The leading Postgres data and AI company
Staff Security Engineer
Location
United States
Posted
26 days ago
Salary
0
Seniority
Lead
Job Description
Staff Security Engineer
EDB
• Lead cross-functional application security initiatives to identify, prioritize, and mitigate security risks across EDB's products. • Write and review code to build security automation and tooling that serves the full InfoSec organization accelerating the team's ability to detect, respond, and remediate. • Build & orchestrate security agents deploying AI-driven security tools using LLMs and orchestration frameworks (LangChain) to automate threat modeling, alert triaging, and code analysis. • Partner with internal teams to implement security guardrails for internal AI applications, focusing on prompt injection mitigation, data leakage prevention, and secure architectures. • Integrate AI tools into the SDLC to perform automated architectural risk assessments, security reviews, and identify vulnerabilities in generated code or toolsets. • Design and integrate complex security architectures across cloud and on-premise environments, strengthening EDB's overall defense posture against advanced threats. • Lead vulnerability disclosure investigations, coordinating with engineering teams to assess impact, validate findings, and drive timely remediation. • Embed security into the software development lifecycle through secure design reviews, code review, threat modeling, and ongoing partnership with engineering and product teams. Build trust with development teams by meeting them where they are, respecting their workflows, and delivering clear guidance throughout implementation. • Deliver security solutions as minimum valuable products, starting with the smallest solution that provides the needed value and iterating over time as capacity allows. • Drive continuous improvement of security tooling, detection capabilities, and monitoring infrastructure.
Job Requirements
- A developer-centric background with demonstrated ability to write and review production-quality code in Python, Go, or a comparable language.
- Hands-on LLM engineering with proven experience working with LLM APIs (Anthropic Claude, OpenAI) and 'AI-as-a-Service' kits to build functional internal tools or security automations.
- Deep understanding of the OWASP Top 10 for LLMs, including risks like prompt injection, insecure output handling, and training data poisoning.
- Ability to craft complex, multi-shot prompts and system instructions to ensure AI security agents provide high-fidelity, low-noise results.
- Proven experience leading cross-functional application security initiatives in complex, distributed environments.
- Demonstrated experience leading vulnerability disclosure investigations, including impact assessment, coordination with engineering teams, and driving remediation. (You don't need to be able to write novel exploits — you need to assess risk and drive fixes.)
- Proven ability to build trust with development teams: reviewing their code, engaging in their design discussions, and partnering as a peer rather than a gatekeeper.
- Strong communication skills with the ability to influence cross-functional stakeholders, translate technical security concerns into business risks, and negotiate priorities with partner teams to get security initiatives on shared roadmaps.
- An empathetic, collaborative approach to working with partner teams, respecting their processes and assuming the best while still driving accountability for security outcomes.
- Demonstrated ability to balance long-term security architecture initiatives with day-to-day operational security needs, delivering incremental value rather than waiting for large, all-at-once solutions.
- An AI-first approach to problem solving and security, leveraging AI tools and techniques to accelerate delivery, automate security workflows, and enhance decision-making.
- Interest in growing into a broader InfoSec role over time, taking on expanded scope and influence across the organization.
Benefits
- We provide access to CuraLinc to aid employees in health and wellness tips and practices
- Wellness Fridays extending to December 2026!
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cybersecurity Lead Engineer
TelosTelos provides cybersecurity services and solutions for a global base of clients in the government, military, and commercial sectors. The information technology
Title: Cybersecurity Lead Engineer - C Location: Ashburn United States Job Description: The most security-conscious organizations trust Telos Corporation to protect their vital IT assets. The reputation of our company rests on the quality of our solutions and the integrity of our people. Explore what you can bring to our solutions in the areas of cyber, cloud and enterprise security. Be a part of the Telos culture and see what sets us apart! Telos offers an excellent compensation package with benefits that include generous paid time off, medical, dental, vision, tuition reimbursement, and 401k. Our employees enjoy more than just a great work environment! This position will be based at Remote/Ashburn - Travel 10% Responsibilities: - Implement and manage RMF processes to ensure compliance with NIST, DoD, and other applicable security guidelines. - Conduct vulnerability assessments using ACAS (Nessus/Tenable Security Center) and analyze scan results to identify and mitigate risks. - Utilize SCAP tools for automated security compliance checks and remediation. - Apply Security Technical Implementation Guides (STIGs) to configure and harden systems. - Develop and maintain RMF documentation, including System Security Plans (SSP), and Plan of Action and Milestones (POA&Ms). - Support system accreditation efforts, including security control assessments and risk analysis. - Work closely with project managers, system administrators, system development engineers and other cybersecurity professionals to implement security best practices. - Stay updated on evolving cybersecurity policies, regulations, and emerging threats. Job Requirements Qualifications: - Bachelor's Degree (preferred in Cybersecurity, IT, or related field) - 