Suno logo
Suno

Make any song you can imagine

Head of Security Engineering

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 1-10H1B No SponsorCompany SiteLinkedIn

Location

California + 1 moreAll locations: California | New York

Posted

23 days ago

Salary

$275K - $375K / year

Seniority

Lead

Bachelor Degree10 yrs expEnglishAWSCloudCyber SecurityGoogle Cloud Platform

Job Description

Head of Security Engineering

Suno

• Design and implement secure cloud architectures across cloud platforms (e.g., AWS, GCP) • Enable and lead teams to innovate and develop strong security programs and overall strategies within the domains of Cloud Security, Identity Access Management, Security Operations, and Product Security. • Provide technical leadership of Security products from conception to operation, ensuring they are built to the highest quality standards. • Understand and maintain knowledge of emerging security technologies, advances in agentic AI, and their applications to consumer products • Collaborate closely with other teams to ensure that security is a core consideration with all decisions. • Nurture an engineering team focused on impact, fostering a culture of collaboration, trust, ownership, and open communication. • Create a high-performance team through delivery of clear performance expectations and continuous feedback, while setting a strong bar for engineering standards and high quality decision making.

Job Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field
  • 10+ years of experience leading security engineering and operations departments.
  • 5+ years of experience with securing AWS environments.
  • Proven experience in successfully building and leading mission-critical teams.
  • Experience navigating complex global regulatory environments and consumer ecosystems
  • Strong technical skills and a willingness to dive deeply into details.
  • Experience developing, managing, and evaluating talent.
  • Demonstrated experience working with regulatory bodies, executive leadership, and developing strong partner team relationships.
  • Domain expertise in two or more security specializations (Product Security, Cloud Security, Security Operations, EIAM, Cryptography, etc.)

Benefits

  • Company Equity Package
  • 401(k) with 3% Employer Match & Roth 401(k)
  • Medical, Dental, & Vision Insurance (PPO w/ HSA & FSA options)
  • 11 Paid Holidays + Unlimited PTO & Sick Time
  • 16 Weeks of Paid Parental Leave
  • Creative Education Stipend
  • Generous Commuter Allowance
  • In-Office Lunch (5 days per week)

Related Categories

Related Job Pages

More Security Engineer Jobs

EY logo

Staff Cyber Architect – OT Security, Engineering

EY

Building a #BetterWorkingWorld by providing trust through assurance and helping organizations grow, transform & operate.

Full TimeRemoteTeam 10,001+Since 1989H1B Sponsor

• Perform vulnerability assessments on OT assets including PLCs, HMIs, SCADA systems, historians, and industrial networks • Support asset inventory and vulnerability tracking for OT environments • Analyse vulnerability scan results and advisories (ICS-CERT, vendors) to determine risk and impact • Assist in risk-based prioritization and remediation of identified vulnerabilities as per production constraints • Understanding of security-related operational processes in the OT-ICS environments

India
Job Closed
EY logo

Senior Cyber Architect – OT Security

EY

Building a #BetterWorkingWorld by providing trust through assurance and helping organizations grow, transform & operate.

Full TimeRemoteTeam 10,001+Since 1989H1B Sponsor

• Monitor OT networks using specialized OT SOC and network monitoring tools • Analyse alerts from OT security monitoring solutions (e.g., Nozomi, Claroty, Tenable.ot, Defender for IoT, etc.) • Identify suspicious activities, anomalies, and indicators of compromise (IoCs) affecting ICS environments • Perform Level 2 alert triage and investigation for OT incidents • Support for OT cybersecurity incident response activities • Understanding of security-related operational processes in the OT-ICS environments • Understanding of technologies (typical assets, communication protocols, technical architectures) utilized by OT-ICS systems and networks • Knowledge of cyber / information security concepts, risk and controls concepts • Understanding of aspects of functional safety (SIS) • Knowledge of TCP/IP, concepts of OSI layer and protocols, networking and security concepts • Knowledge of the technical security solutions utilized within OT-ICS systems and networks • Knowledge of OS (Windows / Linux) security, Database security • Prior experience working alongside delivery leads and architects to Identify and manage risks is a plus

India
Job Closed
Cisco logo

Security Research Engineer

Cisco

We securely connect everything to make anything possible.

