understand issues, identify root causes, and drive practical solutions through resolution. Direct experience with vulnerability management or security operations is valuable, but technical aptitude, sound judgment, continuous learning, and the ability to translate findings into actionable remediation guidance are equally important. ESSENTIAL JOB REQUIREMENTS: Must have the ability to perform basic office tasks and sit at a desk for an extended period of time. Job requires extensive use of computers and phones. While performing the job, the employee is required to sit, crouch, kneel, crawl, reach and have the ability to lift up to 40 pounds. Ability to work with typical hardware and cabling practices required. Must have strong written and verbal communication skills to adequately convey ideas and work well with a team. Ability to talk and hear, sit and use their hands and fingers, and reach in all directions is essential in performance of the job. Must be able to interact effectively with people at all levels of company. Work during established business hours and may require occasional weekend and/or evening work. FULL-TIME REMOTE: These roles and job functions can be done remotely, while maintaining our strong commitment to customer service and our business goals. Employees are welcome to come to an office to work if needed, and some travel for team meetings will be required. PAY RANGE: Minimum $96,484.38 - Max $164,023.43 Annual This range is reflective of the national salary average for this position and will be adjusted using geographic variance for physical location of the hired candidate. American AgCredit may compensate outside of the salary range for bona fide reasons not related to membership in a protected class. Reflected is the national base pay range and title offered for this job at the current level. Compensation, title, and job level may be adjusted based on candidate qualifications including but not limited to achievements, skills, experience, or work location. Salary offered, within the applicable range, is one component of the total rewards package offered to candidates. All hiring is contingent on eligibility to work in the United States. We are unable to sponsor or transfer visas for applicants. American AgCredit provides equal opportunity in employment to all employees and applicants. We celebrate diversity and do not discriminate on the basis of race, color, creed, religion, national origin, ancestry, alienage or citizenship status, age, sex, sexual orientation, gender identity, gender expression, marital status, genetic information, medical condition, physical or mental disability, pregnancy, childbirth or related medical condition, military service or veteran status, victims of domestic violence, or any other characteristics protected by applicable federal, state, or local laws. American AgCredit prohibits harassment of any individuals on any of the bases listed above. If you need assistance or an accommodation due to a disability, you may contact us at . Originally posted on Himalayas
Security Engineer
Panopto
United States
Company Overview: At Panopto, we are the most customer-centric learning technologycompany in the world. As the leader in visual and audio-based learning, we empower organizations to share knowledge effortlessly in a capture and post-capture world. We don’t just build software; we obsess over our users’ goals to deliver solutions that truly matter. Our mission is simple: to attract the brightest talent, people like you, to Elevate the Craft and do the most impactful work of your career. To enhance our team we are seeking an experienced Security Engineer who thrives at the intersection of engineering and security. In this role, you’ll own the security posture of a platform used by millions, partnering closely with developers to build secure systems from the ground up. Position Summary: In this role, you will have the opportunity to do the most impactful work of your career, elevating your craft while contributing to a team that values lifelong learning. As a Security Engineer, you are a critical guardian of the platform that powers video knowledge management for global universities and businesses. You won't be working in an "ivory tower." Instead, you will Elevate the Craft of security by embedding it directly into the development lifecycle. You will bridge the gap between high-level compliance (ISO 27001, TX-RAMP) and the day-to-day realities of high-velocity engineering, ensuring our posture is pragmatic, scalable, and built on Clarity Over Complexity. You'll also have opportunities to contribute to other initiatives that directly advance our core values and support you in elevating your craft. How You’ll Contribute: In this role, you will have the opportunity to… Design Secure Systems: Partner with engineering teams to conduct threat modeling. You’ll ensure security is "baked-in" to new features from the first line of code, not "bolted-on" at the end. Drive Proactive Defense: Build and maintain automated scanning, penetration testing frameworks, and monitoring tools within our AWS CI/CD pipelines to catch vulnerabilities before they reach production. Own Governance & Compliance: Lead the technical implementation of controls for ISO 27001 and TX-RAMP, turning complex regulatory requirements into simple, actionable engineering standards. Lead Incident Response: Act with ownership during security events. You’ll lead investigations and root-cause analysis, providing the Collective Wisdom needed to prevent future occurrences. Mentor the Team: Champion a "security-first" mindset. You’ll host workshops that empower developers to write secure code and understand modern attack vectors. How We Thrive: You’ll work with a team of talented engineers with a variety of areas of expertise, from devops to design, architecture to accessibility. The team’s experience level ranges from seasoned developers with well over a decade in industry to junior developers and contractors who are growing their roles and impact. The Foundation for Success: Cloud Security Mastery: You have a proven track record of securing AWS environments (IAM, Network Security, Infrastructure-as-Code) at scale. Code-Level Proficiency: You can read and write code (C#, Python, or similar). You don’t just find bugs; you suggest the secure code alternative. Automation Mindset: You prefer a script over a manual check. You have experience with SAST/DAST and vulnerability management platforms. Pragmatic Compliance: You understand that security must support business velocity. You’ve implemented controls in regulated environments without slowing down the mission. Experience: 5+ years in security engineering or software development with a security focus. What Sets You Apart: Experience securing video streaming architectures or high-scale backend services. A history of leading incident response in a remote-first environment. Deep expertise in OWASP Top 10 and secure API design. What Success Looks Like: Within 6 Months: You complete a security audit of our current CI/CD pipeline and establish relationships with lead developers. Within 1 Year: Automate one major manual security check and contribute to our TX-RAMP/ISO certification technical evidence. Your Legacy: Full ownership of the security roadmap; measurable reduction in "security-debt" during the architectural review phase Join Panopto and play a key role in shaping the security foundation of a platform used by millions. If you love threat modeling, automating defenses, guiding engineering teams, and turning compliance standards into practical, scalable security practices, you’ll feel right at home here. Beyond the Requirements: At this point, we hope you're feeling excited about the job description you’re reading. Even if you don't feel that you meet every single requirement, we still encourage you to apply. We're eager to meet people that believe in our mission and can contribute to our team in a variety of ways - not just candidates who check all the boxes. We want people to feel comfortable expressing their true selves and to come, stay, and do their best work here. Recruiting Tips: From crafting an impressive resume to presenting your best self during our interviews, we're dedicated to ensuring you feel well-prepared and self-assured as you embark on opportunities at Panopto. Discover some valuable Recruiting Tipsfrom our team. The standard interview process at Panopto involves several steps, outlined below, to ensure we approach the process thoughtfully and consistently: Application Review -> Recruiter Call -> Video Interview & Assessment -> Hiring Manager Call -> Interview Loop -> Debrief -> Offer Our people and culture Panopto’s mission is to be the leader in visual and audio-based learning in a capture and post-capture world. Our user base is as diverse as the world’s universities and businesses. Panopto’s commitment to fostering a fair, equitable, and inclusive culture empowers each member of our team to express their authentic selves, contribute their distinct perspectives and make a meaningful impact both individually and collectively. This inclusive environment not only encourages creativity and the free exchange of ideas but also harnesses the power of varied viewpoints. As a result, we are better equipped to tackle our most intricate challenges, leveraging the wealth of different experiences and backgrounds within our team. This collaborative spirit empowers us to challenge ideas (not people) recognizing that our shared success relies on collective wisdom. It drives us to continuously improve and innovate, ultimately elevating the quality of our products and services. It’s what sets Panopto apart as a unique and rewarding place to work. Our purpose We believe that video can have a transformative effect on learning. So we built a video knowledge management platform that helps businesses and universities improve the way that they train, teach, and share knowledge. Since 2007, we have been a pioneer in video capture software, video management, and inside-video-search technology. Panopto has been adopted by more than 1,600 companies and universities worldwide with over 11 million end users. Today, Panopto’s knowledge management platform is the largest repository of expert learning videos in the world. A proud remote-first company, Panopto is headquartered in Pittsburgh, with offices in London, Hong Kong, Singapore, and Sydney, and has received industry recognition for its innovation, rapid growth, and company culture. Panopto is an Equal Opportunity Employer. We value and encourage diversity and solicit applications from all qualified individuals which will receive consideration for employment without regard to race, color, religion, sex, marital status, sexual orientation, gender identity or expression, national origin, age, disability or protected veteran status, or any other legally protected criteria, in accordance with applicable law. Panopto is committed to providing reasonable accommodation to applicants with disabilities. If you require accommodation for interviewing or otherwise participating in the employee selection process, please provide more detail on how we can further support you by reaching out to the Employee Experience department. Remote, US: Candidates looking for flexible or remote-friendly positions are encouraged to apply. Panopto is proud to be a remote-first company. Employees in this position are eligible to work remotely. Remote, International: Candidates looking for flexible or remote-friendly positions are encouraged to apply. Panopto is proud to be a remote-first company. Employees in this position are eligible to work remotely. Still, they may make regular trips to the local international office from time to time, where applicable. Use of Artificial Intelligence (AI): Panopto may utilize artificial intelligence (AI) tools to assist in our recruitment and evaluation process. This may include analyzing resumes, assessing skills, and generating insights to help identify qualified candidates. Please be assured that AI tools are used to support our team, and all final hiring decisions are made by human reviewers. Panopto hiring teams will thoroughly review your application and assessment results. AI is not used to make final decisions regarding your candidacy. By submitting your application and participating in the recruitment process, you acknowledge and consent to Panopto's use of AI tools as described above. We are committed to full compliance with all applicable labor laws, including Equal Employment (EEOC) laws, across all our company entities. To ensure fairness and transparency: We have human oversight in all hiring decisions. If you have concerns regarding the use of AI in your assessment, please contact Panopto Talent Attraction to request a manual review of your application. Please be aware that while we offer this option, the manual review process may take longer than the standard AI-assisted process. Any data collected during this process, including video recordings if applicable, will be retained only for the duration necessary to fulfill the hiring purpose and will be deleted shortly thereafter once the role is filled. We may utilize vendor tools to assist with the AI process. Vendor functions are ‘skill assessments' or 'resume analysis'. Panopto is dedicated to a fair and equitable hiring process for all candidates. Originally posted on Himalayas

