Job Closed
This listing is no longer active.
Innovating business travel with a free-to-use hotel booking platform.
Senior Security Engineer
Location
United States
Posted
136 days ago
Salary
$115.6K - $160K / year
Seniority
Senior
Job Description
Senior Security Engineer
Hotel Engine
• Threat Detection & SIEM Ownership: Own the configuration, tuning, and management of our SIEM solution. You will diagnose unusual threats through sophisticated analysis and develop the alerts needed to respond to security incidents across multiple layers. • Security Analysis & Reviews: Perform architecture reviews, code reviews, and infrastructure configuration reviews. You will conduct light penetration testing on web and mobile apps, identifying root causes of vulnerabilities and resolving them using creative problem-solving. • Vulnerability Management: Maintain and optimize a vulnerability management CI/CD pipeline within our container/application delivery infrastructure. You will adapt proven methods to align security goals with business objectives, even when guidance is light. • Cross-Functional Collaboration: Partner with development and infrastructure teams to enforce secure coding practices and remediation strategies. You will adapt your messaging across teams to reduce misalignment and move security work forward. • Implementation & Tooling: Build and maintain the frameworks and tooling for enterprise security, ensuring that security guidelines are clear and actionable for the broader engineering organization. • Incident Response: Play a key role in incident response and forensic investigations. You will weigh context and data thoughtfully to make smart decisions during high-pressure situations. • Security Advocacy: Stay current on the latest threats and provide direct, clear guidance to development teams. You will help develop security training to empower your peers and improve the team’s overall security posture.
Job Requirements
- Technical Proficiency: Highly skilled in one or more programming languages (e.g., Ruby, Java, Python, C#, Node.js).
- SIEM & Monitoring: Expertise in managing SIEM solutions with a focus on comprehensive, efficient alerting that reduces 'noise.'
- Cloud & Containers: Strong knowledge of Docker and Kubernetes, with hands-on experience in automated container vulnerability management.
- Security Testing: Mastery of SAST, DAST, and IAST tools, with the ability to perform manual validation testing to confirm findings.
- Security Principles: Deep knowledge of the OWASP Top 10, Mitre Top 25, and secure coding practices.
- Analytical Problem Solving: Ability to assess complex, ambiguous situations to identify root causes and provide thoughtful input on difficult security topics.
- Communication: A track record of earning credibility with peers through clear, direct communication and a passion for mentoring others.
- Compliance & Frameworks: Experience working with cloud security concepts and compliance frameworks such as SOC 2 and PCI.
Benefits
- Compensation: Competitive base pay tied to role and experience, with opportunities for bonuses, commissions, and equity.
- Benefits: Check out our full list at engine.com/culture.
- Environments for Success: Different roles have different needs in terms of the environments that drive success which is why we have a hybrid-hub model. Whether you are in one of our amazing offices or fully remote, we’ll make sure you have what you need to succeed.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Consultant
VikingCloudVikingCloud, founded in 1989, is a global cybersecurity and compliance company headquartered in Chicago, Illinois, with additional offices in Dublin, serving more than 4 million bu
• Provide assessments and consulting to our clients. • Manage your own book of work and your own work schedule. • Conduct remote assessment activities and travel to client locations for on-site activities. • Provide status of all engagements assigned on a weekly basis. • Write detailed technical reports and evaluate supporting documentation for compliance with standards and regulations. • Perform consulting, advisory and assessment services. • Maintain relevant certification and continuing education. • Evaluate client compliance with various regulations and standards. • Conduct audits and risk assessments based on NIST standards. • Provide consultative support with clients on risk assessment and audit. • Share expertise with clients and colleagues for decision-making. • Produce detailed reports for clients and industry third parties. • Learn from and contribute to a close-knit group of consultants.
