Job Closed

This listing is no longer active.

Chainguard logo
Chainguard

Making the software supply chain secure by default.

Staff Security Engineer

Security EngineerSecurity EngineerOtherRemoteLeadTeam 51-200Since 2021H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

155 days ago

Salary

$170K - $190K / year

Seniority

Lead

8 yrs expEnglishLinuxmacOSPython

Job Description

Staff Security Engineer

Chainguard

• Engineer and deploy clever controls so security incidents stay rare and boring • Lead incident response efforts, security tool deployments including tabletop exercises • Apply digital forensics and incident response knowledge, skills, and experience toward in-depth security investigations on both hardware endpoint and multi-cloud environments • Engineer security best practices with product teams who appreciate memes as much as mitigations • Experience with Go, Python, or Shell, mostly so you can spend less time yelling at logs and more time celebrating wins • Embrace artificial intelligence and automation in order to protect the enterprise at machine speed • Stay one step ahead of emerging security threats by continuously consuming threat intelligence and related industry happenings • This position includes rotational on-call responsibilities; Not brutal- the workload is reasonable and shared across the team.

Job Requirements

  • 8+ years’ experience in software development, security, or a related field
  • Experience and passion identifying, developing, and integrating threat intelligence into meaningful detection engineering and preventative controls
  • Engineer and or forensic experience securing cloud-native environments
  • Scripting experience
  • Familiarity with macOS or Linux security controls
  • Practiced investigative mindset skills and experience
  • Fluidity with both independent and group work
  • Leading projects and people to successful outcomes with minimal supervision
  • Experience with security frameworks: SOC 2, ISO 27001, NIST
  • Experience with open source software or offensive security is a plus highly desired
  • Boundless technical curiosity
  • Model interpersonal and communication excellence (no assholes)

Benefits

  • Flexible & Remote-First Culture: Work remotely with team meetup opportunities, bi-annual destination summits, and a monthly stipend for coworking spaces, phone and internet costs.
  • Our Approach to Equity: Receive stock options upon hire and promotion. Plus, you can participate in secondary offerings and have 10 years to exercise your options (yes, you read that correctly: 10 years!).
  • 100% Covered Health Insurance: We cover 100% of your health, vision and dental insurance premiums for you and your dependents. Nothing comes out of your paycheck.
  • ∞ Flexible Time Off: Take the time you need – to do our best work, we need to recharge and reset.
  • 18 Weeks Paid Parental Leave: We offer 18 weeks for birthing parents and 12 weeks for non-birthing parents, with the option to use it all at once or throughout your child's first year.

Related Categories

Related Job Pages

More Security Engineer Jobs

Account Executive, Cybersecurity

Funded.club

Funded.club is a global recruitment firm specializing in building high-performing teams for startups and scale-ups, offering a streamlined process that delivers

Security Engineer155 days ago

• A solution salesperson. You understand customer challenges, define requirements, and solve business challenges using our enterprise software solution to achieve positive business outcomes for our prospects. • Great at teaming and collaborating within all departments of a fast-moving startup environment. • Persuasive in your C-level communication. (CISO, Product Security, DevSecOps, VP App Sec leaders are primary targets.) • Persistent in your ability to find, navigate and close complex sales cycles. • Proficient with tools like ZoomInfo, LinkedIn Navigator, Salesforce, SalesLoft, Clari, etc.

Massachusetts
Job Closed

Senior Technical Account Manager, Cybersecurity

Funded.club

Funded.club is a global recruitment firm specializing in building high-performing teams for startups and scale-ups, offering a streamlined process that delivers

Security Engineer155 days ago

• Collaborate with Account Executives to design and present tailored solutions, addressing each customer’s technical and business needs. • Deliver high-impact demos, workshops, and proofs-of-concept (POCs) that demonstrate how Legit integrates with customer environments (CI/CD, SCM, cloud, etc.). • Translate complex requirements into architectural blueprints, aligning Legit capabilities with customer workflows and security objectives. • Serve as the technical voice in sales cycles, building confidence across security, DevOps, Dev Orgs, and executive stakeholders. • Lead onboarding and technical enablement for new customers, ensuring rapid time to value. • Act as a trusted advisor and escalation point, guiding best practices in secure software supply chain management. • Partner with the customer to drive adoption, expansion, and retention, identifying opportunities for upsell and deeper integration. • Conduct Quarterly Business Reviews (QBRs) with technical and executive audiences, highlighting ROI, risk reduction, and next-phase initiatives. • Advocate for customer needs with Product and Engineering, shaping roadmap priorities based on real-world insights. • Contribute to solution playbooks, architecture diagrams, and best-practice guides used across the customer lifecycle.