5-7 years of experience - IAM Level III - Hands-on experience with ACAS (Nessus/Tenable Security Center), SCAP tools, and STIG compliance. - Familiarity with NIST 800-53, DoD RMF process, and system accreditation procedures. - Strong documentation and reporting skills. - Experience working with DoD or federal cybersecurity compliance programs. - Strong analytical and problem-solving skills. The successful candidate must meet eligibility requirements to access sensitive information, which requires US citizenship. Telos maintains a drug-free workplace and will conduct drug testing on all applicants who have accepted an offer of employment. Telos Corporation participates in the E-Verify program. Therefore, any employment with Telos will also be contingent upon confirmation from the Social Security Administration ("SSA") and/or the Department of Homeland Security ("DHS") of your authorization to work in the United States. Telos offers excellent compensation packages including salary commensurate with experience and benefits to meet your needs for today and the future. Telos Corporation and its subsidiaries are committed to equal opportunity for all, without regard to race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, age, veteran status, disability, genetic information, or any other protected characteristic. Telos Corporation will make reasonable accommodations for known physical or mental limitations of otherwise qualified employees and applicants with disabilities unless the accommodation would impose an undue hardship on the operation of our business. Telos Corporation is an EEO/AA employer. Job Type Full-Time Location Ashburn, VA 20147 US (Primary) Telos offers an excellent compensation packages including salary commensurate with experience and benefits to meet your needs for today and the future. Telos and its subsidiaries are an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
Associate Cyber Essentials and Cyber Essentials Plus Assessor
IntelanceEnterprise Architecture. Cybersecurity. AI Operating Models. We build strategic systems for the future of business.
Role Description We are building a selective associate panel to support a growing book of Cyber Essentials and Cyber Essentials Plus engagements. This is not an employment role. It is a long-term associate relationship for experienced assessors who want steady, well-run work, named inclusion on our panel, and a professional home that treats assurance delivery as a craft. - Conduct Cyber Essentials self-assessment reviews against the current IASME question set and issue certification decisions within agreed service levels. - Deliver Cyber Essentials Plus technical audits, including: - vulnerability scanning - authenticated scans - sample device testing - multi-factor authentication validation - malware protection checks - Write clear, defensible assessment reports and certification recommendations. - Guide client technical contacts through remediation where gaps are identified, without drifting into paid consultancy during the certification window. - Maintain evidence and audit trails to IASME Certification Body standards. - Participate in internal calibration sessions to keep assessment quality consistent across the panel. - Where capacity and interest align, support adjacent work across IASME Cyber Assurance Level 1 and Level 2 and ISO 27001 readiness. Qualifications - Current or recently held IASME assessor licence for Cyber Essentials and Cyber Essentials Plus, or equivalent hands-on delivery experience with a willingness to be licensed under Intelance. - Minimum three years delivering Cyber Essentials Plus technical audits in the UK market. - Strong working knowledge of the five Cyber Essentials controls, the current question set, and common interpretation edge cases. - Practical experience with vulnerability scanning tooling used for Cyber Essentials Plus. - Confident engaging directly with client IT and security leads, including SME owners and enterprise CISO teams. - Based in the UK, with the right to work in the UK. - Able to operate outside IR35 through a limited company, or willing to engage on a compliant basis. - Willing to be listed publicly as an Associate Assessor of Intelance, including on LinkedIn, while on the panel. - Excellent written English. Reports must be client-ready without heavy editing. Requirements - Desirable: ISO 27001 Lead Implementer or Lead Auditor certification. - Experience with IASME Cyber Assurance, NIST CSF, or SOC 2 readiness. - Sector depth in financial services, healthcare, SaaS, or private equity-backed mid-market. Benefits - Competitive day rate and per-certification fee structure, paid on 14-day terms. - Right of first refusal on engagements matched to your sector and availability. - Named inclusion on the Intelance Cyber Assurance panel page and proposal credentials. - Co-branded continuing professional development sessions and quarterly calibration workshops. - Referral fee of up to 10 percent of net first-year fees for associate originated client work. - Direct access to the Intelance delivery leadership. No sub-sub-contracting. No layers. - Clean tooling, templates, and quality frameworks so you spend time assessing, not formatting. Company Description Intelance is a strategic consultancy specialising in Enterprise Architecture, AI transformation, and cybersecurity. We help organisations design the systems, structures, and operating models needed to scale, secure, and lead in a volatile world. Our team combines TOGAF-based architecture thinking with cybersecurity governance (Cyber Essentials, ISO 27001), cloud-native patterns, and AI operating model design. From EA blueprints to Zero Trust frameworks to AI adoption roadmaps - Intelance transforms complexity into strategic clarity. We serve public and private sector clients across the UK, Africa, and the Middle East - particularly in regulated industries such as government, healthcare, finance, energy, and pharma.
Network Security Advisor
NTT DATA ServicesNTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers, and application services. Our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.
