Liftoff logo
Liftoff

Liftoff is a leading AI-powered performance marketing platform for the mobile app economy. Our end-to-end technology stack helps app marketers acquire and retain high-value users, while enabling publishers to maximize revenue across programmatic and direct demand. Liftoff’s solutions, including Accelerate, Direct, Monetize, Intelligence, and Vungle Exchange, support over 6,600 mobile businesses across 74 countries in sectors such as gaming, social, finance, ecommerce, and entertainment. Founded in 2012 and headquartered in Redwood City, CA, Liftoff has a diverse, global presence. Come join the rocket ship! 🚀

Senior Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 645Since 2012Company Site

Location

United States

Posted

80 days ago

Salary

$189K - $240K / year

Seniority

Senior

Job Description

Senior Security Engineer

Liftoff

Liftoff is a leading AI-powered performance marketing platform for the mobile app economy. Our end-to-end technology stack helps app marketers acquire and retain high-value users, while enabling publishers to maximize revenue across programmatic and direct demand. Liftoff’s solutions, including Accelerate, Direct, Monetize, Intelligence, and Vungle Exchange, support over 6,600 mobile businesses across 74 countries in sectors such as gaming, social, finance, ecommerce, and entertainment. Founded in 2012 and headquartered in Redwood City, CA, Liftoff has a diverse, global presence. About Liftoff Security Team The Liftoff security team is dedicated to protecting Liftoff’s customers, users, and employees. Our team architects Liftoff’s security posture, designs and builds infrastructure and security improvements, consults with other teams as they develop and launch new products and features, and proactively plans for the unknown. Our work spans the entire company and technology stack, from infrastructure to web and mobile applications, as well as IT systems. We collaborate with key stakeholders to balance business needs while minimizing security risks. Our approach to security is deeply rooted in software engineering principles, emphasizing automation and the development of well-designed security tools. Responsibilities - Establish secure software development standards and integrate security-minded thinking into the development process. - Create frictionless paths for engineering teams to securely build and deploy software. - Perform security assessments of systems and services to ensure compliance with security best practices. - Partner with key stakeholders across the organization to build a culture of security-minded builders. - Assess vendors to ensure their internal security controls meet Liftoff’s security requirements and their products enable secure employee usage. - Triage incoming threat events and vulnerabilities and ensure timely remediation and resolution of the issues. - Conduct post-incident reviews, document findings, and implement necessary remediations. - Develop tooling and automation to detect and mitigate active security threats within our systems. Requirements - 5+ years of experience in security engineering or software engineering. - Experience collaborating with cross-functional teams to deliver impactful security initiatives. - Comfortable reading, writing, and maintaining code in multiple languages. - Strong understanding of application security best practices. - Ability to quickly understand complex engineering architectures and systems. - Demonstrated ability to prioritize security efforts using a risk-based approach. - Proficiency in Go, Python, Clojure, or JavaScript. - Experience working on or collaborating with high-velocity, high-performing software engineering teams. - Proven track record of scaling cloud infrastructure security. - Excellent written and verbal communication skills. Working at Liftoff is fast-paced, fun, and challenging, and we thrive on innovation. Come join our team and help shape the future of the mobile app ecosystem. If this role sounds interesting to you, we would love to hear from you! Locations: This role is eligible for full-time remote work in one of our entities/states and Canada: CA, CO, ID, IL, FL, GA, MA, MI, MN, MO, NJ, NV, NY, OR, PA, TX, UT, and WA. We are a remote-first company with US hubs in Redwood City, Los Angeles, and New York City. Travel Expectations: We offer several opportunities for in-person team gatherings, including but not limited to project meetings, regional meetups, and company-wide events. We expect our employees to attend these gatherings at least once per quarter. These gatherings provide essential opportunities for collaboration, communication, and team building. Compensation: Liftoff offers all employees a full compensation package that includes equity and health/vision/dental benefits associated with your country of residence. Base compensation will vary based on the candidate's location and experience. The following are our base salary ranges for this role: - SF Bay Area, Los Angeles/Orange County, NYC, Seattle: $220,000 - $240,000 - All other California and Washington state locations, Austin, Boston, Denver, Portland: $202,400 - $220,800 - All other cities and towns in our approved states: $189,200 - $206,400 #LI-EL1 We use Covey as part of our hiring and/or promotional process for jobs in NYC and certain features may qualify it as an AEDT. As part of the evaluation process, we provide Covey with job requirements and candidate-submitted applications. We began using Covey Scout for Inbound on January 22, 2024. Please see the independent bias audit report covering our use of Covey here. Liftoff offers a fast-paced, collaborative, and innovative work environment where employees are empowered to grow and make an impact. We’re shaping the future of the mobile app ecosystem—join us and help accelerate what’s next. Liftoff’s compensation strategy includes competitive salaries, equity, and benefits designed to support employee well-being and performance. We benchmark compensation based on role, level, and location to ensure fairness and market alignment. Benefits may include medical coverage, wellness stipends, and additional perks based on your country of residence. Liftoff is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and applicants regardless of race, ethnicity, national origin, age, marital status, disability, sexual orientation, gender identity, religion, veteran status, or any other characteristic protected by applicable law. Agency and Third Party Recruiter Notice: Liftoff does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job postings. No fee will be paid to third parties who submit unsolicited candidates directly to our hiring managers or Recruiting Team. All candidates must be submitted via our Applicant Tracking System by approved Liftoff vendors who have been expressly requested to make a submission by our Recruiting Team for a specific job opening. No placement fees will be paid to any firm unless such a request has been made by the Liftoff Recruiting Team and such a candidate was submitted to the Liftoff Recruiting Team via our Applicant Tracking System.