Security Engineer
SambaSafety
Holding's Ford, MN
SambaSafety Jobs Security Engineer SambaSafety Security Engineer Job Posted 14 Days Ago Posted 14 Days Ago Hiring Remotely in Holding's Ford, MN, USA Remote or Hybrid 130K-150K Annually Senior level Insurance • Logistics • Software • Transportation • Business Intelligence SambaSafety a SaaS company HQ'd in Denver, we are the leader In mobility & driver risk intelligence. The Role Leads application security, vulnerability management, threat detection, AI-driven security automation, and security engineering. Administers SAST, DAST, SCA, SIEM, EDR, IAM, and cloud security platforms; develops MITRE ATT&CK-mapped detections; investigates Tier 2/3 incidents; builds Python-based automation and AI agent integrations; supports architecture reviews, penetration testing, policy development, threat intelligence, compliance, and security reporting. Summary Generated by Built In Who we are: Hi, we’re SambaSafety and we offer the industry’s most comprehensive driver monitoring software. Our mission is promoting safer communities by reducing risk through data insights. Companies trust SambaSafety to keep their employees safe on the roads, price and reduce risk, help protect their brand, their bottom line, and our global community. We’ve built an inclusive, supportive, and exceptional culture where every employee is empowered in their role. Don’t take our word for it; we’ve been recognized as a Top Workplace by The Denver Post, Albuquerque Journal, Sacramento Bee, and Built In Colorado. And our employees rate SambaSafety as top-notch, with a rock solid Top Rating on Glassdoor. What You’ll Do: We are seeking an experienced Security Engineer to join our growing security team in a multifaceted role that combines vulnerability management, application security, MITRE ATT&CK-based threat detection, AI-driven security automation, and security engineering expertise. This position requires a technical security professional with knowledge spanning cloud security, identity and access management (IAM), endpoint detection and response (EDR), SIEM administration, and hands-on scripting for automation development. The successful candidate will work closely with development teams, infrastructure teams, vendors, and internal stakeholders to optimize our security posture and manage enterprise risk. Key Responsibilities: Application Security & Vulnerability Remediation Lead application security vulnerability remediation efforts across development teams Administer SAST tooling Administer DAST tooling Administer SCA and software composition / dependency scanning tools Triage and validate vulnerability findings to reduce false positives Provide remediation guidance to development teams on OWASP Top 10 and secure coding practices Integrate scanning tools with ticketing systems and CI/CD pipelines Generate AppSec metrics and reports Provide security code review support Vulnerability Assessment & Management Administer vulnerability management platforms Configure scan policies, schedules, and asset groups Validate and prioritize vulnerability findings using risk-based prioritization (CVSS + context) Conduct expert analysis and risk scoring of vulnerabilities Coordinate remediation with IT and development teams Manage vulnerability exceptions and risk acceptances Track vulnerability aging and SLA compliance Generate management reports and dashboards Participate in product vulnerability management meetings Participate in Security by Design reviews MITRE ATT&CK & Threat Detection Develop detection rules mapped to ATT&CK techniques Implement ATT&CK-based alert triage workflows Configure SIEM correlation rules using ATT&CK Conduct gap analysis of ATT&CK coverage Integrate threat intelligence feeds with ATT&CK mapping Build ATT&CK-based hunting queries Create ATT&CK-mapped incident reports AI-Driven Security Automation & Agent Engineering Build and maintain scripted, cloud-based automation pipelines supporting the team's AI-driven security operations platform Develop and tune AI agent prompts, verdict logic, and disposition rules for automated alert triage Extend the team's internal tool-integration framework connecting security platforms for AI-assisted operations Integrate automation with SIEM, EDR, and ticketing systems Build automated enrichment and reporting workflows Monitor and tune agent/automation performance and disposition accuracy Develop custom integrations using APIs and cloud-native services Maintain observability for automated security workflows Security Engineering & Architecture Lead Tier 2/3 security incident investigation and response Administer EDR, SIEM, and IAM platforms Implement and tune detection rules and alerts Manage cloud security configurations Support penetration testing and red team activities Conduct WAF/CDN rule audits and configuration reviews Provide security engineering expertise for infrastructure and application architecture decisions Support complex security investigations requiring deep technical analysis Contribute to security design reviews and technical security standards Policy & Threat Intelligence Draft and review security policies and procedures Conduct policy gap analysis against frameworks Analyze threat intelligence from multiple sources Integrate threat feeds into detection and automation workflows Implement IOC blocking and detection rules Participate in information sharing communities (ISACs) Create threat intelligence reports Required Qualifications: Education & Experience Bachelor's degree in Computer Science, Information Security, Engineering, or related technical field, or equivalent professional experience 5-7 years of experience in security engineering with demonstrated expertise in multiple security domains, including application security Technical Skills Expert knowledge of vulnerability management platforms Proficient in MITRE ATT&CK mapping for detection rules and incident response Strong experience with SAST, DAST, and SCA tooling for application security Deep understanding of application vulnerabilities (OWASP Top 10, injection flaws, XSS, authentication bypasses) Hands-on scripting experience building cloud-based automation (serverless functions, event-driven pipelines, secrets management) Experience with, or strong interest in, AI agent engineering and tool-integration protocols for security operations Proficiency administering EDR platforms Experience with SIEM administration Solid understanding of IAM platforms and federation/SSO concepts Proficiency in cloud security (AWS, Azure, or GCP) Solid understanding of WAF configuration and audit Proficiency in scripting and automation (Python required; PowerShell a plus) Understanding of DevSecOps and secure CI/CD practices Practical experience with AI-powered security tooling, including building or operating LLM-based agents, and awareness of emerging AI threats (prompt injection, tool/agent security risks) Ability to produce dashboards and reporting for technical and executive audiences Platform & Domain Experience SIEM administration Security automation/orchestration, including AI agent-based automation Vulnerability management platforms EDR platforms DLP platforms GRC platforms SAST tooling DAST tooling SCA / dependency scanning tooling Cloud security (AWS, Azure, or GCP) Threat intelligence platforms Ticketing and collaboration platforms Soft Skills & Experience Strong analytical thinking and problem-solving capabilities Excellent communication skills for technical and business audiences Strong Agile proficiency with ability to integrate security into sprint planning Experience collaborating with development teams and partnering on secure coding Ability to translate technical vulnerability findings into actionable remediation guidance Strong written communication skills for security documentation, audit responses, and questionnaire completion Act as escalation point for Security Analysts Participate in project security reviews Support sales team with security questionnaires Participate in customer security calls Preferred Qualifications: Certifications CySA+ (CompTIA) Cloud Security certification (AWS, Azure, or GCP) GIAC GSEC Certified Ethical Hacker (CEH) GIAC GWEB (Web Application Penetration Tester) CompTIA PenTest+ (optional) GIAC GCTI (Cyber Threat Intelligence) (optional) SIEM Platform Certification (optional) Additional Experience DevSecOps experience integrating SAST/DAST into CI/CD pipelines Secure software development lifecycle (SSDLC) implementation experience Compliance experience with SOC 2, ISO 27001, or industry-specific regulations Experience with security audit preparation and vendor risk assessment programs Threat intelligence analysis and integration experience Experience coordinating third-party penetration testing Security awareness training development and delivery Experience building or integrating LLM-based agents/automation for security operations Experience with container and Kubernetes security concepts Benefits and Perks: Flexible and generous Paid Time Off and Paid Volunteer Days 401k Employer Match Generous Healthcare Benefits Up to 12 weeks paid time off for maternity leave based on tenure Wellness &Tuition Reimbursement Flexible Work Arrangements Lots of SambaSafety swag & SambaSafety Events Our team of talented and committed safety professionals is exceptional. At SambaSafety we strive to foster an inclusive culture that supports, encourages and celebrates a wide array of diversity. We are committed to create a space where all employees can show up as their authentic selves every day, and we work to advance employee equality, diversity and inclusion. SambaSafety provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, gender identity, and expression or genetics. Come join us to find out for yourself what all the excitement is about! Read Full Description Skills Required Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent professional experience 5-7 years of experience in security engineering, including application security expertise Expert knowledge of vulnerability management platforms Experience mapping MITRE ATT&CK techniques for detection rules and incident response Experience with SAST, DAST, and SCA application security tooling Understanding of OWASP Top 10 and application vulnerabilities Hands-on experience building cloud-based security automation Experience with or strong interest in AI agent engineering and security tool integration Experience administering EDR platforms Experience administering SIEM platforms Understanding of IAM platforms and federation or SSO concepts Proficiency in AWS, Azure, or GCP cloud security Understanding of WAF configuration and auditing Python scripting proficiency Understanding of DevSecOps and secure CI/CD practices Experience with AI-powered security tooling and LLM-based agents Ability to produce technical and executive security dashboards and reports CySA+ certification AWS, Azure, or GCP cloud security certification GIAC GSEC certification Certified Ethical Hacker certification GIAC GWEB