Role Description The Network Senior Specialist Advisor is responsible for the daily operations and maintenance of firewall, Prisma, F5, and routing and switching environments across multiple customer infrastructures. This role primarily supports network security products from leading vendors such as Palo Alto, Cisco, and F5. The advisor will design, validate, and troubleshoot network traffic flows, security implementations, and configurations to ensure stable and secure operations. Network Services include the ongoing management and support of customers’ network and security environments. The successful candidate will independently troubleshoot firewall and network traffic issues, maintain accurate and up-to-date documentation for network and security platforms, and support operational processes. The role requires the ability to work independently, resolve complex issues with minimal client input, and appropriately escalate matters when solutions are not immediately apparent. Qualifications - Highly experienced Network and Security Architect with 12+ years of hands-on network troubleshooting experience, including at least 5 years in network and security administration - Extensive hands-on experience with Palo Alto Firewalls, Prisma Access / Prisma SASE, Cisco routing and switching, F5, SD-WAN, and AWS networking - Strong expertise in routing protocols including EIGRP, BGP, along with hands-on experience with switching technologies - CCIE (Routing & Switching) & PCNSE certification - Proven ability to analyze complex technical issues and design optimal, scalable solutions - Deep understanding of Palo Alto architecture, including templates, stacks, Global Protect, and advanced troubleshooting using packet captures and debugs - Network design experience is a strong advantage Requirements - Act as a Subject Matter Expert (SME), providing advanced technical escalation support to L2/L3 engineers - Deliver end-to-end operational support for enterprise Network and Security environments across multiple customers - Troubleshoot and resolve complex issues related to Palo Alto Firewalls, Prisma/GlobalProtect, Routing & Switching, F5 and associated network traffic flows - Perform advanced troubleshooting using packet captures, logs, and debugs on Palo Alto firewalls - Write custom queries and generate operational and security reports using Palo Alto reporting tools - Support daily steady-state operations, including request fulfillment, change management, and participation in weekly on-call rotations - Conduct weekly and monthly health checks across all supported network security platforms - Perform system maintenance activities, including upgrades, patching, and configuration updates - Assist in firewall rule set reviews to enhance customers’ overall security posture and compliance - Detect, investigate, and respond to security incidents; create customer tickets and manage issues through resolution and closure - Develop and provide clear resolution and remediation plans for device, service, and security issues - Ensure compliance with Service Level Agreements (SLAs), operational standards, and ITIL best practices - Maintain accurate, current documentation for systems, configurations, procedures, and operational activities - Proactively recommend service, process, and technical improvements to optimize the Network Security and Firewall teams Benefits - Flexible work arrangements - Access to a robust ecosystem of innovation centers - Commitment to employee development and training - Inclusive and adaptable work environment
IT & Cyber Security Engineer
OnTracHeadquartered in Chandler, Arizona, OnTrac is a package delivery company that provides overnight delivery services at ground rates to millions of consumers. Thi
Role Description The IT & Cyber Security Engineer is responsible for designing, building, and maintaining robust security architectures across hybrid environments (on‑prem + cloud). You will enable the SOC by improving detection and orchestration capabilities and enable GRC by translating regulatory requirements into technical controls and automated evidence collection. This is a "hands-on-keyboard" role that requires the ability to pivot between deep technical engineering and assisting in strategic support. Qualifications - Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent practical experience) - 10+ years of progressive experience in IT and Security - At least 3 years in a senior or lead engineering capacity - Strong ability to code/script in Python, PowerShell, or Bash to automate repetitive security tasks and integrations - Deep understanding of SIEM logic, YARA rules, and EDR configuration to improve detection efficacy - Ability to interpret NIST CSF, ISO 27001, or SOC2 and implement the technical controls required to meet them - Preferred CISSP, CISM, or hands-on technical certifications like GIAC (GCIA, GCDA) or Offensive Security (OSCP) Requirements - SOC + GRC enablement: Design and implement technical solutions that assist the SOC in alert orchestration (SOAR) and provide the GRC team with automated risk monitoring and evidence collection capabilities. - Security integration: Lead the integration of security tools (EDR, SIEM, Cloud Security) to ensure a unified and visible security posture. - Risk management support: Assist in technical risk assessments by identifying vulnerabilities and recommending/implementing remediation engineering. - Architecture & engineering: Develop and maintain security infrastructure across hybrid environments (on‑prem/cloud), applying security by design to new deployments. - Incident response escalation: Serve as a Tier 3 escalation point for complex incidents requiring deep forensic and/or architectural expertise. - Mentorship: Guide junior engineers and analysts, fostering technical excellence and proactive security practices. Benefits - Medical, Dental, and Vision insurance; HSA and FSA options - Life and Disability coverage (basic and voluntary) - Voluntary Accident, Critical Illness, Identity & Fraud Protection, Auto & Home, and Pet Insurance - Competitive benefits and 401(k) with company match - Referral Bonus Program - Up to $500 per referral! - Paid Time Off including Holiday pay - Employee Assistance Program - A safe and clean work environment