United States
Job Closed
GitLab logo

Principal Product Manager, Application Security Testing

GitLab

Build software faster. The One DevOps Platform enables your entire org to collaborate around your code. We're hiring.

Security Engineer155 days ago
OtherRemoteTeam 1,001-5,000Since 2014H1B No Sponsor

• Lead product strategy across the Security and Compliance portfolio, with a focus on application security testing as a whole, to drive cohesive roadmaps and measurable growth in adoption and customer value. • Own end-to-end definition and delivery for high-impact initiatives such as packaging internal security capabilities for customers, strengthening vulnerability research, and incubating emerging products from ideation to product-market fit. Ensure clear success criteria, on-time delivery, and demonstrable impact on customer security outcomes and product adoption. • Partner closely with Product Managers in scanners to mentor, coach, and review their product work, including product requirement documents, roadmap decisions, and go-to-market thinking, to elevate the quality and consistency of product execution and improve the success of launches. • Collaborate with cross-functional partners in engineering, design, partnerships, and go-to-market teams to shape positioning, launch plans, and strategic collaborations that expand the Security and Compliance business through increased adoption and engagement. • Drive a clear strategy for vulnerability research and security partnerships, working with internal and external stakeholders to identify opportunities and translate them into product outcomes that measurably improve product quality, coverage, and differentiation. • Use AI-first tools and workflows to quickly explore ideas, create prototypes, and communicate concepts. Increase the speed and quality of product discovery and decision-making by tracking improvements in cycle time and validation effectiveness. • Build strong relationships across GitLab to influence without direct authority, connect work across teams, and help resolve complex escalations in a constructive, transparent way that reduces blockers and improves resolution time and stakeholder satisfaction.

United States
$145.6K - $312K / year
Job Closed
Brookfield Renewable U.S. logo

Engineer/Senior Engineer, Firewall

Brookfield Renewable U.S.

TerraForm Power (“TERP”), a platform company of Brookfield Renewable, attracts high-performing individuals who are driven to make an impact in a fast-paced and collaborative environment. We offer unparalleled opportunity to lead and manage one of the largest renewable energy businesses with decades of history, while contributing to the global need for sustainable energy. We offer tremendous growth opportunity for individuals with an entrepreneurial mindset. The company is committed to employee development, encouraging curiosity, ownership, and continuous learning. You’ll be empowered to take initiative, contribute ideas, and grow your career within a supportive and ambitious organization.