certification CompTIA PenTest+ certification GIAC GCTI certification SIEM platform certification DevSecOps and SSDLC implementation experience SOC 2, ISO 27001, or industry-specific compliance experience Security audit preparation and vendor risk assessment experience Threat intelligence analysis and integration experience Experience coordinating third-party penetration testing Security awareness training development and delivery experience Experience building or integrating LLM-based security automation Container and Kubernetes security experience What the Team is Saying Julia Porter Account Manager The culture, the benefits, the management, and perks are all fantastic. Ask questions, take advantage of the extensive training offered and learn everything about the products so you can speak in the simplest terms to the clients, and have fun too. Julia Porter Account Manager The culture, the benefits, the management, and perks are all fantastic. Ask questions, take advantage of the extensive training offered and learn everything about the products so you can speak in the simplest terms to the clients, and have fun too. Brenden Macy Commercial Counsel Samba’s best asset is its people. The folks I’ve met at Samba have been not only top-notch in their field and position, but are interesting, kind, genuine human beings, too. The combination of such great individuals makes for a fantastic environment Derik Cissell Account Executive, Major Market Getting hired during a Pandemic: Samba did a great job exercising their “open door mentality”, ALL employees are willing to help! The first 2 months have been clearly outlined through activities and expectations to shorten the learning curve! Michelle Gagnon Sales Solutions Consultant, Channel Partner Samba continuously works to curate a positive culture focused on growth and inclusion. Everyone is always ready to jump in and help with any question or issue. I’m excited to be working with a high energy team focused on solving real world problems! John Russell Account Executive, Transportation When you’re here you’re family. Olive Garden stole that from SambaSafety. Instead of endless bread sticks there’s endless career development, opportunity & the chance to be part of something much bigger than yourself. To wake up everyday & sell something you believe in is rare. To do it with people you consider friends & mentors is a blessing. Kyle McGaw Account Executive, Mid-Market I started a couple months ago, and was extremely impressed, not only with how fast they came up with a new program to onboard people from home but also with the quality of the training and how impactful it was to a new person to the organization. The people and culture are amazing and II am very happy with my decision to come work for this company Abby Abreu Senior Account Manager There is a great work/life balance at Samba. Our organization makes an impact to businesses and their employees so we’re usually available, however being in the office 24/7 is not what Samba is about. The high level of trust that we’re all here to work hard and be the best trumps clocking in and working typical 9-5 hours. Kevin Lawlor VP of Human Resources Samba is full of collaborative, highly engaged, driven people continuously looking to outperform. We harness and direct this energy towards intelligent risk-taking leading to greater innovation. Our program encourages dialogue on the vast amount of ideas surfaced by our teams. Selected ideas are assigned to a team for completion. Tommy Cordova Software Architect The environment we create is one of experimentation, where anyone can bring anything to the table as a solution to accomplish a task to enhance and grow our product. No idea is too mundane or question too simple to be discussed and used to grow our people as well as our product offering. SambaSafety Compensation & Benefits Highlights Healthcare Strength — Healthcare includes comprehensive medical, dental, and vision coverage, with one medical plan featuring employer-paid premiums and company HSA contributions alongside mental health options. These elements point to strong core coverage that many candidates prioritize. Leave & Time Off Breadth — Time-off policies feature flexible/unlimited PTO, paid holidays, paid volunteer days, and seasonal Summer Fridays. This breadth of leave supports work-life balance beyond standard PTO banks. Parental & Family Support — Paid parental leave provides up to 12 weeks for primary caregivers and 3 weeks for secondary caregivers, complemented by family medical leave and childcare-related supports. This depth of family leave is notable for a mid-size tech company. Learn more about SambaSafety's Compensation & Benefits → SambaSafety Insights What's It Like to Work at SambaSafety? SambaSafety Culture & Values SambaSafety Career Growth & Development What's the Work-Life Balance Like at SambaSafety? SambaSafety Leadership & Management SambaSafety Company Growth, Stability & Outlook View all jobs at SambaSafety View SambaSafety Profile Report Job Am I A Good Fit? beta Get Personalized Job Insights. Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align. Upload Resume Upload Resume Success! Refresh the page to see how your skills align with this role. The Company HQ: Denver, CO 300 Employees Year Founded: 1998 What We Do SambaSafety is a recognized innovator and leading provider of cloud-based risk management solutions for over 15,000 organizations with automotive mobility exposure, including many on Fortune’s Global 500 list. Employers and insurers benefit from SambaSafety’s continuous monitoring, intuitive insights, risk reduction tools, and configurable pricing solutions. Through the collection, correlation, and analysis of federal, state, local, and telematics data sources, SambaSafety's flexible, end-to-end capabilities enable businesses and insurers to better evaluate and mitigate driving risk, accelerate product development, reduce crashes, and foster safer communities. Why Work With Us Recognized as one of the Top 100 Tech Companies by Builtin and DenverPost & over 4.7 review on Glassdoor, we are the pioneer of driver risk management software in North America. We are proud to be an inclusive culture that supports diversity of all kinds and we are committed to all employees bringing their authentic selves to work every single day. Gallery SambaSafety Offices Learn More Hybrid Workspace Employees engage in a combination of remote and on-site work. Typical time on-site: Flexible HQ Denver, CO Milton Keynes, GB Learn more Option 1 of 1 Similar Jobs SambaSafety Sales Development Representative Insurance • Logistics • Software • Transportation • Business Intelligence Remote or Hybrid 2 Locations 300 Employees 55K-60K Annually SambaSafety Software Operations Engineer Insurance • Logistics • Software • Transportation • Business Intelligence Remote or Hybrid United States 300 Employees 60K-70K Annually SambaSafety Revenue Operations Manager Insurance • Logistics • Software • Transportation • Business Intelligence Remote or Hybrid 2 Locations 300 Employees 90K-110K Annually SambaSafety Automation Engineer Insurance • Logistics • Software • Transportation • Business Intelligence Remote or Hybrid United States 300 Employees 75K-85K Annually View all jobs at SambaSafety View SambaSafety Profile Report Job Continue Not Eligible Save You are not eligible to apply because your location does not meet the criteria for this role. Not Eligible Save Apply Instructions Sign up now Access later Create Free Account Already have an account? Log In .unAuthenticated-modal::backdrop { position: fixed; background: rgba(0, 0, 0, 0.5); } .dot { padding: 2px; border-radius: 50%; } .px-5xl { padding-left: 5rem !important; padding-right: 5rem !important; } .bg-daffodil { background-color: #ffed00 !important; } .gradient-blueberry { background-image: linear-gradient(312deg, rgb(36, 79, 231) 2%, rgb(10, 14, 92) 94%); } Please log in or sign up to report this job. Create Free Account Already have an account? Log In .unAuthenticated-modal::backdrop { position: fixed; background: rgba(0, 0, 0, 0.5); } .dot { padding: 2px; border-radius: 50%; } .px-5xl { padding-left: 5rem !important; padding-right: 5rem !important; } .bg-daffodil { background-color: #ffed00 !important; } .gradient-blueberry { background-image: linear-gradient(312deg, rgb(36, 79, 231) 2%, rgb(10, 14, 92) 94%); }
Security Engineer
Panopto
United States
Company Overview: At Panopto, we are the most customer-centric learning technologycompany in the world. As the leader in visual and audio-based learning, we empower organizations to share knowledge effortlessly in a capture and post-capture world. We don’t just build software; we obsess over our users’ goals to deliver solutions that truly matter. Our mission is simple: to attract the brightest talent, people like you, to Elevate the Craft and do the most impactful work of your career. To enhance our team we are seeking an experienced Senior DevSecOps Engineer who thrives at the intersection of engineering and security. In this role, you’ll own the security posture of a platform used by millions, partnering closely with developers to build secure systems from the ground up. Position Summary: In this role, you will have the opportunity to do meaningful work in your career, elevating your craft while contributing to a team that values lifelong learning. As a Senior DevSecOps Engineer, you are a critical guardian of the platform that powers video knowledge management for global universities and businesses. You will not operate in an isolated silo or an "ivory tower." Instead, you will elevate the craft of security by embedding automated security controls directly into the development lifecycle and CI/CD pipelines. You will bridge the gap between compliance standards (ISO 27001, SOC 2, TX-RAMP) and high-velocity software engineering, ensuring our security posture is pragmatic, scalable, and built on Clarity over Complexity. Driving an AI-first mindset, you will leverage modern automation tools and AI workflows to eliminate manual security tasks, accelerate threat modeling, and simplify system architectures. You'll also have opportunities to contribute to other initiatives that directly advance our core values and support you in elevating your craft. How You’ll Contribute: In this role, you will have the opportunity to… Design Secure Systems: Lead hands-on threat modeling assessments on new features across many different AWS services, ensuring security is baked into application design from the first line of code. Drive Proactive Defense & CI/CD Security: Build, maintain, and enforce automated static (SAST), dynamic (DAST), and dependency (SCA) security testing frameworks within our AWS delivery pipelines to catch vulnerabilities before code reaches production. Secure Cloud & Container Infrastructure: Design and manage security guardrails across AWS environments, Kubernetes clusters, Docker containers, and CloudFormation/CDK/Terraform Infrastructure-as-Code (IaC) deployments. Own Policy & Automated Governance: Lead the technical implementation of policy-as-code and compliance guardrails (ISO 27001, SOC 2, TX-RAMP), translating complex regulatory requirements into simple, actionable engineering standards. Leverage AI Security Tools: Evaluate and integrate AI-assisted tools to accelerate code reviews, log analysis, and vulnerability triage, while establishing secure usage guidelines for developer AI tools. Lead Incident Response: Act with ownership during security events by conducting investigations and root-cause analysis, using collective wisdom to prevent future incidents. Mentor Engineering Teams: Coach developers on secure coding practices, threat identification, and vulnerability remediation through practical mentorship and reusable design patterns. What Success Looks Like: Within 6 Months: Execute threat modeling assessments for active feature releases. Complete an audit of our current CI/CD pipelines, assume technical ownership of cloud security standards, and establish working relationships with lead developers. Within 1 Year: Automate at least one major vulnerability triage workflow in the build pipeline. Your Legacy: Establish fully automated policy-as-code guardrails