Federato logo
Federato

When underwriters have real-time risk selection and portfolio insights at their fingertips, profitable growth follows!

Senior Security Engineer

Location

North America

Posted

30 days ago

Salary

$160K - $180K / year

Seniority

Senior

Job Description

Senior Security Engineer

Federato

• Contribute to our application security program. Work with our SAST, DAST, and SCA tooling, triage and prioritize vulnerabilities, and partner with engineering teams to drive remediation. Participate in threat modeling and secure design reviews on new products and services. • Share incident response on-call. Investigate, contain, and resolve security incidents alongside the rest of the team. Help refine our runbooks, detection coverage, and post-incident process. • Help harden our cloud and Kubernetes environment. Contribute to security posture across GCP and GKE: IAM and least-privilege, secrets management, container and supply chain security, and IaC guardrails (Terraform). • Build detections and security automation. Engineer high-signal detections from cloud, identity, and application telemetry. Automate the toil of vuln triage, access reviews, SaaS posture, questionnaire workflows so the team scales. • Streamline customer security work. Help respond to customer security questionnaires and audits, and build internal tooling and a knowledge base so this scales as deal volume grows. • Strengthen business continuity and DR. Help assess threats to continuity, contribute to DR plans, and run real exercises against them. • Help drive a security culture across engineering. Pair on developer training, secure-coding guidance, and standards work to make the secure path the easy path.

Job Requirements

  • 5+ years of hands-on experience managing cloud infrastructure and automation.
  • Experience in achieving SOC2 Type II, ISO 27001, or similar certifications
  • Experience with Node.js or Python for backend services in a microservices architecture.
  • 3+ years of experience with cloud providers, preferably Google Cloud Platform (GCP).
  • Solid experience with cloud security on GCP or AWS, including IAM, Kubernetes, and IaC.
  • Knowledge of asynchronous processing, message queues (e.g., Kafka, Pub/Sub), and event-driven architecture for backend applications.
  • Experience focused on the internal engineer team success

Benefits

  • Total compensation package includes stock options, benefits, and additional perks.

Related Categories

Related Job Pages

More Security Engineer Jobs

Salesloft logo

Manager, Security Engineering – Operations

Salesloft

Take the right actions to close every deal with the only revenue orchestration platform built around the seller workflow

Full TimeRemoteTeam 501-1,000Since 2011H1B Sponsor

• Manage a hybrid team of analysts and engineers • Oversee the vulnerability management lifecycle • Ensure Security Engineering builds necessary preventive/detective controls • Drive the 'Automation and AI' mindset in the team • Serve as the escalation point for incidents • Partner with Engineering and Infrastructure to integrate security • Translate technical projects and operational risks into business context

United States
$123K - $175K / year
Psychiatry UK logo

Security Engineer

Psychiatry UK

Working to help solve the mental health crisis.

Full TimeRemoteTeam 51-200Since 2012H1B No Sponsor

• Implement and manage security solutions using Microsoft security tools and platforms • Monitor security alerts and respond to incidents in a timely manner • Conduct vulnerability assessments and coordinate remediation efforts • Design and enforce identity and access management (IAM) policies • Secure cloud environments, including Azure resources and hybrid infrastructure • Develop and maintain security documentation, policies, and procedures • Collaborate with cross-functional teams to integrate security into system design • Ensure compliance with regulatory and organizational security requirements • Perform risk assessments and recommend mitigation strategies • Stay current with emerging threats, technologies, and security best practices

United Kingdom
£50K / year
Job Closed

Security Automation Engineer

BreachLock

A fast-growing cybersecurity company focused on delivering high-quality offensive security solutions.

Role Description We are currently hiring for our Engineering team based out of our Hyderabad Offshore Development Center (ODC). - Thorough knowledge of penetration testing on a variety of systems, such as web applications, networks, mobile apps, IoT devices, and APIs including the services layer segments with REST/SOAP/GraphQL APIs, ESB, Middleware, or other channels to identify and exploit vulnerabilities. - Strong understanding of cloud security for environments such as AWS, Azure, GCP, and others. - Capable of researching and staying updated on current security vulnerabilities in order to create proof-of-concept (PoC) or scripts for automated detection. Proficient in proactively addressing emerging threats through continuous monitoring and research. - Develop and maintain tools, scripts, and methodologies to enhance the efficiency and effectiveness of penetration testing activities. - Develop Python-based applications, tools, and scripts according to specifications. - Collaborate with the team to define project requirements and deliver high-quality solutions. - Write clean, efficient, and maintainable code following best practices. - Debug and troubleshoot issues to ensure the performance and reliability of applications. - Work with databases and data processing frameworks to store and manipulate data effectively. - Stay updated on Python libraries, frameworks, and best practices to continuously improve development processes. Qualifications - Proven experience in penetration testing, ethical hacking, and vulnerability assessment. - In-depth knowledge of common security frameworks, standards, and best practices (NIST, OWASP, etc.). - Strong understanding of network protocols, systems architecture, and web application security. - Thorough knowledge of common software vulnerabilities and standards such as OWASP Top 10, SANS Top 25, etc. - Proficiency in using penetration testing tools and frameworks (Metasploit, Burp Suite, Nmap, Wireshark, etc.). - Experience with scripting and programming languages (Python, Bash, PowerShell, JAVA, etc.). - Excellent written and verbal communication skills, including the ability to convey technical concepts to non-technical stakeholders. - Ability to work independently and collaboratively in a team environment. - Strong analytical and problem-solving skills. - Commitment to continuous learning and professional development. Requirements - Opportunity to join a promising Scale-up with accelerated career growth. - Opportunity to join and grow in a rapidly expanding Cybersecurity industry. - Competitive Compensation. - Relocation Benefits. - Healthcare Insurance Benefits. - Company Car Lease Benefits. Benefits - Opportunity to join and grow in a passionate, rapidly expanding industry. - Competitive compensation. - You will be working alongside international experts. - Strong career prospects in an early-stage startup.

India
Indy logo

Head of Security

Indy

Today most-advanced AI-powered DIY accounting software

Full TimeRemoteTeam 201-500Since 2016H1B Sponsor

Role Description Nous recherchons notre Head of Security pour piloter la fonction sécurité d’Indy. Rattaché directement au CTO, tu auras pour mission d’industrialiser la stratégie sécurité, avec un scope large : - Sécurité applicative - Infrastructure - Protection des données - Sensibilisation des équipes Ce n’est pas un rôle de gouvernance. On cherche quelqu’un qui code. Tu interviendras directement dans la codebase pour renforcer les briques critiques : - Authentification - Gestion des secrets - Chiffrement Tu feras des revues de code sécurité sur les PR sensibles. Tes missions : - Réaliser un audit complet de la posture sécurité d’Indy et en déduire la stratégie sécurité court/moyen/long terme - Contribuer dans la codebase sur les sujets critiques : auth, sessions, chiffrement, gestion des secrets - Intégrer la sécurité dans le cycle de développement (shift-left) : threat modeling, SAST/DAST, security reviews - Mettre en place les outils de détection, monitoring et réponse aux incidents - Reprendre le lead de la guilde sécurité et gérer les incidents de sécurité - Former et sensibiliser les équipes tech et non-tech - Être le référent sécurité auprès du Comex, des clients et des partenaires Voici également notre stack complète : - NodeJS (Express & Fastify) - VueJS - MongoDB - Javascript / Typescript - Python - Heroku - AWS - Github CI Nous avons également développé une librairie de composants basée sur VueJS et storybook. Company Description

France
Job Closed