Job Closed
This listing is no longer active.
Senior Security Engineer
Location
United States
Posted
158 days ago
Salary
$107.4K - $150K / year
Seniority
Senior
Job Description
Senior Security Engineer
Onit
• Support the Onit security function during US Central Time business hours. • Implement and manage cloud-native security tools and third-party solutions for threat detection and incident response. • Define, maintain, and execute the Incident Response plan, investigating and resolving incident escalations. • Perform regular risk assessments and vulnerability scans of cloud infrastructure, ensuring timely remediation. • Collaborate with Dev, DevOps, and Infra teams to remediate identified vulnerabilities, discuss security best practices, and assist with security incident response. • Analyze EDR alerts and logs to identify potential security incidents, taking appropriate action. • Continuously evaluate and implement security tools and practices to enhance the security posture of the Onit environment. • Assist with application security reviews and threat modeling. • Assist with security awareness programs for employees regarding security best practices
Job Requirements
- Minimum of 5 years of experience in information security, with at least 3 years focused on cloud security for enterprise SaaS applications.
- Proficient in AWS with a strong understanding of AWS networking/VPC, IAM, Security Groups, EC2, RDS, S3, and containers (EKS/ECS).
- Extensive hands-on experience investigating security incidents, along with the creation, management, and execution of security runbooks / playbooks.
- This includes the ability to search logs in CloudTrail, CloudWatch, VPC Flow logs, etc.
- Experience with tooling for network (e.g. Wireshark) and host forensics
- Knowledge of various AWS Native Security tools, security frameworks, and CSPM tools.
- Experience in security tools such as vulnerability scanners, IDS/IPS, SIEM, firewalls, and endpoint security monitoring.
- Experience with threat detection and threat intelligence.
- Must be proficient in Linux.
- Application security experience with an understanding of SAST, DAST, SBOMs, and other scans and artifacts to help improve application security posture
- Experience with AWS Guard Duty and CrowdStrike or equivalent.
- Strong communication, problem-solving, and collaboration skills.
Benefits
- Health Coverage Choices: Three medical plan options, plus dental and vision, so you can choose what fits best. Employees on our HDHP plan also receive employer contribution to the HSA.
- Retirement Savings: 401(k) with a 100% match on the first 3% and 50% on the next 2% of employee contributions.
- Time Away: Flexible paid time off, 7 sick days, and 9 paid company holidays annually.
- Family Support: Exceptional paid leave for birth parents, non-birth parents, and caregivers. Onit also offers surrogacy and adoption reimbursement.
- Income Protection: 100% employer-paid life and disability insurance.
- Additional Coverage Options: Voluntary benefits including hospital indemnity, critical illness, accident, and even pet insurance.
- Tax-Advantaged Accounts: Healthcare FSA, HSA, and dependent care FSA.
- Community Engagement: One paid volunteer day each year to give back to the community.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Privacy & Security Specialist
Dev PartnersScale your dev team faster with our IT Staff Augmentation services. Hire 100% fully vetted and reliable developers.
• Implement and maintain strong authentication protocols, including multi-factor authentication (MFA) for admin and employee accounts. • Enforce role-based access controls (RBAC) to limit access to sensitive systems and data based on job responsibility. • Monitor security logs and alerts to detect unauthorized access or suspicious activity. • Regularly update and patch website CMS, plugins, payment gateways, and related software to eliminate vulnerabilities. • Implement encryption of sensitive data both at rest and in transit (SSL certificates, AES-256 encryption, etc.). • Develop and maintain data retention and disposal policies, ensuring secure deletion of data no longer needed. • Maintain compliance with PCI-DSS standards for payment security and privacy regulations such as GDPR, HIPAA, or CCPA, as applicable. • Oversee the security of payment processing platforms, ensuring tokenization, end-to-end encryption, and fraud detection tools are in place. • Coordinate with payment gateway providers to maintain updated security certifications and compliance. • Schedule and conduct periodic vulnerability scans, penetration tests, and audits to proactively identify and address security gaps. • Collaborate with external security consultants or ethical hackers for advanced penetration testing. • Develop and maintain an incident response plan and lead response efforts for any suspected or actual breaches. • Provide security awareness training to staff regarding password hygiene, phishing, data handling, and access protocols. • Utilize real-time monitoring tools to oversee server logs, network traffic, and application access. • Implement proactive alerts for suspicious activities and maintain a dashboard of security metrics.
• Architect, Build, and Optimize ML Systems: Develop and deploy robust ML models that deliver high-impact results for real-world applications. • Training Pipeline Development: Design and implement efficient, scalable pipelines to train and retrain ML models, ensuring they meet business needs. • Fine-Tuning Large Language Models (LLMs): Continuously fine-tune LLMs to align with specific enterprise requirements, enhancing accuracy, relevance, and performance. • Feedback Systems Design: Implement and refine feedback loops to iteratively improve the effectiveness of ML models over time. • Cross-Functional Collaboration: Work closely with product and business teams to understand and translate requirements into ML solutions that provide tangible outcomes. • Stay Current with ML Advancements: Keep up with the latest in ML research and best practices, applying insights to our ML infrastructure to ensure it remains at the cutting edge. • Mentorship and Knowledge Sharing: Guide and mentor junior team members, fostering a culture of continuous improvement and technical growth. • Technical Communication: Clearly and effectively communicate ML methodologies, results, and insights to non-technical stakeholders.
Senior AI/ML Engineer, Applied Machine Learning - Security Clearance
Red Cell PartnersRed Cell Partners, founded in 2020, is a dynamic and rapidly growing firm specializing in launching and scaling innovative companies across various industries.
• Architect, Build, and Optimize ML Systems: Develop and deploy robust ML models that deliver high-impact results for real-world applications. • Training Pipeline Development: Design and implement efficient, scalable pipelines to train and retrain ML models, ensuring they meet business needs. • Fine-Tuning Large Language Models (LLMs): Continuously fine-tune LLMs to align with specific enterprise requirements, enhancing accuracy, relevance, and performance. • Feedback Systems Design: Implement and refine feedback loops to iteratively improve the effectiveness of ML models over time. • Cross-Functional Collaboration: Work closely with product and business teams to understand and translate requirements into ML solutions that provide tangible outcomes. • Stay Current with ML Advancements: Keep up with the latest in ML research and best practices, applying insights to our ML infrastructure to ensure it remains at the cutting edge. • Mentorship and Knowledge Sharing: Guide and mentor junior team members, fostering a culture of continuous improvement and technical growth. • Technical Communication: Clearly and effectively communicate ML methodologies, results, and insights to non-technical stakeholders.
• Design, implement, and maintain security services that support the business • Lead the development, implementation, and ongoing maintenance of comprehensive security strategies and solutions • Design and deploy advanced security controls to safeguard networks, systems, and applications • Work across disciplines to shape our security services strategy and execution • Mentor and galvanize new engineers to do their best work • Set and uphold the standard for security processes to support high-quality engineering