across AWS and Kubernetes environments, demonstrating a measurable reduction in security debt during architectural reviews. Values in Action Customer First, Always: You proactively surface friction points in the customer experience before they are escalated — and propose solutions, not just reports. Thrive Together: You share work-in-progress for early feedback, knowing that challenge improves the outcome. You separate critiques of ideas from critiques of people. Elevate the Craft: You hold the bar high on your own work and invest in developing those around you. You treat every project as an opportunity to learn something new. Act with Ownership: You define success by outcomes, not activity. You flag problems early and bring a proposed path forward, not just the problem. Clarity Over Complexity: You default to the simpler solution. Your written communication — internal or external — is direct, specific, and free of filler. How We Thrive: You’ll work with a team of talented engineers with a variety of areas of expertise, from devops to design, architecture to accessibility. The team’s experience level ranges from seasoned developers with well over a decade in industry to junior developers and contractors who are growing their roles and impact. The Foundation for Success: Cloud & Container Security Mastery: Proven track record securing Multi-Account AWS environments and Infrastructure-as-Code deployments (IAM/Identity Center, Network Security, Encryption, Docker/ECS/Fargate, Terraform, CloudFormation/CDK, Security Hub, GuardDuty). Pipeline Automation & Code Proficiency: Strong hands-on experience integrating security tools into CI/CD pipelines and writing automation scripts using Python or Bash. Practical AI Application: Demonstrated experience using AI tools (such as automated code reviewers, LLM tools, or AI-driven security scanners). In addition, experience securing AI systems, AI supply chinese, and AI-assisted workflows. Threat Modeling Execution: Proven ability to evaluate application architectures for security flaws and guide teams on mitigating OWASP Top 10 vulnerabilities. Pragmatic Compliance: Understanding that security must support business velocity, with experience turning compliance requirements into automated checks without slowing down software releases. Experience: 7+ years in security engineering, DevSecOps, software development, or cloud infrastructure security. What Sets You Apart: Security or cloud certifications such as CISSP, AWS Certified Security - Specialty, or Certified Kubernetes Security Specialist (CKS). Experience securing video streaming architectures or high-scale backend services. Experience implementing policy-as-code frameworks in regulated SaaS environments. Join Us Join Panopto and play a key role in shaping the security foundation of a platform used by millions. If you love threat modeling, automating defenses, guiding engineering teams, and turning compliance standards into practical, scalable security practices, you’ll feel right at home here. Beyond the Requirements: At this point, we hope you're feeling excited about the job description you’re reading. Even if you don't feel that you meet every single requirement, we still encourage you to apply. We're eager to meet people that believe in our mission and can contribute to our team in a variety of ways - not just candidates who check all the boxes. We want people to feel comfortable expressing their true selves and to come, stay, and do their best work here. Recruiting Tips: From crafting an impressive resume to presenting your best self during our interviews, we're dedicated to ensuring you feel well-prepared and self-assured as you embark on opportunities at Panopto. Discover some valuableRecruiting Tipsfrom our team. The standard interview process at Panopto involves several steps, outlined below, to ensure we approach the process thoughtfully and consistently: Application Review -> Recruiter Call -> Video Interview & Assessment -> Hiring Manager Call -> Interview Loop -> Debrief -> Offer Our people and culture Panopto’s mission is to be the leader in visual and audio-based learning in a capture and post-capture world. Our user base is as diverse as the world’s universities and businesses. Panopto’s commitment to fostering a fair, equitable, and inclusive culture empowers each member of our team to express their authentic selves, contribute their distinct perspectives and make a meaningful impact both individually and collectively. This inclusive environment not only encourages creativity and the free exchange of ideas but also harnesses the power of varied viewpoints. As a result, we are better equipped to tackle our most intricate challenges, leveraging the wealth of different experiences and backgrounds within our team. This collaborative spirit empowers us to challenge ideas (not people) recognizing that our shared success relies on collective wisdom. It drives us to continuously improve and innovate, ultimately elevating the quality of our products and services. It’s what sets Panopto apart as a unique and rewarding place to work. Our purpose We believe that video can have a transformative effect on learning. So we built a video knowledge management platform that helps businesses and universities improve the way that they train, teach, and share knowledge. Since 2007, we have been a pioneer in video capture software, video management, and inside-video-search technology. Panopto has been adopted by more than 1,600 companies and universities worldwide with over 11 million end users. Today, Panopto’s knowledge management platform is the largest repository of expert learning videos in the world. A proud remote-first company, Panopto is headquartered in Pittsburgh, with offices in London, Hong Kong, Singapore, and Sydney, and has received industry recognition for its innovation, rapid growth, and company culture. Panopto is an Equal Opportunity Employer. We value and encourage diversity and solicit applications from all qualified individuals which will receive consideration for employment without regard to race, color, religion, sex, marital status, sexual orientation, gender identity or expression, national origin, age, disability or protected veteran status, or any other legally protected criteria, in accordance with applicable law. Panopto is committed to providing reasonable accommodation to applicants with disabilities. If you require accommodation for interviewing or otherwise participating in the employee selection process, please provide more detail on how we can further support you by reaching out to the Employee Experience department. Remote, US: Candidates looking for flexible or remote-friendly positions are encouraged to apply. Panopto is proud to be a remote-first company. Employees in this position are eligible to work remotely. Remote, International: Candidates looking for flexible or remote-friendly positions are encouraged to apply. Panopto is proud to be a remote-first company. Employees in this position are eligible to work remotely. Still, they may make regular trips to the local international office from time to time, where applicable. Use of Artificial Intelligence (AI): Panopto may utilize artificial intelligence (AI) tools to assist in our recruitment and evaluation process. This may include analyzing resumes, assessing skills, and generating insights to help identify qualified candidates. Please be assured that AI tools are used to support our team, and all final hiring decisions are made by human reviewers. Panopto hiring teams will thoroughly review your application and assessment results. AI is not used to make final decisions regarding your candidacy. By submitting your application and participating in the recruitment process, you acknowledge and consent to Panopto's use of AI tools as described above. We are committed to full compliance with all applicable labor laws, including Equal Employment (EEOC) laws, across all our company entities. To ensure fairness and transparency: We have human oversight in all hiring decisions. If you have concerns regarding the use of AI in your assessment, please contact Panopto Talent Attraction to request a manual review of your application. Please be aware that while we offer this option, the manual review process may take longer than the standard AI-assisted process. Any data collected during this process, including video recordings if applicable, will be retained only for the duration necessary to fulfill the hiring purpose and will be deleted shortly thereafter once the role is filled. We may utilize vendor tools to assist with the AI process. Vendor functions are ‘skill assessments' or 'resume analysis'. Panopto is dedicated to a fair and equitable hiring process for all candidates. Originally posted on Himalayas

Security Engineer
Robert Half
Petaluma, CA
Description We are looking for a Security Engineer to join a Contract assignment supporting endpoint protection and device readiness for an aviation-focused organization in Petaluma, California. This role is ideal for someone who combines hands-on desktop support experience with a strong grounding in cybersecurity and can help prepare, secure, and validate user hardware for deployment. The position involves onsite collaboration, practical troubleshooting, and day-to-day security operations across laptops and other endpoint devices. Responsibilities: Prepare laptops and endpoint equipment for deployment by imaging systems, completing device setup, and verifying configuration standards. Install, configure, and confirm the performance of security applications so devices meet internal protection and compliance expectations before release to users. Execute hardware diagnostics, operating system checks, and security validation activities to confirm each asset is ready for production use. Review remote work environments and identify steps needed to improve home office security and reduce endpoint-related risk. Administer and support endpoint security and identity tools, including CrowdStrike and Okta,for provisioning. Monitor endpoint events and security notifications, investigate issues, and take appropriate action to address potential threats or control gaps. Apply desktop security requirements by maintaining endpoint safeguards, identity controls, and device protection practices. Partner with Help Desk and other technical teams to assist with hardware rollouts, employee onboarding, and resolution of security-related device issues. Support patching efforts, vulnerability remediation work, and other ongoing initiatives designed to strengthen endpoint security. Provide onsite technical assistance for endpoint hardware, device administration, and operational security needs during the engagement. Requirements At least 3 years of experience in endpoint security, desktop support, infrastructure security, or a related information security function. Demonstrated hands-on ability to image, configure, deploy, and troubleshoot laptops, desktops, and other endpoint hardware. Working knowledge of endpoint protection platforms such as CrowdStrike and related security technologies. Experience with Okta, identity and access management practices, and desktop security controls. Ability to analyze, prioritize, and respond to endpoint alerts, security incidents, and operational issues. Familiarity with patch management, vulnerability remediation, and endpoint administration tools such as NinjaOne or similar platforms. Understanding of Windows environments, cloud-connected systems such as Azure, and secure computing standards in regulated or high-security settings. Strong collaboration and troubleshooting skills, with experience working alongside Help Desk, Infrastructure, and Security teams. Technology Doesn`t Change the World, People Do. Robert Half is the world`s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles. Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. Download the Robert Half app and get 1-tap apply, notifications of AI-matched jobs, and much more. All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information. 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking "Apply Now," you`re agreeing to Robert Half`s Terms of Use and Privacy Notice.