Security Engineer155 days ago
OtherRemoteTeam 501-1,000

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This is an Operational Technology (OT) role embedded in the TerraForm Power Remote Operations Centre, responsible for designing, implementing, and maintaining secure network perimeters for wind, solar, and battery storage operations with a focus on NERC CIP compliant architecture. The Firewall Engineer will work in close partnership with the TERP Cybersecurity Manager, Compliance and Operations Centre staff to ensure robust, compliant, and resilient OT network security across all sites and control centers. Responsibilities - Architecture, Design & Implementation - Design and implement OT network security controls, such as perimeter firewalls, internal segmentation, site‑to‑site and remote‑access VPNs, and WAFs. - Build secure network solutions that align with system architecture for wind, solar, and BESS facilities, EMS/SCADA, and the system control centers. - Define network security zones and conduits for OT, corporate IT, and cloud environments; enforce least privilege and micro‑segmentation. - Engineer solutions using Cisco (ASA/Firepower/FTD) and Check Point (CCSA/CCSE) platforms; integrate with management consoles and policy orchestration tools. - Implement secure remote access for operators, vendors, and field technicians using MFA, bastion/Jump hosts, and role‑based access. - Operations, Monitoring & Incident Response - Administer firewall policies, objects, NAT, routing (OSPF/BGP), and HA/cluster configurations; manage rule lifecycle and clean‑up. - Maintain WAF protections (e.g., F5, Fortinet, Check Point, or cloud WAF) including rule tuning, bot mitigation, and API security. - Operate and improve monitoring and control tools (SIEM/SOAR, NetFlow, packet capture, IDS/IPS); build dashboards and alerts for NERC systems. - Conduct log analysis, threat hunting, and participate in incident triage and response; provide on‑call support for critical events. - Perform regular firewall health checks, performance tuning, firmware/OS upgrades, and vulnerability remediation. - Support occasional after‑hours maintenance windows on an as needed basis. - Compliance & Change Management (NERC Focus) - Implement and maintain controls aligned to NERC CIP standards applicable to Low Impact sites and Medium Impact control centers (e.g., CIP‑003, CIP‑005, CIP‑007, CIP‑008, CIP‑009, CIP‑010, CIP‑011, CIP‑013). - Serve as the technical owner for firewall‑related CIP controls (for example CIP‑005, CIP‑007, CIP‑010), including configuration baselines, access controls, logging, and evidence collection. - Establish and enforce configuration baselines, access controls, evidence collection, and audit‑ready documentation. - Run structured change management programs for firewall and WAF policies, including risk assessment, testing, approvals, and post‑implementation review. - Support audits, self‑assessments, and impact ratings; assist with personnel risk assessment and vendor risk management where applicable. - Collaborate with OT, IT, Compliance, Engineering, and Plant Operations to ensure controls meet operational needs without compromising reliability. - Collaborative Responsibilities - Work in close partnership with the TERP Cybersecurity Manager to align firewall, VPN, and WAF controls with OT/IT cybersecurity strategy, incident response protocols, and compliance requirements. - Participate in joint incident response, risk assessments, and continuous improvement initiatives with the Cybersecurity Manager and Operations Centre leadership. - Coordinate with Operations Centre, plant operators, and engineering teams to ensure security controls support operational reliability and compliance. - Technology Evaluation & Continuous Improvement - Evaluate new firewall, WAF, VPN, and OT security technologies; lead POCs and make data‑driven recommendations. - Identify opportunities to enhance resilience (segmentation, Zero Trust, SD‑WAN security, secure cloud connectivity), and automate repeatable tasks (e.g., policy linting, backup/restore, compliance evidence collection). - OT-Specific Duties - Manage vendor and contractor access for maintenance and commissioning, ensuring robust controls for temporary access and logging. - Design solutions that address site-specific challenges, including limited bandwidth, remote access constraints, and environmental factors. - Support operational resilience by coordinating change windows with grid operations and implementing failsafe configurations to avoid plant outages. Qualifications - Engineer - 5+ years of hands‑on experience administering enterprise firewalls and VPNs (Cisco ASA/Firepower/FTD; Check Point). - Working knowledge of WAF technologies and web security (OWASP Top 10, TLS, mTLS, API security). - Strong command of TCP/IP, routing (OSPF/BGP), NAT, ACLs, IPS/IDS, and packet analysis. - Experience with SIEM/log management (e.g., Splunk, QRadar, LogRhythm), network monitoring (e.g., SolarWinds), and configuration management. - Familiarity with NERC CIP concepts and control implementations for Low and/or Medium Impact environments, or equivalent experience in other regulated OT/ICS environments (for example IEC 62443). - Solid documentation skills and experience operating within formal change management processes. - Clear communicator able to translate complex security topics for plant operations, engineering, compliance, and leadership. - Strong prioritization and execution in high‑availability environments; calm under pressure during incidents. - Collaborative and customer‑focused; builds trusted relationships with site personnel and external partners. - Senior Engineer - All above, plus; - 10+ years in network security with deep expertise in Cisco and Check Point ecosystems, including clustering/HA, threat defense, and advanced policy design. - Proven leadership of firewall/WAF architecture in OT/ICS or critical infrastructure (utilities, energy, industrial). - Demonstrated experience interpreting and implementing NERC CIP requirements in Medium Impact control centers, including evidence management and audit support. - Proficiency guiding incident response and problem management for high-availability environments; ability to mentor engineers and lead complex changes. - Track record of evaluating, selecting, and integrating new technologies; experience with automation (e.g., Ansible, Python) and policy compliance tooling. Education & Certifications - Bachelor’s degree in Computer Science, Electrical/Computer Engineering, Information Security, or related field; or equivalent experience. - Relevant certifications preferred: - Cisco: CCNP Security, CCIE (Security) (plus) - Check Point: CCSA/CCSE - Others, a plus Industry‑Specific (Renewable Energy & OT/ICS) Requirements - Experience with the secure transport of SCADA/EMS, plant DCS/RTUs/PLCs, and OT protocols (OPC, DNP3, Modbus). - Understanding of interconnections between substations, collector systems, BESS EMS, and corporate networks; secure data flows to forecasting, trading, and asset performance platforms. - Knowledge of telecom links common in renewables (leased lines, microwave, LTE/private cellular) and secure backhaul to control centers. - Awareness of site conditions (limited bandwidth, remote access constraints, environmental factors) and designing resilient, maintainable solutions. - Vendor and contractor access management for maintenance, OEM support, and commissioning activities, with strong control over temporary access and logging. - Safety and reliability mindset: change windows coordinated with grid operations, rollback plans, and fail‑safe configurations to avoid plant outages. Compensation $120,000-$140,000 USD, bonus eligible

United States
$120K - $140K / year
Job Closed