Related Categories

Related Job Pages

More Security Engineer Jobs

KinPOS Corporation logo

Information Security Specialist – PCI DSS

KinPOS Corporation

We provide strategic improvement potential and drive revenue and earnings growth through certified secure channels.

ContractRemoteTeam 11-50Since 2008H1B No Sponsor

• Protect critical information under international standards such as PCI DSS • Contribute to strengthening the organization's security

United States
Job Closed
Sonar logo

Security Engineer

Sonar

Trusted by 6M devs, Sonar helps you build quality code quickly & systematically with our Clean as You Code methodology.

Full TimeHybridTeam 201-500H1B No Sponsor

Title: Security Engineer Location: Bochum Type: Employee / Full-Time Workplace: onsite Category: IT Ops Job Description: Who is Sonar? Who is Sonar?   Sonar helps prevent code quality and code security issues from reaching production, amplifies developers' productivity in concert with AI assistants, and improves the developer experience with streamlined workflows. Sonar analyzes all code, regardless of who writes it — your internal team, genAI, or third parties — resulting in more secure, reliable, and maintainable applications. Rooted in the open source community, Sonar’s solutions support over 30 programming languages, frameworks, and infrastructure technologies. Today, Sonar is used by +7M developers and 400K organizations worldwide, including the DoD, Microsoft, NASA, MasterCard, Siemens, and T-Mobile.   We believe in developing great products that are supported by great internal teams and a strong culture.  We are highly committed to and obsessed with the company, users, each other, and our open source community. We have high standards and hold each other accountable for acting with positivity, dedication, thoughtfulness, empathy, and passion daily.    We are deliberate with our decisions with high clarity of intention. At the same time, we feel extreme urgency and move forward quickly.    And lastly, we are highly effective and operationally efficient. We operate collectively as One Team to accomplish our goals.   At Sonar, CODE is more than just an acronym – it's a mindset that defines daily operations.    Why You Should Apply:    At Sonar, we’re a group of brilliant, motivated, and driven professionals working hard to help supercharge developers to build better, faster. Sonar helps to continuously improve code quality and code security while reducing developer toil. This means that developers can focus on doing more of what they love and less of what they don’t. Our solutions don’t just solve symptoms of problems – we help fix issues at the source – for all code, whether it's developer-written, AI-generated, or from third parties.   We have a dynamic culture with employees worldwide and hub offices in the USA, Switzerland, the UK, Singapore, and Germany. Team members should be able to come to work every day, work on a product they are proud of, love what they do, and feel energized by their peers. With our roots deep in the open source community, we’re all about the mission: supercharge developers to build better, faster.   The Impact You Will Have: We are still at the beginning of our growth journey and are continuously introducing new processes, technologies, and tools. In this role, you will: - Be a pivotal engineering contributor to the design, implementation, and operation of security controls and automation across our identity platforms, endpoints, and core IT services. - Own key parts of our IdP and access automation stack (e.g., SSO, SCIM, group‑based access, JIT access), ensuring that users get the right access at the right time with strong controls and auditability. - Design and maintain security monitoring, alerting, and SIEM integrations that give us real‑time visibility into identity, endpoint, and SaaS risks. - Partner with IT Ops, Information Security, and Infrastructure Engineering to ensure security controls are deeply integrated into operations (incident management, change, and problem processes), not bolted on. - Use and champion AI tooling to make security operations more efficient — from alert triage and runbook execution to knowledge retrieval and reporting. - Help define and improve how we measure the reliability and effectiveness of our security controls (SLIs/SLOs, error budgets, and dashboards), making risk and performance visible and actionable to stakeholders.   