Security Engineer
Chess.com
Remote
About Us Chess.com is one of the largest gaming sites in the world and the #1 platform for playing, learning, and enjoying chess. We are a team of 600+ fully remote people in 60+ countries working hard to serve the global chess community. We are here to support 250M+ chess players worldwide with the best possible product, content, and tools to serve the community! We are a tech company. A gaming company. A content company. And we do it all with passion and commitment to the game. Above all we prize our mission-driven, flat, life-celebrating, no-corporate culture, and we look forward to meeting you and learning more about what you can bring to the team. About The Role The Security Engineer plays a critical role in protecting our technology infrastructure and maintaining the security posture of our gaming platform. This position exists to proactively identify, assess, and mitigate security vulnerabilities while serving as a trusted security advisor to engineering teams across the organization. The role directly impacts our ability to safeguard user data, maintain platform integrity, and ensure secure development practices are embedded throughout our product development lifecycle. This position is essential for building and maintaining robust security defenses in a fast-paced, remote-first technology environment where security expertise must be seamlessly integrated into daily engineering operations and strategic decision-making processes. What you'll do Lead vulnerability management program by triaging, reproducing, and assessing security vulnerabilities submitted through Bug Bounty programs, working directly with engineering teams to prioritize and remediate discovered security gaps Conduct comprehensive threat modeling by collaborating with engineering teams to analyze proposed solutions, ensuring designs meet security industry standards and identifying potential attack vectors before implementation Manage security incident response by reviewing penetration testing results and SIEM reports, translating technical findings into actionable remediation tasks, and tracking resolution progress through completion Optimize security infrastructure by applying updates to Web Application Firewalls (WAF) and other security systems, ensuring configurations align with current threat landscape and organizational needs Drive security tool evaluation and implementation by researching, evaluating, and recommending security software solutions, attending vendor demonstrations, and leading procurement processes from requirements gathering through deployment Provide security consultation and guidance by serving as subject matter expert to development teams, ensuring security best practices are integrated into software development lifecycle and architectural decisions Maintain security awareness and documentation by communicating security updates, progress reports, and recommendations to stakeholders through established channels and maintaining current security policies and procedures Qualifications Bachelor's degree in Computer Science, Information Security, or related technical field, or equivalent professional experience Minimum 3+ years of professional experience specifically in web application security Demonstrated expertise with security testing tools such as Burp Suite or equivalent web request analysis and tampering tools Strong written communication skills in English with ability to clearly explain technical security concepts to diverse audiences Experience working effectively in fully distributed/remote team environments Proven ability to collaborate cross-functionally with engineering and development teams Preferred Skills and Qualifications Previous hands-on experience managing or participating in Bug Bounty programs Programming experience in PHP or JavaScript Experience with penetration testing methodologies and tools Knowledge of SIEM platforms and security monitoring systems Familiarity with Web Application Firewall (WAF) configuration and management Understanding of secure software development lifecycle (SDLC) practices Experience with Jira or similar project management and issue tracking systems Strong sense of ownership and accountability in a flat organizational structure Passion for continuous learning and staying current with evolving security threats and technologies About the Opportunity This is a full-time opportunity We are 100% remote (work from anywhere!) --- You can learn more about us here: Originally posted on Himalayas
Security Engineer
Offchain Labs
United States
At Offchain, we aren’t just building products: we’re leading a movement. As pioneers in blockchain scalability and security, we're at the forefront of transforming how the world interacts with decentralized applications. We're laying the foundation that will define the next generation of digital commerce, governance, and human interaction. This involves tackling real-world challenges that come with scaling blockchain technology, without compromising on its core principles: decentralization, security and transparency. At the center of this vision is our people. Our team is made up of thinkers and doers that embrace new challenges and seek solutions that push existing boundaries. If you’re energized by solving unprecedented problems, and believe in the role that decentralized systems will play in creating a more equitable digital future, then we want to hear from you. Why Offchain? Offchain is setting the pace for the entire Ethereum ecosystem. We built the Arbitrum stack that powers Arbitrum One, the most widely adopted Ethereum scaling solution that exists today. Arbitrum’s ecosystem is undergoing tremendous growth with hundreds of projects and dApps on Arbitrum One today. Over 100 different teams have used Offchain technology to build their own Arbitrum chains. Major players in the space, Robinhood, BlackRock, Ethena Labs, Securitize, Aave, and Apechain are all using the Arbitrum stack. Arbitrum’s thriving ecosystem wouldn’t exist without our advanced technology stack. Arbitrum, Prysm, ZeroDev. These aren’t just product names. These are tools that are actively reshaping what's possible on Ethereum and advancing its core infrastructure. To top it all off? We’re backed by $124 million in funding. We’ve demonstrated consistent execution with billions in secured value, thousands of supported projects, and infrastructure processing millions of transactions seamlessly. The Role As a Security Engineer at Offchain, you will play a key role in defining and improving our cloud security posture and collaborate across teams to ensure that our operations are secure, compliant, and aligned with regulatory and industry best practices - such as SOC2. What you'll do: Leverage your extensive experience in Cloud Security to design, implement, and improve secure cloud-native architectures and CI/CD pipelines. Apply deep expertise in cloud infrastructure security to proactively identify risks, enforce best practices, and harden systems across the entire technology stack. Automate security controls and educate developers for future-proofing against vulnerabilities. Play an active part in designing and evolving the company’s overall information security governance and compliance program through: policies, standards, procedures, awareness. Work closely with engineering, infrastructure, and product teams to make sure controls fit both business objectives and technical realities. What you'll need: 5+ years of experience in a security engineering role. Mastery of cloud infrastructure, particularly AWS. Prior experience focusing on infrastructure security and Kubernetes. Familiarity with secret management tools like Vault or KMS. Strong understanding of core information security concepts and major regulatory frameworks/standards (e.g. SOC2, ISO 27001, NIST CSF). Experience conducting security design reviews, threat modelling, and security testing. Excellent written and verbal communication skills, with the ability to present complex technical details as clear, risk-focused recommendations. Perks: Remote-first global workforce + NY office Professional reimbursement program (facilitates industry conference attendance, certifications, and more) Medical, dental & vision coverage (US + some other countries) 401k retirement plan + company match (US only) Wellness stipend Home office set up / ergonomic equipment program Attention Offchain Job Seekers: This role cannot be performed in California, or Colorado. Please be advised that there has been a rise in fraudulent recruiter activities, particularly within the Web3 space. If you would like to confirm whether someone is an Offchain employee or the legitimacy of an offer you received, please email At Offchain, we are committed to building a welcoming and supportive workplace for all employees, regardless of their background or identity. We strive to create an environment where everyone feels valued and has an equal opportunity to succeed and thrive. We encourage candidates from all walks of life to apply and join our team. Originally posted on Himalayas

Security Engineer
AlertMedia
IN, USA; Austin, TX, USA
AlertMedia Jobs Security Engineer AlertMedia Security Engineer Job Posted 5 Days Ago Reposted 5 Days Ago Easy Apply 2 Locations Remote or Hybrid Mid level Artificial Intelligence • Cloud • Information Technology • Security • Social Impact • Software AlertMedia helps companies keep their people safe, informed, and connected during emergencies and other critical events. The Role Designs and improves security controls across software, applications, CI/CD workflows, and AWS infrastructure. Strengthens monitoring, detection, and incident response; supports SOC 2 and ISO audits; and advises Engineering, Sales, Legal, and enterprise customers on security architecture and compliance. The role requires hands-on cloud security expertise, application security knowledge, strong communication, and the ability to lead customer security reviews and technical discussions. Summary Generated by Built In Do work that matters. At AlertMedia , we help organizations protect their people, operations, and brand. Our modern Risk Intelligence and Response platform empowers teams to detect emerging threats, assess impact, and respond with confidence. We believe building resilience should be simpler—and it starts with bringing critical information and workflows together in one unified platform. Our core values drive us in our important mission of keeping people safe & informed: We’re humans not robots Customers always come first We work better together Simplicity is our strength Our reputation is priceless Hard work pays off As one of the fastest growing software companies in the nation, we’re focused on finding the best talent and building the best team to continue accelerating our rapid growth to keep up with our demand. We’re also an AI-forward company, and we expect everyone on our team to use modern AI tools such as Claude, ChatGPT, and others, to work smarter, move faster, and optimize processes. Who you are: You are a hands-on Security Engineer who can translate security and compliance requirements into practical technical solutions. You communicate clearly with technical and nontechnical audiences and enjoy working across teams. You are comfortable balancing cloud security, application security, compliance, and customer-facing responsibilities in a fast-paced environment. What you get to do every day: Partner with Engineering to design, implement, and improve security controls across AlertMedia’s software, application architecture, and AWS infrastructure. Strengthen security monitoring, detection, and incident response capabilities. Integrate security controls into continuous integration and continuous delivery (CI/CD) pipelines and software development workflows. Support compliance efforts, including SOC 2 and ISO audits. Lead the technical portions of enterprise customer security reviews and architecture discussions. Develop deep knowledge of AlertMedia’s software and advise Sales and Legal on customer security questions. Clearly communicate security risks, requirements, and recommendations to technical teams, business partners, and customers. Identify opportunities to improve security and compliance controls across the product and infrastructure. What you bring to the role: Three or more years of experience in security engineering, information security, compliance, or a related role. Must have hands-on experience securing AWS environments. Experience with AWS security services such as: Identity and Access Management, Virtual Private Cloud, Key Management Service, Web Application Firewall, Security Hub, GuardDuty, and Macie. Knowledge of identity and access management, encryption standards, cloud infrastructure, and security tooling. Experience integrating security into CI/CD pipelines and software development workflows. Experience supporting SOC 2 and/or ISO audits. Experience supporting application security, cloud security, or incident response programs. Experience participating in customer security reviews and explaining technical concepts to different audiences. Experience leading technical security or architecture discussions with enterprise customers. Strong analytical, project management, organization, and prioritization skills. A collaborative and adaptable approach, with the ability to work effectively across technical and business teams. Location: This is a remote, U.S.-based position. Please note that we currently do not hire candidates residing in the following states: Alaska, California, Hawaii, Louisiana, Mississippi, Montana, New Hampshire, North Dakota, Oregon, Pennsylvania, Rhode Island, Vermont, Washington, West Virginia, and Wyoming Sponsorship: AlertMedia does not sponsor employment visas. Candidates must have existing authorization to work in the U.S. without the need for sponsorship now or in the future. Why you’ll love working at AlertMedia: At AlertMedia, you won’t just build your career — you’ll be part of something meaningful, surrounded by people who genuinely care about the work and each other. Competitive base salary + Company-wide bonus program Generous and flexible time off and parental leave policies Health benefits - Medical, Dental, Vision and Life Insurance are 100% paid for employees! 