Job Closed
This listing is no longer active.
Making cities move more efficiently
Lead Security Engineer
Location
United States + 1 moreAll locations: United States | Canada
Posted
88 days ago
Salary
$140K - $200K / year
Job Description
Lead Security Engineer
Swiftly, Inc.
Company Description Swiftly is on a mission to help cities move more efficiently. We are the leading transit data platform for agencies to share real-time passenger information, manage day-to-day operations, and improve service performance. Today, over 200 transit agencies in 12 countries – including LA Metro, MARTA, SEPTA, and MBTA – rely on Swiftly to improve on-time performance by up to 40% and increase passenger information accuracy by up to 50%. The result is better service reliability, increased ridership, and more efficient transit operations. Even though Swiftly's HQ office is located in San Francisco, CA, we are open to candidates in most locations across the U.S. as well as Ontario and British Columbia, Canada. At this time we are unable to provide Visa sponsorship. Engineering at Swiftly Engineering at Swiftly is not only about writing code – we believe in creating empowered product teams that work together to conceptualize new features and bring them to life. Each team aims to strike a balance between delivering incremental improvements, creating prototypes to test new ideas and mitigate risks, and building scalable software using industry best practices. We’re guided by a mission to positively impact transit riders, and we embrace humility and intentionality in how we make technical decisions so that we best meet our customers’ needs. About the Role We're looking for a Lead Security Engineer to join our Platform and Security team and help build on Swiftly's security posture. Our team owns both compliance and security, grounding compliance in real security work; it's not a checklist exercise for us. We hold SOC 2 Type II certification and are expanding into additional compliance frameworks. You'll take dedicated ownership of this work as it grows. In this role, you'll partner closely with engineering, product, and go-to-market teams to design secure solutions, build DevSecOps tooling, and drive our compliance roadmap. You'll balance strategic initiatives with hands-on work in our cloud-native environment. We're looking for someone equally comfortable working in codebases and leading cross-functional initiatives; a force multiplier who can train teams, represent security to customers and executives, and make security a natural part of how Swiftly ships products. You'll have full visibility into quarterly planning, sprint ceremonies, and team roadmaps. Our open culture values input from all Swiftlets, and you'll have all the context you need to build out a robust security roadmap. We believe excellent security isn't just about tools and controls; it's about empowering product, infrastructure, and corporate IT teams to make secure decisions every day. As you onboard, you'll focus on the highest-impact areas while drawing on the expertise, support, and shared responsibility of our existing team * We use AI tools for scheduling and summarization in our hiring process. We do not use AI tools to make decisions about who moves forward or to assess the strength of candidates. Every application is reviewed and all hiring decisions are made by Swiftly team members. This is an active, open role that we are currently hiring for at Swiftly. What You'll Do Make Swiftly Secure - Own Swiftly's security risk register and threat models; identify, prioritize, and drive remediation of risks across application and infrastructure. - Design secure architectures for our SaaS platform, mobile applications, and IOT/Hardware Integration, focusing on authentication, authorization, data protection, and network boundaries - Recommend, implement, and manage security tools end-to-end - Build DevSecOps guardrails into CI/CD so vulnerabilities, misconfigurations, and license issues surface early - Conduct internal security assessments and coordinate engagements with external penetration testers. - Own security policies and standards; ensure they're practical, adopted, and measurable - Define standards for secure adoption of AI coding assistants, building reusable patterns, custom configurations, and guardrails that help developers move fast safely Compliance & Customer Trust - Lead renewals and continuous readiness for existing certifications like SOC 2 - Proactively identify security frameworks required for international expansion; scope cost, level of effort, and timelines to inform market entry decisions; and lead execution of new certifications - Respond to customer security and compliance inquiries and support product marketing with security content Incident Response & Detection - Design and maintain security incident response plans, playbooks, and escalation paths - Serve as an escalation point for security incidents; lead triage, root cause analysis, and remediation Security Leadership - Define and maintain security KPIs and dashboards for executive and board reporting - Give teams visibility into their security posture and coach them to improve - Influence roadmap prioritization to ensure security and compliance are first-class concerns - Mentor engineers in secure design and help grow a security-aware culture across Swiftly by delivering security training and office hours for developers and other stakeholders - Drive corporate IT security strategy, including endpoint hardening, email security, IAM standards, and periodic access reviews What will set you up for success - 5+ years of experience in security engineering with both strategic and hands-on work - Strong experience securing cloud-native environments (AWS preferred), including IAM, networking, logging/monitoring, and secrets management - Hands-on experience with infrastructure-as-code (Terraform) and policy-as-code frameworks (OPA, Sentinel, or similar) - Background building security into CI/CD pipelines and development workflows - Familiarity with container and orchestration security - Excellent threat modeling and risk assessment skills; able to translate complex risks into clear options and tradeoffs - Experience with compliance frameworks (SOC 2 preferred) and audit processes - Strong communication skills; comfortable working across technical and non-technical teams - Self-directed and comfortable operating with autonomy Nice to haves - Relevant certifications (CISSP, cloud security certifications) - Experience advising on security for AI/ML or LLM-powered features - Mobile application security experience (Android preferred) - Experience with GRC and compliance platforms - Background in application security or penetration testing - Experience with international