Senior Software Engineer – Fleet Security
SamsaraSamsara Inc. is on a mission to increase the sustainability of the operations that power the global economy. The company pioneers the Connected Operations Cloud
• Deliver Full-Stack Customer Solutions: Operate with deep autonomy across the product stack to deliver customer-facing solutions. • Lead Technical Design and Data Modeling: Lead technical design discussions to solve high-scale data challenges and influence the platform roadmap with a focus on seamless future product growth. • Pioneer End-to-End ML / AI Deployment: Build next-generation ML / AI-driven models and features directly integrated into our Connected Operations Platform, ensuring real-time performance and reliability. • Harness Data for Customer ROI: Leverage one of the world's largest operational datasets to deliver instant, actionable insights that generate Clear + Fast ROI for our customers. • Collaborate with other engineering teams to make design decisions and understand downstream implications in our product to ensure a seamless customer experience • Ship features that are immediately used by our customers and iterate based on their feedback • Deliver full stack features across front-end, back-end and mobile. GoLang, GraphQL, Typescript, React and ReactNative are some of the components of our technology stack. Direct experience with these technologies is not required. • Be responsible for maintaining the production systems that your team owns and provide operational support. • Champion, role model, and embed Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices.
Senior Security Engineer II
AledadeSelf-described as "a new company with an old-fashioned goal," Aledade aims to put healthcare control back into the hands of doctors. Headquartered in Bethesda, Maryland, the compan
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description As a Senior Security Engineer II for Identity and Access Management (IAM) at Aledade, you will play a central role in enhancing the security posture of our enterprise, cloud-native environments, and applications. We are seeking a dedicated professional with in-depth knowledge of IAM principles, standards, and best practices to help safeguard our systems and support our security compliance initiatives. In this role, you will work to design, implement, and maintain robust IAM solutions, managing authentication, authorization, and provisioning across diverse platforms. You will also collaborate closely with various teams to ensure alignment between IAM solutions and organizational security requirements, enabling secure and seamless access across the enterprise and cloud services. Your ability to partner cross-functionally will be key to driving impactful outcomes and further strengthening our digital landscape. Primary Duties - Working cross functionally to design, build, and operate solutions that continuously improve and automate our security capabilities. - Leveraging data to understand trends, metrics, and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders. - Leading and enhancing incident response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents. - Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures. - Mentoring and coaching more junior engineers or analysts. Qualifications - BS / BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 8 years security domain experience without degree. - 6+ years of experience in software or security engineering within Cloud Native environments. - 4+ years of experience working with large datasets to identify opportunities for security posture improvements or to detect, investigate and respond to threats. - 4+ years of experience acting as a trusted advisor in a team setting, solving for short-term and long-term business value. - 4+ years of experience coaching other engineers or analysts. Requirements - Identity & Access Management experience. - In-depth knowledge of authentication protocols, authorization mechanisms, and directory services. - Strong proficiency implementing IAM solutions within very complex environments. - Familiarity with regulatory compliance and security standards. - Experience generating automated metrics to measure service and program effectiveness and consistency. - Strong communication skills, both written and verbal, with the capability to articulate complex security issues to a diverse audience. - Automation skills: Powershell, Python, Terraform. - Expertise on Okta products - Directory, SSO, MFA, Workflows, ISPM and IGA. - Experience with tools in the security stack strongly preferred: Auth0/Entra ID/Ping Identity, Cloud Platforms - AWS/Azure/GCP. Benefits - Flexible work schedules and the ability to work remotely are available for many roles. - Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners. - Robust time-off plan (21 days of PTO in your first year). - Two paid volunteer days and 11 paid holidays. - 12 weeks paid parental leave for all new parents. - Six weeks paid sabbatical after six years of service. - Educational Assistant Program and Clinical Employee Reimbursement Program. - 401(k) with up to 4% match. - Stock options. - And much more!
• Leading the design and implementation of a policy- and standards-driven cybersecurity governance program supported by GRC tooling • Establishing and maturing a data governance and protection program across the full data lifecycle • Defining and enforcing data classification, labeling, and handling requirements • Establishing and maintaining enterprise security governance structures, roles, and accountability • Serving as a trusted advisor to business and technology stakeholders on governance, risk, and compliance matters • Driving identification, escalation, and resolution of cybersecurity GRC risks and issues • Supporting and maintaining cybersecurity compliance certifications and initiatives



