Cobalt AI logo
Cobalt AI

DETECT MORE. RESPOND FASTER. SAVE MONEY.

Senior Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 51-200Since 2016H1B No SponsorCompany SiteLinkedIn

Location

California

Posted

173 days ago

Salary

$160K - $190K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglishCloudPython

Job Description

Senior Security Engineer

Cobalt AI

• Run Cobalt's endpoint and cloud asset security stack across managed laptops, desktops, and cloud infrastructure — including EDR, vulnerability management, and continuous compliance monitoring tooling • Administer Cobalt's compliance automation platform as the system of record for controls and evidence — manage personnel records, reconcile against HRIS and identity provider data, and handle edge cases outside the primary HRIS • Own end-to-end onboarding and offboarding security across employees, contractors, and external partners — verify new hires complete security gating before access is provisioned, apply the right requirements for each personnel tier, and close out access promptly when people leave • Triage alerts from EDR, SIEM, and the vulnerability scanner; recommend patches, file risk acceptances, and gather evidence to close out remediations • Co-own Cobalt's SOC 2 program — coordinate with auditors, gather evidence from internal teams, and run control testing (SSO, IAM, change management, access reviews) ahead of fieldwork • Maintain Cobalt's security policies (vulnerability management, logging and monitoring, incident response, access control), keep them current as the business evolves, and draft new policies when we identify gaps • Own the customer security questionnaire pipeline — partner with Sales, GTM, and product leads to turn around SIG, CAIQ, and bespoke vendor assessments quickly and accurately • Run vendor security reviews for new software and services Cobalt adopts, with clear turnaround expectations and a process the rest of the company can rely on • Triage suspected phishing reports and serve as incident manager when something happens — scope, contain, document, and run the postmortem • Own annual security awareness training rollout and tracking across the company • Partner with Engineering to secure the Cobalt Monitoring Intelligence platform at the edge and bring security perspective into design and code review • Support pen test engagements end-to-end: scoping, remediation tracking, and re-test follow-up

Job Requirements

  • 5+ years in a security engineering, security analyst, or IT security role at a SaaS, cloud, or enterprise software company
  • Hands-on experience running endpoint security and compliance tooling — EDR, vulnerability management, and continuous compliance monitoring platforms — in a regulated environment
  • Strong working knowledge of SOC 2 Type II controls and direct experience supporting an audit cycle (evidence collection, control testing, auditor coordination)
  • Experience answering customer security questionnaires (SIG, CAIQ, or bespoke) with technical accuracy and customer-friendly framing
  • Proficiency with cloud security fundamentals — IAM, network controls, logging, and common attack surfaces — plus solid scripting in Python or Bash
  • BS in Computer Science, Information Security, or equivalent professional experience
  • Proven experience collaborating with cross-functional teams and promoting a culture of sharing security knowledge.

Benefits

  • Competitive salary
  • Equity
  • Full benefits (medical, vision, dental)
  • Flexible work arrangements

Related Categories

Related Job Pages

More Security Engineer Jobs

DuckDuckGo logo

Senior Web Security Engineer, Browser Platform

DuckDuckGo

Independent internet privacy company. Download our browser with privacy built-in, unlike Chrome, on mobile & desktop.

Security Engineer173 days ago
OtherRemoteTeam 51-200Since 2008H1B No Sponsor

• Conduct browser security audits (special pages, DuckAI integrations, password manager, etc.) • Execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code) • Manage application security scanning infrastructure setup (aka SAST/DAST integrations in GitHub) • Deliver on Internal red-team operations (simulated attack scenarios) • Support security triage

United States
$178.5K / year
Full TimeRemoteTeam 5,001-10,000H1B No Sponsor

• Diseñar e implementar prácticas de Seguridad en la Nube y DevSecOps • Asegurar la seguridad de los datos en entornos de nube • Desarrollar flujos de trabajo automatizados de detección y respuesta

Spain
Mozilla logo

Staff Security Engineer, Product Security

Mozilla

The Mozilla Corporation was founded in 2005 as a taxable, wholly-owned subsidiary of the Mozilla Foundation, which launched in 2003. The corporation serves the

Security Engineer173 days ago

• Safeguard millions of users by embedding security into Firefox, Mozilla VPN, and other mission-critical products. • Ensure software products are secure by embedding security into the full Software Development Life Cycle (SDLC). • Anticipate, prioritize and mitigate risks through proactive threat modeling, security assessments, security testing, and automation. • Perform security code reviews • Lead penetration testing on web, mobile, and embedded applications, then guide remediation efforts. • Develop and maintain automated security tests within CI/CD pipelines to catch vulnerabilities early. • Partner with engineers to integrate security throughout the software development lifecycle—not as an afterthought, but as a core design principle. Provide security guidance, develop secure solutions, and facilitate secure releases. • Help define and enforce security policies and provide security guidance to development teams. • Help shape Mozilla's security culture through collaboration, guidance, and education.

United States
$138K - $217K / year
Job Closed

• Secure client IT assets against cyber threats, including malware, ransomware, and unauthorized access attempts • Monitor and analyze security tools and logs to detect suspicious activity and potential incidents • Stay current on threat intelligence and emerging attack techniques • Investigate, triage, and respond to security incidents, including containment and remediation activities • Collaborate with client end users to assess security needs and recommend appropriate solutions • Configure, maintain, and support security technologies such as EDR, firewalls, IDS/IPS, DNS security, MFA, application security, and email security • Implement and maintain strong Microsoft 365 security practices, including conditional access, MFA, and business email compromise prevention and remediation • Participate in vulnerability management efforts using commercial vulnerability scanning tools • Assist with client, server, and laptop configurations, installations, and troubleshooting as needed • Engage in client discussions around security vulnerabilities, mitigation strategies, and best practices • Apply data encryption best practices to protect data at rest • Analyze security data and generate reports for internal and client stakeholders • Provide occasional after-hours and weekend support during active incident response efforts.

United States
$85K - $100K / year
Job Closed