Job Closed

This listing is no longer active.

Senior Information Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam ,Since 2009H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

69 days ago

Salary

0

Seniority

Senior

Postgraduate Degree25 yrs expEnglishCloudDNSSplunk

Job Description

Senior Information Security Engineer

Stack Exchange

• Lead Contribute to security requirements in designing, developing, and deploying large-scale services and platforms • Conducting security architecture reviews of the application stack, including applications built on cloud and emerging technologies • Design and develop platform-level solutions to promote security-related initiatives and improvements. - Review source code for potential security issues, recommend and implement fixes • Providing specific risk assessment and remediation guidelines for developers and business owners - Belief in automation and tooling as a critical part of the software lifecycle • Document and disseminate security guidelines for common security issues, remediation guidance, and security baselines • Contribute to SOC2 and ISO 27001/27701 audits as needed • Work with developers to provide security guidance • Actively promote improving the security culture and education within the organization • Eager to learn new technologies and solutions • Be curious about how systems work and how they fail, design them to be sustainable in the face of failures

Job Requirements

  • 25+ years of experience in web application security, secure application design and architecture, threat modeling, secure coding, and cryptography
  • Strong desire to secure systems, define and improve processes.
  • Familiarity with: Containers, Cloud, Servers, Networking, DNS, and PaaS & SaaS
  • Deep technical understanding of the OWASP Top 10
  • Experience with Splunk or similar SIEM
  • Experience with Nexpose or similar vulnerability scanning tools
  • Experience integrating security tools to work as an ecosystem
  • Solid experience in threat modeling and identification techniques
  • Ability to work with developers to resolve security issues
  • Experience in code reviews, vulnerability detection, and root cause analysis

Benefits

  • Competitive Base Salary
  • Generous paid vacation
  • Generous parental leave (16 weeks at 100% pay), family care leave, and unlimited sick days
  • Industry-leading health benefits that are applicable per country of residence for all our full-time employees
  • Company-paid Life Insurance
  • Home Internet stipend
  • Professional allocation for your growth and development
  • One-time allowance to assist with your home office setup
  • Company-paid access to Calm, Bravely, LinkedIn Learning, MyAcademy and Overdrive

Related Categories

Related Job Pages

More Security Engineer Jobs

LastPass logo

Principal Business Information Security Officer

LastPass

LastPass manages your passwords and online life, so you don’t have to.

Full TimeRemoteTeam 501-1,000Since 2008H1B No Sponsor

• Lead the continued evolution of LastPass's risk management framework to ensure it remains repeatable, scalable, and consistently applied • Design and scale the BISO-aligned advisory model, defining engagement patterns, communication flows, and partnership rhythms that embed GRC in business decisions • Provide just-in-time risk advisory for product development, engineering changes, supplier decisions, architecture reviews, and other high-impact initiatives, ensuring risks and tradeoffs are clearly understood • Build strong cross-functional partnerships, serving as a trusted advisor who translates complex technical and business risks into actionable, business-aligned recommendations • Coach GRC Analysts to adopt advisory behaviors, apply the risk framework consistently, and deliver high-quality just-in-time support across their aligned business areas • Partner with Governance and GRC Engineering to integrate risk insights with standards, continuous control monitoring signals, and assurance workflows • Lead technical and executive-level risk discussions through Risk Governance Committees, driving clarity, alignment to risk appetites, and accountable decisions • Produce clear, executive-ready risk narratives, reports, and dashboards that support leadership understanding, prioritization, and decision-making

Canada
Job Closed
1Password logo

Senior Developer, Product Security

1Password

Productive businesses use 1Password to secure employees at scale.