compliance frameworks - Familiarity with regulated industries or public sector requirements - Experience with physical device security (IoT, embedded systems, or field-deployed hardware) - Experience with Mobile Device Management (MDM) solutions for enterprise or fleet deployments Pay Range In accordance with pay transparency laws, please see the approximate salary ranges below. These ranges represents the anticipated low and high end of the salary for this position. Actual salaries will vary and are based on a multitude of non-discriminatory factors including final role leveling decisions, a candidate’s relevant work experiences/skills, and geographic location. Salary is one component of Swiftly’s total compensation package, which also includes stock options, competitive benefits, 401(k)/ RRSP matching, a fantastic team and culture, opportunity to have a huge impact, emphasis on professional growth and holistic wellness, and other perks. US Salary Range: $140,000 - 200,000 Canadian Salary Range: $165,000 - 200,000 Beyond the Skills We are looking for candidates who are passionate about mobility, sustainability, or mission-oriented projects that have a significant real-world impact. Ideal candidates encompass the core values of our company: Team. Together, we are more effective and better supported Impact. Drive impact for our customers, our company, and all of our teams Diversity. See differing perspectives as ways to address our weaknesses and find new strengths Communication. Assume others internally and externally have good intentions Feedback. We share feedback because we want each other to grow professionally and personally Growth. Foster personal, professional, and company growth Benefits: • Competitive salary • Equity compensation (company ownership) for every employee • Medical, Dental and Vision • Retirement with Employer Match • Flexible Spending Account (FSA) • Home office setup reimbursement • Monthly cell/internet reimbursement • Monthly "Be Well" stipend • Flexible PTO with a recommended minimum • Flexible work environment • 16 paid holidays - including months without US national holidays • 8 fully paid weeks of leave for child birth/adoption Travel note: Swiftly employees can generally expect to travel 1–2 times a year for in-person company or team offsites. As a fully distributed company, we consider these offsites important for cultivating strong relationships across our teams! Attending these in-person is expected and encouraged, although we understand everyone has different personal circumstances and we will consider requests for exceptions. Customer-facing team members and other specific roles may be expected to travel more frequently. We are an equal opportunity employer - we are committed to a workplace that is as dynamic, diverse, and passionate as the communities we serve.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Job Description Job Description Required Certificates and Licenses: - Arkansas Department of Education High School Science Teaching Certification Required Residency Requirements: - This position is remote and strongly prefer candidates that reside in Arkansas. Start Date: School Year 2026/2027 The High School Science Teacher is a highly qualified, state certified educator responsible for delivering specific course content in an online environment. Teachers provide instruction, support, and guidance, manage the learning process, and focus on students’ individual needs. Teachers monitor student progress through Stride K12’s learning management system. They actively work closely with students and parents/learning coaches to advance each student’s learning toward established goals. Teachers typically work from home but must travel occasionally throughout the year to various school functions, such as state testing or as otherwise required by the school. K12, a Stride Company, believes in Education for ANYONE. We provide families with an online option for a high-quality, personalized education experience. Students can thrive, find their passion, and learn in an environment that encourages discovery at their own pace. Passionate Educators are needed at the Stride K12 partner school, Arkansas Virtual Academy (ARVA) We want you to be a part of our talented team! The mission of Arkansas Virtual Academy (ARVA) is to provide an exemplary individualized and engaging educational experience for students by incorporating school and community/family partnerships coupled with a rigorous curriculum along with a data-driven and student-centered instructional model. Student success will be measured by valid and reliable assessment data, parent and student satisfaction, and continued institutional growth within the academic community. Join us! This is a full-time position. Ability to work independently, typically 40+ hours per week is required. Ability to maintain a professional home office without distraction during workday, typically 9-5 (or 8-4) or as defined by the school. ESSENTIAL FUNCTIONS: Reasonable accommodation may be made to enable individuals with disabilities to perform their essential duties. - Provides rich and engaging synchronous and asynchronous learning experiences for students - Commitment to personalizing learning for all students - Demonstrates a belief in all students’ ability to succeed and meet high expectations - Differentiates instruction based on student level of mastery - Augments course content according to prescribed policies and procedures using appropriate asynchronous and synchronous tools under guidance from principal and coach - Maintains grade book ensuring student academic integrity, makes student placement and promotion decisions, and alerts administrators to concerns about student performance and progress - Prepares students for high stakes standardized tests - Understands that a primary responsibility is to establish and maintain positive rapport with families and regularly communicates with and responds to students and learning coaches/parents in a timely manner - Supports learning coaches/parents with student curricular and instructional issues, as well as basic troubleshooting in a virtual classroom environment that is in line with academy policies and procedures - Travels as required (on average once per month and/or approximately 20% of the time) for face-to-face professional development, student testing, and as required by school REQUIRED MINIMUM QUALIFICATIONS: - Bachelor's degree AND - Active state teaching license AND - Ability to clear required background check DESIRED QUALIFICATION: - Experience working with proposed age group - High School - Experience supporting adults and children in the use of technology. - Experience teaching in an online (virtual) and/or in a brick-and-mortar environment. - Experience