401K with generous company match Amazing rewards and incentives – we love celebrating each other! Commitment to community service with opportunities to give back A Best Places to Work company 10 years in a row and numerous other awards Access to new downtown office with 360 views of Austin, high-tech building gym and nearby running trails Ongoing career development opportunities through our Learning & Development team You'll do meaningful work—while growing your career in a fast-moving, global company with an award-winning culture About AlertMedia: We are the leading risk intelligence and response platform — trusted by the largest companies in the world to protect their people and assets when it matters most. We are a high-growth, PE-backed SaaS company with more than 4,000 clients scaling rapidly across the globe. Our technology is unmatched with a unified platform, a 7+year history of AI innovation, a customer NPS of 70+, and a culture that sets us even further apart from our competition. We are an equal opportunity employer focused on creating a collaborative and exciting place for all to work. Ensuring a diverse, inclusive, and equitable workplace for all people is key to our success and core to our values. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. This is an amazing opportunity to be part of our wave of momentum and take our company, and your career, to the next growth stage. We'd love to get to know you better and share how we serve our amazing customers. For more information, please visit www.alertmedia.com . Come join us in our mission to save lives and minimize loss through effective communication. By applying for the role, you agree that Alert Media will use your Personal Information in connection with the recruitment process and in accordance with our Privacy Policy – https://www.alertmedia.com/legal/privacy-policy/ Read Full Description Skills Required Three or more years of experience in security engineering, information security, compliance, or a related role Hands-on experience securing AWS environments Experience with AWS security services including IAM, VPC, KMS, WAF, Security Hub, GuardDuty, and Macie Knowledge of identity and access management, encryption standards, cloud infrastructure, and security tooling Experience integrating security into CI/CD pipelines and software development workflows Experience supporting SOC 2 and/or ISO audits Experience supporting application security, cloud security, or incident response programs Experience participating in customer security reviews and explaining technical concepts to different audiences Experience leading technical security or architecture discussions with enterprise customers Strong analytical, project management, organization, and prioritization skills Collaborative and adaptable approach with the ability to work effectively across technical and business teams Existing authorization to work in the United States without current or future employment visa sponsorship What the Team is Saying Zach Strategic Partnerships Manager I joined for the opportunity to learn from a leadership team with a proven track record of success and to help build a company with a solution that saves lives while disrupting our industry. Zach Strategic Partnerships Manager I joined for the opportunity to learn from a leadership team with a proven track record of success and to help build a company with a solution that saves lives while disrupting our industry. Talia Account Executive With no prior sales experience, I used to struggle with imposter syndrome. AlertMedia recognized my potential and provided the support and guidance for me to be successful! I'm so glad I took that leap of faith with a company that continuously invests in my future! Liel Enterprise Sales Director We have annual leadership awards tied to a company trip for top performers and on the first Tuesday lunch of each quarter, we give out peer-nominated awards. It is awesome to be recognized from both perspectives. Matt Software Architect To be a successful developer at AlertMedia you will need to be smart and passionate about great code. Our most valuable developers consistently "check their ego at the door" and focus exclusively on the best solution for the problem. Peter SVP of Safety Solutions AlertMedia is inherently a very collaborative culture. No one here is above helping others, including our executive leadership team. We are readily available to assist through negotiations, demos, customer calls or to simply provide guidance. Time is never wasted on someone who cares and is focusing their effort on the right things. Alex Chief Marketing Officer Given our current size, collaboration comes easily, but as we grow, we have been even more intentional about how we work with each department. For example, our team often drops in on the weekly Sales meetings, holds a weekly meeting with the Sales team leads, and has a Slack channel with all of Sales so people can share ideas and ask questions. AlertMedia Compensation & Benefits Highlights Healthcare Strength — Healthcare is considered a standout, with fully employer‑paid medical, dental, vision, disability, and life insurance for employees and subsidized options for dependents. Mental‑health resources and FSA/HSA options add depth to the coverage. Parental & Family Support — Family support is notable through fully paid parental and new‑child bonding leave for birthing and secondary caregivers. Carrot family‑forming benefits and adoption assistance further extend support. Leave & Time Off Breadth — Time away is broad, featuring flexible/unlimited PTO, paid holidays and wellness days, and a paid sabbatical after a long‑tenure milestone. These programs are framed to encourage employees to unplug and recharge. Learn more about AlertMedia's Compensation & Benefits → AlertMedia Insights What's It Like to Work at AlertMedia? AlertMedia Culture & Values AlertMedia Career Growth & Development What's the Work-Life Balance Like at AlertMedia? AlertMedia Leadership & Management AlertMedia Company Growth, Stability & Outlook View all jobs at AlertMedia View AlertMedia Profile Report Job Am I A Good Fit? beta Get Personalized Job Insights. Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align. Upload Resume Upload Resume Success! Refresh the page to see how your skills align with this role. The Company HQ: Austin, TX 450 Employees Year Founded: 2013 What We Do AlertMedia helps organizations protect their people and businesses through all phases of an emergency. Our award-winning threat intelligence, emergency communication, and travel risk management solutions help companies of all sizes identify, respond to, and recover from critical events faster and more confidently. Our team of in-house intelligence analysts and meteorologists work around the clock to monitor thousands of data sources around the world, providing our customers and employees with verified, credible information to protect them from impending threats. AlertMedia has been recognized both nationally and locally for its exceptional company culture, most recently being named to Inc. Magazine’s Best Workplaces list for 2023. We were also named to Forbes’ list of America’s Best Startup Employers for two consecutive years, Austin Business Journal’s Best Places to Work for nine consecutive years, and Built In Austin’s 100 Best Places to Work in Austin. Located in the heart of downtown Austin in the "smartest building in the city", AlertMedia inspires and invests in our employees through continuous developmental experiences, including Career Month, community volunteering, mentorship programs, Employee Resource Groups, and weekly "Tuesday Lunches" where the company comes together to learn about and discuss any business updates. AlertMedia also facilitates a robust internship program, working with universities (including HBCUs), non-profit organizations like Hiring Our Heroes, and similar partners to invest in the future of our diverse workforce. Why Work With Us AlertMedia employees have a strong connection to our mission and product. An anonymous employee survey recently revealed 99% of our people feel the work they do is important and making a direct impact, 94% feel our diverse, grow-from-within culture is collaborative and supportive, and 92% are taking advantage of our career development opportunities Gallery AlertMedia Teams Learn More Mexico City About our Teams Option 1 of 1 AlertMedia Offices Learn More Hybrid Workspace Employees engage in a combination of remote and on-site work. Our hybrid policy provides flexibility so employees can work and collaborate from home or in our Austin offices, either full- or part-time. We ask employees in Austin to join us on Tuesday for company-sponsored lunch to connect and learn together. Typical time on-site: 2 days a week HQ Austin, TX MX London, GB Learn more 1 2 Option 1 of 2 Similar Jobs AlertMedia Strategic Intelligence Analyst (Americas) Artificial Intelligence • Cloud • Information Technology • Security • Social Impact • Software Easy Apply Remote or Hybrid 2 Locations 450 Employees AlertMedia Senior Product Manager Artificial Intelligence • Cloud • Information Technology • Security • Social Impact • Software Easy Apply Remote or Hybrid 2 Locations 450 Employees AlertMedia Product Manager Artificial Intelligence • Cloud • Information Technology • Security • Social Impact • Software Easy Apply Remote or Hybrid 2 Locations 450 Employees AlertMedia Financial Systems Manager Artificial Intelligence • Cloud • Information Technology • Security • Social Impact • Software Easy Apply Remote or Hybrid 2 Locations 450 Employees View all jobs at AlertMedia View AlertMedia Profile Report Job Not Eligible Save You are not eligible to apply because your location does not meet the criteria for this role. Not Eligible Save Apply Instructions Send resume to Sign up now Access later Create Free Account Already have an account? Log In .unAuthenticated-modal::backdrop { position: fixed; background: rgba(0, 0, 0, 0.5); } .dot { padding: 2px; border-radius: 50%; } .px-5xl { padding-left: 5rem !important; padding-right: 5rem !important; } .bg-daffodil { background-color: #ffed00 !important; } .gradient-blueberry { background-image: linear-gradient(312deg, rgb(36, 79, 231) 2%, rgb(10, 14, 92) 94%); } Please log in or sign up to report this job. Create Free Account Already have an account? Log In .unAuthenticated-modal::backdrop { position: fixed; background: rgba(0, 0, 0, 0.5); } .dot { padding: 2px; border-radius: 50%; } .px-5xl { padding-left: 5rem !important; padding-right: 5rem !important; } .bg-daffodil { background-color: #ffed00 !important; } .gradient-blueberry { background-image: linear-gradient(312deg, rgb(36, 79, 231) 2%, rgb(10, 14, 92) 94%); }
Security Engineer
AlertMedia
United States
Do work that matters. At AlertMedia, we help organizations protect their people, operations, and brand. Our modern Risk Intelligence and Response platform empowers teams to detect emerging threats, assess impact, and respond with confidence. We believe building resilience should be simpler—and it starts with bringing critical information and workflows together in one unified platform. Our core values drive us in our important mission of keeping people safe & informed: We’re humans not robots Customers always come first We work better together Simplicity is our strength Our reputation is priceless Hard work pays off As one of the fastest growing software companies in the nation, we’re focused on finding the best talent and building the best team to continue accelerating our rapid growth to keep up with our demand. We’re also an AI-forward company, and we expect everyone on our team to use modern AI tools such as Claude, ChatGPT, and others, to work smarter, move faster, and optimize processes. Who you are: You are a hands-on Security Engineer who can translate security and compliance requirements into practical technical solutions. You communicate clearly with technical and nontechnical audiences and enjoy working across teams. You are comfortable balancing cloud security, application security, compliance, and customer-facing responsibilities in a fast-paced environment. What you get to do every day: Partner with Engineering to design, implement, and improve security controls across AlertMedia’s software, application architecture, and AWS infrastructure. Strengthen security monitoring, detection, and incident response capabilities. Integrate security controls into continuous integration and continuous delivery (CI/CD) pipelines and software development workflows. Support compliance efforts, including SOC 2 and ISO audits. Lead the technical portions of enterprise customer security reviews and architecture discussions. Develop deep knowledge of AlertMedia’s software and advise Sales and Legal on customer security questions. Clearly communicate security risks, requirements, and recommendations to technical teams, business partners, and customers. Identify opportunities to improve security and compliance controls across the product and infrastructure. What you bring to the role: Three or more years of experience in security engineering, information security, compliance, or a related role. Must have hands-on experience securing AWS environments. Experience with AWS security services such as: Identity and Access Management, Virtual Private Cloud, Key Management Service, Web Application Firewall, Security Hub, GuardDuty, and Macie. Knowledge of identity and access management, encryption standards, cloud infrastructure, and security tooling. Experience integrating security into CI/CD pipelines and software development workflows. Experience supporting SOC 2 and/or ISO audits. Experience supporting application security, cloud security, or incident response programs. Experience participating in customer security reviews and explaining technical concepts to different audiences. Experience leading technical security or architecture discussions with enterprise customers. Strong analytical, project management, organization, and prioritization skills. A collaborative and adaptable approach, with the ability to work effectively across technical and business teams. Location: This is a remote, U.S.-based position. Please note that we currently do not hire candidates residing in the following states: Alaska, California, Hawaii, Louisiana, Mississippi, Montana, New Hampshire, North Dakota, Oregon, Pennsylvania, Rhode Island, Vermont, Washington, West Virginia, and Wyoming Sponsorship: AlertMedia does not sponsor employment visas. Candidates must have existing authorization to work in the U.S. without the need for sponsorship now or in the future. Why you’ll love working at AlertMedia: At AlertMedia, you won’t just build your career — you’ll be part of something meaningful, surrounded by people who genuinely care about the work and each other. Competitive base salary + Company-wide bonus program Generous and flexible time off and parental leave policies Health benefits - Medical, Dental, Vision and Life Insurance are 100% paid for employees! 401K with generous company match Amazing rewards and incentives – we love celebrating each other! Commitment to community service with opportunities to give back A Best Places to Work company 10 years in a row and numerous other awards Access to new downtown office with 360 views of Austin, high-tech building gym and nearby running trails Ongoing career development opportunities through our Learning & Development team You'll do meaningful work—while growing your career in a fast-moving, global company with an award-winning culture About AlertMedia: We are the leading risk intelligence and response platform — trusted by the largest companies in the world to protect their people and assets when it matters most. We are a high-growth, PE-backed SaaS company with more than 4,000 clients scaling rapidly across the globe. Our technology is unmatched with a unified platform, a 7+year history of AI innovation, a customer NPS of 70+, and a culture that sets us even further apart from our competition. We are an equal opportunity employer focused on creating a collaborative and exciting place for all to work. Ensuring a diverse, inclusive, and equitable workplace for all people is key to our success and core to our values. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. This is an amazing opportunity to be part of our wave of momentum and take our company, and your career, to the next growth stage. We'd love to get to know you better and share how we serve our amazing customers. For more information, please visit . Come join us in our mission to save lives and minimize loss through effective communication. By applying for the role, you agree that Alert Media will use your Personal Information in connection with the recruitment process and in accordance with our Privacy Policy – Originally posted on Himalayas
