DETECT MORE. RESPOND FASTER. SAVE MONEY.
Senior Security Engineer
Location
California
Posted
173 days ago
Salary
$160K - $190K / year
Seniority
Senior
Job Description
Senior Security Engineer
Cobalt AI
• Run Cobalt's endpoint and cloud asset security stack across managed laptops, desktops, and cloud infrastructure — including EDR, vulnerability management, and continuous compliance monitoring tooling • Administer Cobalt's compliance automation platform as the system of record for controls and evidence — manage personnel records, reconcile against HRIS and identity provider data, and handle edge cases outside the primary HRIS • Own end-to-end onboarding and offboarding security across employees, contractors, and external partners — verify new hires complete security gating before access is provisioned, apply the right requirements for each personnel tier, and close out access promptly when people leave • Triage alerts from EDR, SIEM, and the vulnerability scanner; recommend patches, file risk acceptances, and gather evidence to close out remediations • Co-own Cobalt's SOC 2 program — coordinate with auditors, gather evidence from internal teams, and run control testing (SSO, IAM, change management, access reviews) ahead of fieldwork • Maintain Cobalt's security policies (vulnerability management, logging and monitoring, incident response, access control), keep them current as the business evolves, and draft new policies when we identify gaps • Own the customer security questionnaire pipeline — partner with Sales, GTM, and product leads to turn around SIG, CAIQ, and bespoke vendor assessments quickly and accurately • Run vendor security reviews for new software and services Cobalt adopts, with clear turnaround expectations and a process the rest of the company can rely on • Triage suspected phishing reports and serve as incident manager when something happens — scope, contain, document, and run the postmortem • Own annual security awareness training rollout and tracking across the company • Partner with Engineering to secure the Cobalt Monitoring Intelligence platform at the edge and bring security perspective into design and code review • Support pen test engagements end-to-end: scoping, remediation tracking, and re-test follow-up
Job Requirements
- 5+ years in a security engineering, security analyst, or IT security role at a SaaS, cloud, or enterprise software company
- Hands-on experience running endpoint security and compliance tooling — EDR, vulnerability management, and continuous compliance monitoring platforms — in a regulated environment
- Strong working knowledge of SOC 2 Type II controls and direct experience supporting an audit cycle (evidence collection, control testing, auditor coordination)
- Experience answering customer security questionnaires (SIG, CAIQ, or bespoke) with technical accuracy and customer-friendly framing
- Proficiency with cloud security fundamentals — IAM, network controls, logging, and common attack surfaces — plus solid scripting in Python or Bash
- BS in Computer Science, Information Security, or equivalent professional experience
- Proven experience collaborating with cross-functional teams and promoting a culture of sharing security knowledge.
Benefits
- Competitive salary
- Equity
- Full benefits (medical, vision, dental)
- Flexible work arrangements
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Web Security Engineer, Browser Platform
DuckDuckGoIndependent internet privacy company. Download our browser with privacy built-in, unlike Chrome, on mobile & desktop.
• Conduct browser security audits (special pages, DuckAI integrations, password manager, etc.) • Execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code) • Manage application security scanning infrastructure setup (aka SAST/DAST integrations in GitHub) • Deliver on Internal red-team operations (simulated attack scenarios) • Support security triage
• Diseñar e implementar prácticas de Seguridad en la Nube y DevSecOps • Asegurar la seguridad de los datos en entornos de nube • Desarrollar flujos de trabajo automatizados de detección y respuesta
Staff Security Engineer, Product Security
MozillaThe Mozilla Corporation was founded in 2005 as a taxable, wholly-owned subsidiary of the Mozilla Foundation, which launched in 2003. The corporation serves the
• Safeguard millions of users by embedding security into Firefox, Mozilla VPN, and other mission-critical products. • Ensure software products are secure by embedding security into the full Software Development Life Cycle (SDLC). • Anticipate, prioritize and mitigate risks through proactive threat modeling, security assessments, security testing, and automation. • Perform security code reviews • Lead penetration testing on web, mobile, and embedded applications, then guide remediation efforts. • Develop and maintain automated security tests within CI/CD pipelines to catch vulnerabilities early. • Partner with engineers to integrate security throughout the software development lifecycle—not as an afterthought, but as a core design principle. Provide security guidance, develop secure solutions, and facilitate secure releases. • Help define and enforce security policies and provide security guidance to development teams. • Help shape Mozilla's security culture through collaboration, guidance, and education.
• Secure client IT assets against cyber threats, including malware, ransomware, and unauthorized access attempts • Monitor and analyze security tools and logs to detect suspicious activity and potential incidents • Stay current on threat intelligence and emerging attack techniques • Investigate, triage, and respond to security incidents, including containment and remediation activities • Collaborate with client end users to assess security needs and recommend appropriate solutions • Configure, maintain, and support security technologies such as EDR, firewalls, IDS/IPS, DNS security, MFA, application security, and email security • Implement and maintain strong Microsoft 365 security practices, including conditional access, MFA, and business email compromise prevention and remediation • Participate in vulnerability management efforts using commercial vulnerability scanning tools • Assist with client, server, and laptop configurations, installations, and troubleshooting as needed • Engage in client discussions around security vulnerabilities, mitigation strategies, and best practices • Apply data encryption best practices to protect data at rest • Analyze security data and generate reports for internal and client stakeholders • Provide occasional after-hours and weekend support during active incident response efforts.