with online learning platforms. - Ability to work collaboratively with other teachers to interpret and produce numeric, tabular, and graphic representations of student data, and use it to drive instructional decisions. - Receptive to receiving coaching regularly with administrators and teacher trainers. - Ability to embrace change and adapt to ensure excellent student outcomes. - Proficient in Microsoft Excel, Outlook, Word, PowerPoint. - Ability to rapidly learn and adapt to new technologies and teaching platforms. - Ability to maintain teacher certification/professional development hours and fluency in K12 systems, programs and curriculum. Compensation & Benefits: Stride, Inc. considers a person’s education, experience, and qualifications, as well as the position’s work location, expected quality and quantity of work, required travel (if any), external market and internal value when determining a new employee’s salary level. Salaries will differ based on these factors, the position’s level and expected contribution, and the employee’s benefits elections. Offers will typically be in the bottom half of the range. Work Environment: The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. - This is a virtual, work-from-home, remote position. Job Type Board Employee_CW The above job is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow any other instructions, and perform any other related duties, as assigned by their supervisor. All employment is “at-will” as governed by the law of the state where the employee works. It is further understood that the “at-will” nature of employment is one aspect of employment that cannot be changed except in writing and signed by an authorized officer. If you are a job seeker with a disability and require a reasonable accommodation to apply for one of our jobs, you can request the appropriate accommodation by contacting stridecareers@k12.com. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities Stride, Inc. is an equal opportunity employer. Applicants receive consideration for employment based on merit without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status, or any other basis prohibited by federal, state, or local law. Stride, Inc. complies with all legally required affirmative action obligations. Applicants will not be discriminated against because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant.
• Conduct analyses using SAST, DAST, and SCA • Implement secure development practices (SSDLC) • Perform security-focused code reviews • Create policies and guidelines for development teams • Perform penetration tests (pentesting) • Configure and operate SIEM tools • Respond to incidents and conduct forensic analyses • Develop and maintain incident response playbooks • Implement security controls in AWS environments • Audit policies in Kubernetes and microservices • Automate security checks in CI/CD pipelines • Work with Infrastructure as Code (IaC) • Evolve the ISMS and support initiatives such as ISO 27001 • Create security policies and standards • Conduct risk assessments and keep security documentation up to date • Support internal and external audits
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description We are seeking a Cybersecurity Engineer to help protect our organization's systems, networks, and data from cyber threats. This role will design, implement, and maintain security controls and technologies while monitoring and responding to security incidents. The ideal candidate is highly analytical, detail-oriented, and passionate about protecting critical systems and information. - Design and implement security solutions to protect infrastructure, networks, and applications. - Monitor systems for security incidents and respond to threats or vulnerabilities. - Conduct vulnerability assessments and penetration testing. - Implement and manage security tools such as SIEM, EDR, firewalls, and intrusion detection systems. - Investigate security alerts and incidents and coordinate remediation efforts. - Ensure compliance with security standards and regulatory requirements. - Develop and maintain security policies, procedures, and documentation. - Perform risk assessments and recommend security improvements. - Collaborate with IT and engineering teams to integrate security into system architecture. - Stay up to date on emerging cybersecurity threats and technologies. Qualifications - Experience with security technologies such as SIEM, IDS/IPS, EDR, firewalls, and endpoint security tools. - Knowledge of network security concepts and protocols. - Experience with vulnerability management and security monitoring. - Strong analytical and incident response skills. - Familiarity with security frameworks such as NIST, ISO 27001, or CIS. Requirements - Experience with cloud security (AWS, Azure, or Google Cloud). - Knowledge of scripting languages such as Python, Bash, or PowerShell. - Experience with penetration testing or threat hunting. - Understanding of DevSecOps practices. - Security certifications such as Security+, CISSP, CEH, or GIAC. Education & Experience - Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field. - 3+ years of experience in cybersecurity or information security. - Relevant certifications preferred.
Senior Developer, Product Security
1PasswordProductive businesses use 1Password to secure employees at scale.
• Work within a small team of developers who are specialists in Rust, Go, Swift, and Security Development • Implement new security features for the next generation of 1Password and develop secure libraries to share common security-critical code across our applications • Assist in security design efforts or scoping initiatives for new features by identifying major tasks and breaking down, estimating, and planning work • Demonstrate leadership in security development and act as a trusted point of contact for management and other developers • Code, test, debug, deliver and maintain production software systems for new and existing product features • Collaborate with a variety of teams across our hybrid core architecture from Design to QA, as well as security engineering for design guidance and secure coding practices • Work with your teammates to communicate technical requirements to stakeholders and solve technical problems in a scalable and realistic way • Mentor junior and new team members by helping them understand team expectations, providing technical guidance, sharing knowledge, and engaging in pair programming sessions • Review code for others to maintain high code quality, knowledge share within the team, and support creating a safe environment of giving and receiving feedback • Stay informed about the latest industry trends, technologies, and best practices in security development