Security Engineer
AlertMedia
United States
Do work that matters. At AlertMedia, we help organizations protect their people, operations, and brand. Our modern Risk Intelligence and Response platform empowers teams to detect emerging threats, assess impact, and respond with confidence. We believe building resilience should be simpler—and it starts with bringing critical information and workflows together in one unified platform. Our core values drive us in our important mission of keeping people safe & informed: We’re humans not robots Customers always come first We work better together Simplicity is our strength Our reputation is priceless Hard work pays off As one of the fastest growing software companies in the nation, we’re focused on finding the best talent and building the best team to continue accelerating our rapid growth to keep up with our demand. We’re also an AI-forward company, and we expect everyone on our team to use modern AI tools such as Claude, ChatGPT, and others, to work smarter, move faster, and optimize processes. Who you are: You are a hands-on Security Engineer who can translate security and compliance requirements into practical technical solutions. You communicate clearly with technical and nontechnical audiences and enjoy working across teams. You are comfortable balancing cloud security, application security, compliance, and customer-facing responsibilities in a fast-paced environment. What you get to do every day: Partner with Engineering to design, implement, and improve security controls across AlertMedia’s software, application architecture, and AWS infrastructure. Strengthen security monitoring, detection, and incident response capabilities. Integrate security controls into continuous integration and continuous delivery (CI/CD) pipelines and software development workflows. Support compliance efforts, including SOC 2 and ISO audits. Lead the technical portions of enterprise customer security reviews and architecture discussions. Develop deep knowledge of AlertMedia’s software and advise Sales and Legal on customer security questions. Clearly communicate security risks, requirements, and recommendations to technical teams, business partners, and customers. Identify opportunities to improve security and compliance controls across the product and infrastructure. What you bring to the role: Three or more years of experience in security engineering, information security, compliance, or a related role. Must have hands-on experience securing AWS environments. Experience with AWS security services such as: Identity and Access Management, Virtual Private Cloud, Key Management Service, Web Application Firewall, Security Hub, GuardDuty, and Macie. Knowledge of identity and access management, encryption standards, cloud infrastructure, and security tooling. Experience integrating security into CI/CD pipelines and software development workflows. Experience supporting SOC 2 and/or ISO audits. Experience supporting application security, cloud security, or incident response programs. Experience participating in customer security reviews and explaining technical concepts to different audiences. Experience leading technical security or architecture discussions with enterprise customers. Strong analytical, project management, organization, and prioritization skills. A collaborative and adaptable approach, with the ability to work effectively across technical and business teams. Location: This is a remote, U.S.-based position. Please note that we currently do not hire candidates residing in the following states: Alaska, California, Hawaii, Louisiana, Mississippi, Montana, New Hampshire, North Dakota, Oregon, Pennsylvania, Rhode Island, Vermont, Washington, West Virginia, and Wyoming Sponsorship: AlertMedia does not sponsor employment visas. Candidates must have existing authorization to work in the U.S. without the need for sponsorship now or in the future. Why you’ll love working at AlertMedia: At AlertMedia, you won’t just build your career — you’ll be part of something meaningful, surrounded by people who genuinely care about the work and each other. Competitive base salary + Company-wide bonus program Generous and flexible time off and parental leave policies Health benefits - Medical, Dental, Vision and Life Insurance are 100% paid for employees! 401K with generous company match Amazing rewards and incentives – we love celebrating each other! Commitment to community service with opportunities to give back A Best Places to Work company 10 years in a row and numerous other awards Access to new downtown office with 360 views of Austin, high-tech building gym and nearby running trails Ongoing career development opportunities through our Learning & Development team You'll do meaningful work—while growing your career in a fast-moving, global company with an award-winning culture About AlertMedia: We are the leading risk intelligence and response platform — trusted by the largest companies in the world to protect their people and assets when it matters most. We are a high-growth, PE-backed SaaS company with more than 4,000 clients scaling rapidly across the globe. Our technology is unmatched with a unified platform, a 7+year history of AI innovation, a customer NPS of 70+, and a culture that sets us even further apart from our competition. We are an equal opportunity employer focused on creating a collaborative and exciting place for all to work. Ensuring a diverse, inclusive, and equitable workplace for all people is key to our success and core to our values. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. This is an amazing opportunity to be part of our wave of momentum and take our company, and your career, to the next growth stage. We'd love to get to know you better and share how we serve our amazing customers. For more information, please visit . Come join us in our mission to save lives and minimize loss through effective communication. By applying for the role, you agree that Alert Media will use your Personal Information in connection with the recruitment process and in accordance with our Privacy Policy – Originally posted on Himalayas
Security Engineer
Figma
United States
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! As a Security Engineer you will identify and drive impactful projects to improve the security of Figma’s product, platform, and IT systems. We are hiring for multiple teams within Security Engineering: AI Security, Platform Security, Product Security, and Anti-Abuse. This is a remote first role. You will partner closely with teams across the company and focus on systemic security improvements and risk reduction. You will also participate in operational security responsibilities like security reviews, consulting, vulnerability triage, and security incident response. Examples of what you may work on across teams: AI Security Perform technical security assessments, code audits, and design reviews for new AI infrastructure, platforms, and products. Design and develop technical solutions to secure AI models, tooling, debugging workflows, and data pipelines. Advocate for secure practices across Figma’s AI infrastructure, platforms, and data systems. Build the next generation of internal AI-powered access insights and security tooling. Help run penetration testing and offensive security exercises against Figma’s AI infrastructure, platforms, and products. Platform Security Perform technical security assessments, code audits, and design reviews for changes to Figma’s cloud and corporate infrastructure. Design and develop solutions to prevent or mitigate cloud and corporate security risks. Advocate for secure practices within Figma’s cloud and corporate infrastructure. Build platforms and tooling to detect and respond to infrastructure and corporate security threats. Product Security Perform technical security assessments, code audits, and design reviews for new product features. Design and develop solutions to prevent or mitigate product security vulnerabilities. Advocate for secure development practices across Figma’s products and services. Help run penetration testing, offensive security exercises, and support our bug bounty program. Help respond to product security incidents. Anti-Abuse Design and build technical systems to prevent spam, fraud, and abuse. Partner closely with product teams to identify and address potential abuse vectors. Develop new signals and improve the use of existing signals to detect abusive behavior. Help respond to spam, fraud, and abuse incidents. This is a full-time role that can be held from one of our US hubs or remotely in the United States. We’d love to hear from you if you have: 5+ years of proven engineering experience working in either a Security Engineering or a Software Engineering role. In the case of the latter, some security experience is preferred. Strong security judgment in threat modeling and risk prioritization and/or strong technical judgment in designing and building maintainable, scalable systems. Proficiency in at least one general-purpose coding language. Strong communication and interpersonal skills, with demonstrated experience collaborating across functions. While not required, it’s an added plus if you also have: Subject matter expertise in Application Security, Cloud Security, Corporate Security, Data Access Governance, and/or IAM (Identity and Access Management). Demonstrated ability to make hard prioritization decisions in security controls. At Figma, one of our values is Grow as you go. We believe in hiring smart, curious people who are excited to learn and develop their skills. If you’re excited about this role but your past experience doesn’t align perfectly with the points outlined in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles. #LI-Remote Pay Transparency Disclosure Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. Figma offers equity to employees, as well as a competitive package of additional benefits, including health, dental, and vision coverage; retirement benefits with company contributions; parental leave and reproductive or family planning support; mental health and wellness benefits; and paid time off. Figma provides paid sick leave, holidays, and other leave benefits in compliance with applicable federal, state, and local laws, including the requirements of the Washington Minimum Wage Act and related regulations. Exempt employees are eligible for employer‑provided paid flexible PTO in addition to flexible paid sick leave. PTO is subject to manager approval. Additional benefits may include company recharge days, cell phone and home internet reimbursements, and a number of lifestyle spending accounts. Figma also offers sales incentive compensation for most sales roles and an annual bonus plan for eligible non-sales roles. All compensation and benefits are subject to applicable plan terms and may be modified by Figma at any time, consistent with applicable law. Annual Base Salary Range: $153,000—$376,000 USD At Figma we celebrate and support our differences. We know employing a team rich in diverse thoughts, experiences, and opinions allows our employees, our product and our community to flourish. Figma is an equal opportunity workplace - we are dedicated to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity/expression, veteran status, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. We will work to ensure individuals with disabilities are provided reasonable accommodation to apply for a role, participate in the interview process, perform essential job functions, and receive other benefits and privileges of employment. If you require accommodation, please reach out to accommodations-ext@figma.com. These modifications enable an individual with a disability to have an equal opportunity not only to get a job, but successfully perform their job tasks to the same extent as people without disabilities. Examples of accommodations include but are not limited to: Holding interviews in an accessible location Enabling closed captioning on video conferencing Ensuring all written communication be compatible with screen readers Changing the mode or format of interviews To ensure the integrity of our hiring process and facilitate a more personal connection, we require all candidates keep their cameras on during video interviews. Additionally, if hired you will be required to attend in person onboarding. By applying for this job, the candidate acknowledges and agrees that any personal data contained in their application or supporting materials will be processed in accordance with Figma's Candidate Privacy Notice.