What You Will Do Daily: - Security Monitoring, Alerting & SIEM Ownership: Working with the Information Security team, design, implement, and maintain alerting rules, dashboards, and runbooks across our SIEM and logging platforms, with a focus on identity, access, and SaaS security signals. Continuously tune alerts to reduce noise, improve fidelity, and align with error budgets and SLOs for critical security and identity services. - Endpoint Defense In Depth: Architect and implement our multilayer endpoint defence systems (e.g. Crowdstrike, Cyberark, Cloudflare, secure browser policies), balancing risk against usability in coordination with the Information Security team. - Identity Platform & Access Automation: Build and maintain automation for our identity platforms (e.g., SSO, SCIM provisioning, group‑based access policies, lifecycle workflows) in partnership with Information Security. Implement guardrails and policy‑as‑code for identity, ensuring changes are reviewed, tested, and auditable before reaching production. - Infrastructure as Code & Security Controls as Code: Use IaC and configuration management (e.g., Terraform, Ansible, or similar) plus scripting languages (e.g., Python, Go) to deploy and manage security tooling, integrations, and policies. Treat security controls (e.g., logging, scanning, hardening, secret management) as software artifacts that can be versioned, tested, and rolled back safely. - Observability & Integration with Core IT Operations: Ensure that logging, metrics, and tracing for security‑relevant systems (IdP, VPN, endpoint protection, critical SaaS) are robust, accurate, and integrated into our observability stack. Integrate security events and automations with ITSM and incident management workflows, enabling fast routing, triage, and resolution. - Incident Response & Post‑Incident Engineering: Participate in the on‑call rotation for relevant security and identity services. Lead or contribute to post‑incident reviews, turning root causes into preventative engineering changes (new alerts, automations, guardrails, or documentation) that reduce MTTR and recurrence. - AI‑Enabled Security Operations: Use AI tooling (e.g., LLM‑based assistants, automation platforms) to accelerate alert triage, enrichment, and investigation, while keeping humans in control of decisions. Identify opportunities to embed AI in security and IT operations workflows (e.g., threat intelligence and alert correlation) and help implement these safely and effectively. The Experience You Will Need: - Security Engineering & Operations Background: Significant hands‑on experience (4–7 years) in security engineering, security operations, or closely related roles in modern, fast‑paced environments (e.g., SaaS, enterprise IT, cloud‑native infrastructure). - Identity & Access Management Expertise: Practical experience operating IdPs and IAM systems at scale (e.g., Okta, Azure AD, or similar), including SSO, MFA, lifecycle management, and least‑privilege policies. Experience designing and implementing automated provisioning and deprovisioning (e.g., SCIM, HRIS integrations, group‑based and role‑based access models). - SIEM, Logging & Observability: Proven experience with SIEM and observability platforms (e.g., ELK/EFK, Splunk, Datadog, or similar), including writing and tuning detection rules, building dashboards, and working with large‑scale log ingestion. Comfort working with SLIs/SLOs and error budgets for critical services, and using these to guide priorities for hardening and automation. - Automation & Infrastructure as Code: Strong experience with IaC and configuration management tools (e.g., Terraform, CloudFormation, Ansible, or similar) and with scripting/programming