Full TimeRemoteTeam 10,001+Since 1984H1B Sponsor

Role Description This is a fully remote role based in the United States. As a member of Talos, you will support cutting edge detection and mitigation technologies. You will work towards keeping yourself abreast of the latest industry threat creation and defense techniques, and you will develop proof-of-concept solutions, provide domain expertise, and guide implementation to facilitate successful security posture in Cisco’s products. If you enjoy vulnerability research, crash analysis, reverse engineering, and researching new techniques and writing tools to automate these tasks, this job is for you! Your Impact - Security research including development of tools for vulnerability analysis and mitigation. - Development of static and run-time analysis tools to figure out root cause and input conditions related to a vulnerability. - Vulnerability triage and proof of concept exploit development to support the creation of detection content. - Write detailed technical reports, summaries, and testing methodologies. - Research emerging technologies, protocols, and testing methodologies. - Develop proof of concept exploits for testing vulnerability mitigations. - Perform patch analysis to find and trigger vulnerabilities. - Reverse engineer binary applications, protocols, and formats. - Analyze vulnerabilities and emerging security threats and technologies. - Provide critical security focused expertise to engineering organizations. Qualifications - 3+ years of experience in vulnerability research or a closely related area such as exploit or mitigation development on Linux Systems. - 3+ years’ experience with C/C++, and a scripting language (e.g., Python), and assembly (e.g., x86/x64, ARM, etc.). Requirements - Bachelor’s degree or equivalent in Computer Science, Electrical Engineering, Cyber Security, or other tech-related degree. - Experience with Linux internals. - Experience with binary auditing and reverse engineering, and with related tools such as IDA Pro, Binary Ninja, Ghidra, etc. and with plugin development. - Experience with common vulnerabilities and methods of exploitation, such as memory corruption, web application exploitation, file format vulnerabilities, protocol-based weaknesses, etc. - Knowledge of common file formats, network protocol structures, and enterprise networking architecture. - Ability to work independently with minimum supervision and to tackle additional tasks as the need arises. Benefits - Medical, dental and vision insurance. - 401(k) plan with a Cisco matching contribution. - Paid parental leave. - Short and long-term disability coverage. - Basic life insurance. - 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees. - 1 paid day off for employee’s birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco. - Non-exempt employees receive 16 days of paid vacation time per full calendar year. - Exempt employees participate in Cisco’s flexible vacation time off program. - 80 hours of sick time off provided on hire date and each January 1st thereafter. - Optional 10 paid days per full calendar year to volunteer.

United States
$146.7K - $277.6K / year
Qualcomm logo

Senior Security Certification Analyst

Qualcomm

Since 1985, Qualcomm has been an innovator in the wireless telecommunications industry with more than 13,000 patents in the United States. Today, Qualcomm provides a variety of pro

Role Description We are seeking a senior security certification engineer with a strong hands-on background in FIPS 140-2 and FIPS 140-3 validations. You will join our Security Certification team supporting Qualcomm product certifications across hardware and software domains. In this role, you will apply 5-8 years of experience to ensure Qualcomm cryptographic modules achieve FIPS 140 compliance, working closely with worldwide engineering teams, product managers, corporate security, third-party evaluation labs, and government validation authorities. The role offers exposure to all aspects of product security—especially cryptography, certification requirements, and the development of FIPS documentation—ultimately enabling Qualcomm to meet global customer security needs and deploy trusted, compliant solutions. Qualifications - Bachelor's degree in Electrical Engineering, Computer Science, Information Security, Mathematics or equivalent - Preferred: Master's in Computer Engineering, Mathematics, Computer Science, or Electrical Engineering Requirements - 5+ years of experience in embedded product’s security, cryptography, and security certification (e.g. Secure Processor or secure element, Cryptographic libraries, hardware cryptography, and embedded security software) in the context of FIPS 140-2/-3, Common Criteria (CC), SESIP or banking standards such as EMVCo, MasterCard, VISA, etc. - 3+ years of embedded security/cryptography experience with direct involvement in FIPS 140-2/-3 cryptographic module validations (e.g. cryptographic library or secure hardware module validation) - 2+ years of experience in project management - Intermediate knowledge of cryptography (symmetric, asymmetric, hashes, RNG) and associated standards Preferred Qualifications - 8+ years total experience in secure embedded systems or product security roles (beyond FIPS) – indicating deeper expertise - 5+ years of experience working in or with accredited FIPS 140 evaluation labs (e.g. ATSEC) or in product teams that achieved FIPS validations – provides valuable perspective on the testing and certification process - 5+ years of experience in project management - Advanced cryptography knowledge (e.g. various standards, entropy sources) and familiarity with security architecture (ARM TrustZone, hardware cryptographic engines, etc.) Principal Duties and Responsibilities - Coordinate and execute FIPS 140-3 validation projects from planning through lab submission and certification, working under guidance from senior team members as needed. - Prepare, review, and maintain detailed FIPS certification documentation (e.g. security policies, design documentation), ensuring strict compliance with NIST requirements. - Collaborate closely with third-party labs and certification authorities to facilitate evidence collection, testing, and resolve any issues throughout the validation process. - Advise and support internal engineering teams on FIPS 140 requirements and best practices, helping integrate compliance into product development. - Work independently on assignments with moderate supervision, and effectively plan and prioritize tasks to meet project milestones. - Communicate clearly with cross-functional stakeholders (engineers, managers, external evaluators), conveying technical details and progress. Minimum Qualifications - Bachelor's degree in Engineering, Computer Science, or related field and 4+ years of Security Engineering or related work experience. - OR Master's degree in Engineering, Computer Science, or related field and 3+ years of Security Engineering or related work experience. - OR PhD in Engineering, Computer Science, or related field and 2+ years of Security Engineering or related work experience.

France