We help companies take care of their people.
Lead Security Engineer
Location
United States
Posted
61 days ago
Salary
$190K - $230K / year
Seniority
Senior
Job Description
Lead Security Engineer
Benepass
• Build, operationalize, and scale the security engineering practices that protect the benefits platform • Work across application security, cloud security, security architecture, supply chain security, detection engineering, and vulnerability management • Partner deeply with the teams building web and mobile applications, backend services, system integrations, card and banking workflows, infrastructure as code, and data platforms • Turn risk reduction into scalable guardrails, automated controls, and clear engineering guidance • Help define secure AI tooling usage, LLM and code-assistant governance, and data protection practices for AI-enabled development workflows • Balance ideal security outcomes with engineering velocity and business priorities
Job Requirements
- 7+ years in security engineering, application security, cloud security, product security, platform security, or closely related technical security roles
- Proven ability to lead broad security engineering initiatives as a senior IC
- Strong working knowledge of secure SDLC practices, secure design review, threat modeling, API security, code scanning, SAST, CI/CD security integrations, security testing, defect management, and vulnerability remediation workflows
- Hands-on experience with AWS-native security patterns and services
- Ability to guide secure system builds involving access control, encryption standards, key and certificate management, vaulting, secrets management, and managed HSM/KMS-backed cryptographic services
- Experience hardening build, test, and deployment workflows through dependency scanning, SBOMs, artifact signing, secret scanning, CI/CD guardrails
- Ability to use frameworks such as NIST CSF 2.0 and OWASP SAMM pragmatically
Benefits
- 95% coverage of medical, dental, and vision
- $250 WFH setup (one time)
- $500/year Learning & Development Benefit
- $150/month cell phone + internet
- $100/month Wellness
- $100/month Co-working and Commuter Benefit
- Flexible PTO
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Lead Contribute to security requirements in designing, developing, and deploying large-scale services and platforms • Conducting security architecture reviews of the application stack, including applications built on cloud and emerging technologies • Design and develop platform-level solutions to promote security-related initiatives and improvements. - Review source code for potential security issues, recommend and implement fixes • Providing specific risk assessment and remediation guidelines for developers and business owners - Belief in automation and tooling as a critical part of the software lifecycle • Document and disseminate security guidelines for common security issues, remediation guidance, and security baselines • Contribute to SOC2 and ISO 27001/27701 audits as needed • Work with developers to provide security guidance • Actively promote improving the security culture and education within the organization • Eager to learn new technologies and solutions • Be curious about how systems work and how they fail, design them to be sustainable in the face of failures
Principal Business Information Security Officer
LastPassLastPass manages your passwords and online life, so you don’t have to.
• Lead the continued evolution of LastPass's risk management framework to ensure it remains repeatable, scalable, and consistently applied • Design and scale the BISO-aligned advisory model, defining engagement patterns, communication flows, and partnership rhythms that embed GRC in business decisions • Provide just-in-time risk advisory for product development, engineering changes, supplier decisions, architecture reviews, and other high-impact initiatives, ensuring risks and tradeoffs are clearly understood • Build strong cross-functional partnerships, serving as a trusted advisor who translates complex technical and business risks into actionable, business-aligned recommendations • Coach GRC Analysts to adopt advisory behaviors, apply the risk framework consistently, and deliver high-quality just-in-time support across their aligned business areas • Partner with Governance and GRC Engineering to integrate risk insights with standards, continuous control monitoring signals, and assurance workflows • Lead technical and executive-level risk discussions through Risk Governance Committees, driving clarity, alignment to risk appetites, and accountable decisions • Produce clear, executive-ready risk narratives, reports, and dashboards that support leadership understanding, prioritization, and decision-making
Senior Developer, Product Security
1PasswordProductive businesses use 1Password to secure employees at scale.
• Work within a small team of developers who are specialists in Rust, Swift, Kotlin and Security Development • Implement new security features for the 1Password iOS and core hybrid applications • Assist in security design efforts or scoping initiatives for new features • Demonstrate leadership in security development • Collaborate with teams across our hybrid core architecture • Mentor junior and new team members • Review code for others to maintain high code quality • Stay informed about the latest industry trends, technologies, and best practices in security development
Telecom Security Risk Consultant
P1 SecuritySecuring Operators and governments critical mobile infrastructure to defend against cybersecurity threats and attacks
• Lead and deliver deep‑dive telecom security risk assessments and security consulting for operators, vendors, and critical infrastructure programs (Security Architecture Reviews, RAN & OSS Risk Assessment, MOCN Risk Assessment, IMS Cloud Risk Assessment, 5G Core Risk Assessment). • Define assessment scope, threat model, and risk methodology; translate technical findings into clear, actionable risk statements and remediation roadmaps. • Perform architecture and design reviews across 2G/3G/4G/5G, IMS, EPC/5GC, RAN/OpenRAN, OSS/BSS, interconnect, roaming, cloud-native telecom platforms (Kubernetes/OpenStack), wireline and other OT and IT infrastructure. • Assess security controls and compliance alignment (e.g., GSMA, 3GPP, NIST/ISO principles) including identity, key management, crypto choices, secure boot, supply chain, and operational security. • Analyze protocol and interface exposure (SS7, Diameter, GTP, SIP/IMS, SIGTRAN, HTTP APIs) and identify abuse cases, misconfigurations, and systemic weaknesses. • Evaluate cloud and platform security for telecom workloads (multi-tenancy, network segmentation, service mesh, IAM, secrets management, CI/CD, container hardening). • Conduct evidence-based testing and validation when required (configuration review, log review, traffic analysis, fuzzing/abuse-case testing) and coordinate with P1 Labs R&D for advanced topics. • Produce high-quality deliverables: executive summaries, technical annexes, risk registers, reports and presentations; ensure consistency and repeatability across engagements. • Support pre-sales and customer workshops: clarify requirements, estimate effort, contribute to proposals, and communicate scope and value. • Mentor team members and contribute to internal knowledge base, assessment playbooks, and reusable tooling.