languages (e.g., Python, Go, or equivalent) to automate security and operational tasks. Track record of converting manual, repetitive operational work into reliable automation and self‑service capabilities. - Security Controls Implementation: Experience implementing and operating security controls as code: vulnerability scanning, configuration baselines, secret management (e.g., HashiCorp Vault), key rotation, and certificate management. - Incident Management & Cross‑Functional Collaboration: Demonstrated experience participating in or leading incident response, root cause analysis, and post‑incident follow‑through in partnership with IT Ops, Security, and Engineering. Strong communication skills in English, able to explain complex security and operational topics to both technical and non‑technical audiences. - AI Fluency: Comfortable using modern AI tooling (e.g., LLM‑based assistants, automation frameworks) as part of daily work for analysis, content generation, and workflow automation. Ability to reason about where AI is and isn’t appropriate in security and operations, balancing speed with risk and control. Why You Will Love It Here: - Our culture and mission set us apart. We have a dynamic work culture that values respect and kindness and embraces the right to fail (and get right back up again!).  - Great people make a great company. We value people skills as much as technical skills and strive to keep things friendly while still being passionate leaders in our domains.  - We have a flexible work policy that includes 3 days in-office and 2 days work-from-home each week for those located near our office locations; some locations such as Dubai, India, Japan and Australia operate fully remotely. - We have a growth mindset. We love learning and believe continuous education is critical to our success. In an ever-changing industry, new skills are necessary, and we're happy to help our team acquire them. - As the leader in our field, our products and services are as strong as our internal team members. - We embrace transparency with regular meetings, cascading messages and updates on the growth and success of our organization. Benefits of Working with Sonar: - Pension Scheme: 1st Pillar (Unterstützungskasse): Automatic, financed by Sonar, 3% of gross salary, an additional benefit in addition to your salary. - Pension Scheme:2nd Pillar (bAV): Voluntary, 15% contribution by Sonar from social security savings. - We encourage usage of our robust time-off allocations with 28 PTO days for our employees based out of the Geneva region, plus additional days based on seniority and circumstances. - Sonar recognizes holidays on working calendar days. If the holiday date occurs on a Saturday, we will recognize the day on the preceding Friday. If the holiday date occurs on a Sunday, we will recognize the day on the following Monday. - Public transport reimbursement of 60% for annual subscription. - Generous discretionary Company Growth Bonus, paid annually.   - Global workforce with employees in 20+ countries representing 35+ unique nationalities. - We have an annual kick-off somewhere in the world where we meet to build relationships and goals for the company. We Value Diversity, Equity, and Inclusion:   At Sonar, we believe that our diversity is our strength. We are a global company that values and respects different backgrounds, perspectives, and cultures.   We are committed to fostering a diverse and inclusive work environment where everyone feels valued and empowered to contribute their best. We are proud to be an equal opportunity employer and welcome all qualified applicants, regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.   All offers of employment at Sonar are contingent upon the precise results of a comprehensive background check and reference verification conducted before the start date.   We do not currently support visa candidates in the US.   Applications that are submitted through agencies or third party recruiters will not be considered.  We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