Full TimeRemoteTeam 501-1,000Since 2009H1B Sponsor

• Work within a small team of developers who are specialists in Rust, Swift, Kotlin and Security Development • Implement new security features for the 1Password iOS and core hybrid applications • Assist in security design efforts or scoping initiatives for new features • Demonstrate leadership in security development • Collaborate with teams across our hybrid core architecture • Mentor junior and new team members • Review code for others to maintain high code quality • Stay informed about the latest industry trends, technologies, and best practices in security development

California
$153K - $214K / year
P1 Security logo

Telecom Security Risk Consultant

P1 Security

Securing Operators and governments critical mobile infrastructure to defend against cybersecurity threats and attacks

ContractRemoteTeam 11-50Since 2011H1B No Sponsor

• Lead and deliver deep‑dive telecom security risk assessments and security consulting for operators, vendors, and critical infrastructure programs (Security Architecture Reviews, RAN & OSS Risk Assessment, MOCN Risk Assessment, IMS Cloud Risk Assessment, 5G Core Risk Assessment). • Define assessment scope, threat model, and risk methodology; translate technical findings into clear, actionable risk statements and remediation roadmaps. • Perform architecture and design reviews across 2G/3G/4G/5G, IMS, EPC/5GC, RAN/OpenRAN, OSS/BSS, interconnect, roaming, cloud-native telecom platforms (Kubernetes/OpenStack), wireline and other OT and IT infrastructure. • Assess security controls and compliance alignment (e.g., GSMA, 3GPP, NIST/ISO principles) including identity, key management, crypto choices, secure boot, supply chain, and operational security. • Analyze protocol and interface exposure (SS7, Diameter, GTP, SIP/IMS, SIGTRAN, HTTP APIs) and identify abuse cases, misconfigurations, and systemic weaknesses. • Evaluate cloud and platform security for telecom workloads (multi-tenancy, network segmentation, service mesh, IAM, secrets management, CI/CD, container hardening). • Conduct evidence-based testing and validation when required (configuration review, log review, traffic analysis, fuzzing/abuse-case testing) and coordinate with P1 Labs R&D for advanced topics. • Produce high-quality deliverables: executive summaries, technical annexes, risk registers, reports and presentations; ensure consistency and repeatability across engagements. • Support pre-sales and customer workshops: clarify requirements, estimate effort, contribute to proposals, and communicate scope and value. • Mentor team members and contribute to internal knowledge base, assessment playbooks, and reusable tooling.

France
Nagarro logo

Associate Principal Engineer, Cloud Security

Nagarro

Nagarro (Frankfurt: NA9) is a leader in digital product engineering and drives technology-led business breakthroughs.

Full TimeRemoteTeam 10,001+Since 1996H1B Sponsor

• Develop and maintain enterprise level security architecture, reference models, and security patterns. • Conduct threat modeling (using STRIDE, DREAD, LINDDUN, or similar methodologies) for applications, APIs, and infrastructure. • Review high level and low level solution designs for security gaps and recommend mitigations. • Define secure coding guidelines and assist development teams in secure implementation Cryptography & Hardware Security Module (HSM). • Manage and operate HSMs (Thales, nCipher, Azure Key Vault Managed HSM, AWS CloudHSM, etc.). • Oversee lifecycle operations: key generation, rotation, storage, distribution, and decommissioning - Implement and enforce cryptographic standards (AES 256, RSA 2048/4096, ECC, TLS 1.2/1.3, etc.). • Integrate HSMs into application workflows and enterprise systems Compliance & Security Validation. • Validate third party and internal software integrations for compliance (ISO 27001, PCI DSS, SOC 2, local regulatory standards). • Perform architectural risk assessments and oversee secure onboarding of vendors and SaaS platforms. • Ensure alignment of solutions with Zero Trust principles and enterprise security policies Cloud & Infrastructure Security. • Architect secure solutions in cloud environments (Azure, AWS, GCP) - Define IAM, network segmentation, encryption, and logging strategies. • Evaluate and enhance container and Kubernetes security Incident Response & Governance. • Contribute to incident response planning and root cause analysis . • Maintain security documentation, roadmaps, and architectural standards. • Collaborate closely with DevOps, development, networking, and governance.

Sri Lanka
Job Closed