Job Closed
This listing is no longer active.
The smartest person in the room
Security Engineer – Infrastructure Security
Location
United States
Posted
129 days ago
Salary
$175K - $250K / year
Seniority
Senior
Job Description
Security Engineer – Infrastructure Security
1mind
• Design and build layered security controls across OS, Kubernetes, networks, identity, and CI/CD to protect high-value assets. • Drive deployment of security enhancements and policy changes across multi-region infrastructure. • Lead high-impact initiatives: checkpoint/model artifact protection and encryption, network isolation and segmentation, secrets and machine identity, policy-as-code, and secure storage/access pathways. • Automate detection, prevention, and response with guardrails and paved paths (IaC modules, validated baselines, admission controls). • Embed security into developer workflows (shift-left reviews, SAST/DAST/SCA, SBOM, provenance), and instrument robust observability for security signals. • Partner on risk assessments, threat modeling, and incident response; deliver postmortems and durable mitigations. • Champion a healthy security culture that enables rapid iteration while meeting reliability, safety, and compliance expectations.
Job Requirements
- Deep understanding of security principles, common vulnerabilities, and practical defenses across infra and application layers.
- 5+ years building and operating core infrastructure security or platform security at scale.
- Expertise securing cloud platforms (e.g., AWS/Azure/GCP), including cloud networking, identity, and cloud-agnostic abstractions.
- Experience with datacenter security from construction/bring-up to multi-tenant operations.
- Familiarity with container/Kubernetes security (workload identity, admission controls, policy engines, image supply chain).
- Proven track record delivering scalable, automated security solutions and moving organizations via tooling and paved paths.
- Strong analytical/problem-solving skills; crisp communication with technical and non-technical stakeholders.
- Plus: Service mesh and mTLS, HSM/KMS and envelope encryption, OPA/rego, attestation & provenance, TPM/PKI, confidential computing, GPU/accelerator security, compliance frameworks.
Benefits
- health insurance
- retirement plans
- paid time off
- flexible work arrangements
- professional development
- bonuses
- stock options
- equipment allowances
- wellness programs
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Conduct security assessments and build a prioritized remediation roadmap across infrastructure and services • Harden AWS and Kubernetes environments: IAM, network policies, workload isolation, secrets management • Secure AI-specific attack surfaces: prompt injection defenses, PII handling in LLM pipelines, model interaction data leakage • Embed automated security into CI/CD: dependency scanning, container image scanning, code analysis, secrets detection • Design secure-by-default patterns for service communication, authentication, and data handling • Build incident response capabilities: detection, alerting, response workflows, and post-incident review • Partner with engineering teams to improve security posture without becoming a bottleneck
Avint is hiring a Senior ISSO (Cybersecurity Compliance Lead / RMF SME) to support and protect critical federal systems within the HACS program at FRTIB HQ. In this role, you’ll be part of a high-performing team leading Risk Management Framework (RMF) and Authority to Operate (ATO) efforts across mission-critical systems. You’ll work at the intersection of cybersecurity, compliance, and mission operations, ensuring systems are secure, authorized, and aligned with federal requirements
Staff Security Engineer
PaxosPaxos is a regulated blockchain infrastructure company building transparent and transformative financial solutions.
• Lead the design and implementation of secure infrastructure application architecture and standards. • Embed security into the development lifecycle by building tooling and CI/CD guardrails. • Conduct deep-dive threat modeling sessions for new products and identify issues. • Serve as an Incident Commander during high-severity security events. • Oversee the lifecycle of cryptographic material and key management services. • Mentor Senior and Mid-level security engineers and champion a "security-first" culture.
Role Description The Security Specialist will drive enhancements in threat detection, incident response, vulnerability management, and cloud security. This role requires strong expertise in Microsoft Azure security technologies, SIEM operations, threat intelligence, and security automation, ensuring Beem’s defenses are proactive, scalable, and resilient against modern cyber threats. As a key member of the security team, you will work hands-on with Microsoft Sentinel, Sentinel Data Lake, Defender XDR, KQL-based threat hunting, SOAR automation, and UEBA to optimize Beem’s Security Operations Center (SOC) capabilities. You will also play a pivotal role in improving cloud security posture management (CSPM), identity security, and endpoint protection. The Security Specialist will be responsible for strengthening and maturing Beem’s Security Operations capabilities while overseeing the operational governance of a Managed Security Services Provider (MSSP) delivering SOC services. This role is open to remote or hybrid working arrangements within British Columbia. What you’ll do: - Security Operations & Incident Response - Lead threat detection engineering by writing advanced KQL-based detection rules in Microsoft Sentinel. - Manage and fine-tune SIEM correlation rules, threat intelligence integrations, and alerting mechanisms. - Deploy and optimize Microsoft Defender for Endpoint, Defender for Cloud, and Defender for Identity. - Lead the deployment, configuration, and continuous optimization of Wiz (Cloud Security platform). - Develop custom detection logic for MITRE ATT&CK TTPs. - Integrate external threat intelligence feeds into Sentinel. - Conduct periodic validation of log coverage. - Own the development, standardization, and maintenance of comprehensive documentation across the enterprise security toolset. - Develop and maintain Standard Operating Procedures (SOPs) for various workflows. - Own and operationalize enterprise Privileged Access Management and Identity & Access Management controls. - Incident Response & Security Automation - Serve as an escalation point for security incidents, performing forensic analysis. - Develop and execute incident response runbooks for various threats. - Automate security response workflows using SOAR capabilities. - Conduct log analysis and correlation from diverse data sources. - Perform digital forensics and malware analysis. - Lead threat hunting exercises. - Vulnerability Management & Cloud Security - Enhance vulnerability scanning and remediation workflows. - Design and implement custom security baselines for various systems. - Harden Azure environments by applying CIS Benchmarking and Microsoft Secure Score improvements. - Secure Kubernetes Services and containerized workloads. - Work with IAM teams to optimize Conditional Access Policies. - Security Metrics & Threat Intelligence - Develop and track KPIs and KRIs to measure security posture. - Design, implement, and operationalize comprehensive health monitoring across the enterprise security toolset. - Implement threat intelligence initiatives. - Continuously assess and enhance security processes. - Compliance & Governance - Assist in responding to internal and external audits. - Maintain a deep understanding of security frameworks and standards. - Provide security advisory and governance support for IT and engineering teams. Qualifications - Bachelor’s degree in Computer Science, Information Security, or a related field. - 6-8 years of hands-on experience in security operations. - Extensive experience with Microsoft security technologies. - Proficiency in KQL scripting for threat hunting and security analytics. - Strong understanding of cloud security principles. - Industry certifications preferred: CISSP, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Cybersecurity Architect Expert. - Experience leading security operations projects. - Strong problem-solving skills in high-pressure incident response scenarios. - Ability to collaborate cross-functionally and communicate effectively. - Agile mindset with a continuous improvement approach. Benefits - Annual salary range: $95,500 - 119,400. - Performance bonuses tied to shared goals. - Extended health coverage, including mental health support. - Dental care. - Disability coverage. - Vacation and personal days. - Generous RRSP contributions. - In-house financial advice. - Free banking accounts and special mortgage rates.