New York + 8 moreAll locations: New York | Switzerland | United Kingdom | Singapore | Germany | United Arab Emirates | India | Japan | Australia
Full TimeRemoteTeam 10,001+Since 1961H1B Sponsor

• Establish long-term relationships within assigned accounts while developing an understanding of the client’s strategic goals and overall impact on business results. • Provide project leadership, coordination and architectural guidance for the customer’s Network Virtualization and major VMware initiatives. • Collaborate with multi-functional VMware project teams which could consist of VMware consultants, engineers, product management and support staff. • Map additional VMware solutions to the customer’s unique business and technical requirements. • Maintain a current knowledge of VMware’s load balancing and security solutions, along with a high-level technical knowledge of VMware’s product line and future product direction. • Lead and drive challenging requests across simultaneous client engagements. • Provide clear and constructive product feedback to VMware Product Management teams based on customer use-cases and requirements. • Understand the customer’s high-level business challenges while functioning as an advisory resource for “Best Practices” and driving adoption of VMware solutions within your accounts.

Japan

Security Design Architect

Control Risks Group Holdings

Control Risks Group Holdings focuses on helping organizations through its work as a global specialist risk consultancy. The company offers its expertise to help

Role Description The Security Design Architect / Engineer role will be experienced in protective design, physical security, and/or civil construction to support the Client's Global Security Systems & Technology program. The individual will directly support the Design, Engineering, & Construction (DEC) team and will require a strong understanding of construction project life cycles, including pre-lease, design, and construction phases. In partnership with teammates, this individual will manage all aspects of project management and coordination of protective design requirements including: - Site hardening (barriers, fencing, lighting) - Structural hardening of the building perimeter (façades and doors) - Structural hardening of building interiors (lobbies, mailrooms, critical spaces) for new build and retrofit projects In addition, the position requires close coordination with operational and technological security teams as well as architects, engineers, manufacturers, and contractors across a variety of disciplines (Civil, Landscape, Architectural, and Structural). Responsibilities include, but are not limited to: - Lead daily operations and direct the implementation of guidelines and processes that ensures a cohesive, consistent, and uniformed global program. - Manage end-to-end protective design scope (pre-lease, planning, design, construction, quality assurance) ensuring on-time delivery while driving execution. - Partner with other project specialists responsible for similar processes to collaborate and consolidate project work. - Manage builds of existing and new construction and retrofits, protective design consultant selection, and third-party vendor recommendations. - Act as the liaison and point of contact for both internal and external cross-functional partners, third party vendors, and protective design consultants. - Foster strong cross-functional partnerships and provide clear, concise communication to both technical and non-technical stakeholders. - Meet regularly with stakeholders and project design teams to provide status updates and coordinate project specific requirements. - Provide ongoing communication of planning, project status, issues and risks in a timely fashion to internal global security team members and cross functional partners. - Support continual improvement efforts through evaluation of current practices; investigation of new products; development of presentation materials, forms, and guidance documents; coordination and execution of pilots for programs; and present recommendations and provide business justification to relevant partners. Qualifications - Bachelor’s degree in Architecture, Engineering (Architectural, Civil, Structural), and/or Construction Management with 3-5+ years of relevant work experience in design and construction supervision of offices. - Alternatively, 6+ years of experience in project management or design and construction of offices. - Knowledge of workplace or office design project, protective design and construction management in NORAM region. - Experience with PlanGrid, or ability to learn quickly. - Experience documenting, managing, and executing scalable and repeatable processes. - Experience in cross-functional and multi-disciplinary coordination through planning, design, and construction project phases. - Experience communicating technical information to both technical and non-technical stakeholders. - Proficient with Excel, Outlook, Word, PowerPoint. - Strong verbal and written communication, attention to detail, and organization. - Highly motivated and able to work independently without overhead guidance. - Comfortable working in a fast-paced and demanding setting. - Travel within region required. - Direct experience with protective design products, systems, and/or projects. Benefits - Medical Benefits - Prescription Benefits - FSA - Dental Benefits - Vision Benefits - Life and AD&D - Voluntary Life and AD&D - Disability Benefits - Voluntary Benefits - 401 (K) Retirement - Nationwide Pet Insurance - Employee Assistance Program

United States
$100K - $105K / year
Job Closed