Security Engineer
Stripe
United States
Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career. About the team Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE bridges the gap using real attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale. We partner closely with Fraud, Risk and Product Engineering to run rigorous experiments, balancing aggressive risk mitigation against legitimate user conversion. Operating as both a strike team and an incubator, ACE builds automated regression suites in partnership with Abuse Research to permanently block threat recurrence and seamlessly transfers mature controls to long-term product owners across Stripe. What you’ll do As an Abuse Control Engineer on the Abuse Control Engineering (ACE) team, you will design, prototype, and incubate technical defenses that safeguard Stripe’s financial ecosystem against complex, cross-cutting abuse vectors. Where emerging threat patterns identify Stripe product weaknesses, ACE steps in to rapidly build and experiment with technical safeguards. Driven by empirical evidence and Stripe’s FT3 (Fraud Taxonomy 3.0) framework, you will translate threat intelligence into hard technical control requirements (e.g., API rate-limiting, step-up challenges, parameter validation, pre-debit holds). You will carefully balance security and product velocity, running experiments to evaluate risk reduction against user conversion impact. Managing controls through a strict incubation lifecycle, you will build automated regression suites to prevent recurrence and partner with native product teams to hand off mature, long-term defenses. Responsibilities Rapid Control Prototyping: Design, prototype, and deploy technical controls across API, protocol, and product boundaries to immediately close high-impact abuse vectors. Evidence-Based Technical Requirements: Translate empirical attacker evidence and FT3 threat research Abuse Research, Fraud and Security into precise technical abuse requirements and control specifications. Control Co-Design: Collaborate closely with teams across Stripe to co-design resilient, secure controls across payment, onboarding, identity, and Connect surfaces. Risk Experimentation: Run rigorous experiments and A/B tests to measure risk reduction against legitimate user conversion impact, optimizing controls to minimize friction while neutralizing threats. Regression Testing: Build comprehensive regression testing suites and automated attack simulations with Abuse Research to ensure mitigated abuse vectors do not recur. Stakeholder Management: Execute ACE’s incubation model by defining handoff criteria, operational documentation, and target dates to transfer successful controls to product teams. Who you are We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement. Minimum requirements 3+ years of experience in Security Engineering, Software Engineering, Application Security, or Anti-Abuse Engineering in a high-scale production environment. B.S. or M.S. in Computer Science, Cybersecurity, Software Engineering, or a related technical field, or equivalent practical experience. Strong software development background with expert proficiency in Python, Go, Java, or similar production languages, alongside expert SQL skills for analyzing system telemetry. Hands-on engineering experience building API-level safeguards, rate-limiting frameworks, authentication/authorization checks, or input validation controls. Demonstrated experience with automated testing frameworks, including writing unit, integration, and regression tests for critical backend software. Strong cross-functional collaboration and communication skills, with a track record of partnering across security, product, and platform teams to drive technical outcomes. Preferred qualifications Proven track record of designing and executing A/B tests, evaluating control efficacy, and balancing security safeguards against user conversion friction. Deep expertise in threat modeling, secure system architecture, and modern application security design principles. Familiarity with established threat frameworks (e.g., FT3, MITRE ATT&CK) and applying adversary kill chain analysis to build resilient defenses. Strong domain knowledge of financial fraud vectors, threat actor TTPs, and attacker infrastructure (e.g., Account Takeover, Card Testing, Credential Stuffing). Hands-on experience with large-scale data processing platforms (e.g., Databricks, Trino, PySpark) to monitor and measure control performance across distributed systems. Demonstrated capability in incubating software features, establishing clear operational handoff criteria, and seamlessly transitioning ownership to partner engineering teams. Originally posted on Himalayas
Security Engineer
Stripe
United States
Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career. About the team Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE bridges the gap using real attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale. We partner closely with Fraud, Risk and Product Engineering to run rigorous experiments, balancing aggressive risk mitigation against legitimate user conversion. Operating as both a strike team and an incubator, ACE builds automated regression suites in partnership with Abuse Research to permanently block threat recurrence and seamlessly transfers mature controls to long-term product owners across Stripe. What you’ll do As an Abuse Control Engineer on the Abuse Control Engineering (ACE) team, you will design, prototype, and incubate technical defenses that safeguard Stripe’s financial ecosystem against complex, cross-cutting abuse vectors. Where emerging threat patterns identify Stripe product weaknesses, ACE steps in to rapidly build and experiment with technical safeguards. Driven by empirical evidence and Stripe’s FT3 (Fraud Taxonomy 3.0) framework, you will translate threat intelligence into hard technical control requirements (e.g., API rate-limiting, step-up challenges, parameter validation, pre-debit holds). You will carefully balance security and product velocity, running experiments to evaluate risk reduction against user conversion impact. Managing controls through a strict incubation lifecycle, you will build automated regression suites to prevent recurrence and partner with native product teams to hand off mature, long-term defenses. Responsibilities Rapid Control Prototyping: Design, prototype, and deploy technical controls across API, protocol, and product boundaries to immediately close high-impact abuse vectors. Evidence-Based Technical Requirements: Translate empirical attacker evidence and FT3 threat research Abuse Research, Fraud and Security into precise technical abuse requirements and control specifications. Control Co-Design: Collaborate closely with teams across Stripe to co-design resilient, secure controls across payment, onboarding, identity, and Connect surfaces. Risk Experimentation: Run rigorous experiments and A/B tests to measure risk reduction against legitimate user conversion impact, optimizing controls to minimize friction while neutralizing threats. Regression Testing: Build comprehensive regression testing suites and automated attack simulations with Abuse Research to ensure mitigated abuse vectors do not recur. Stakeholder Management: Execute ACE’s incubation model by defining handoff criteria, operational documentation, and target dates to transfer successful controls to product teams. Who you are We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement. Minimum requirements 3+ years of experience in Security Engineering, Software Engineering, Application Security, or Anti-Abuse Engineering in a high-scale production environment. B.S. or M.S. in Computer Science, Cybersecurity, Software Engineering, or a related technical field, or equivalent practical experience. Strong software development background with expert proficiency in Python, Go, Java, or similar production languages, alongside expert SQL skills for analyzing system telemetry. Hands-on engineering experience building API-level safeguards, rate-limiting frameworks, authentication/authorization checks, or input validation controls. Demonstrated experience with automated testing frameworks, including writing unit, integration, and regression tests for critical backend software. Strong cross-functional collaboration and communication skills, with a track record of partnering across security, product, and platform teams to drive technical outcomes. Preferred qualifications Proven track record of designing and executing A/B tests, evaluating control efficacy, and balancing security safeguards against user conversion friction. Deep expertise in threat modeling, secure system architecture, and modern application security design principles. Familiarity with established threat frameworks (e.g., FT3, MITRE ATT&CK) and applying adversary kill chain analysis to build resilient defenses. Strong domain knowledge of financial fraud vectors, threat actor TTPs, and attacker infrastructure (e.g., Account Takeover, Card Testing, Credential Stuffing). Hands-on experience with large-scale data processing platforms (e.g., Databricks, Trino, PySpark) to monitor and measure control performance across distributed systems. Demonstrated capability in incubating software features, establishing clear operational handoff criteria, and seamlessly transitioning ownership to partner engineering teams.