Twilio logo
Twilio

Twilio is a Platform-as-a-Service (PaaS) company established in 2007. In support of a flexible workplace, Twilio has previously posted freelance, flexible sched

Staff Enterprise Security Engineer

Location

Ireland + 1 moreAll locations: Ireland | United Kingdom

Posted

13 days ago

Salary

0

Seniority

Senior

Job Description

Staff Enterprise Security Engineer

Twilio

Title: Staff Enterprise Security Engineer, AI Security Location: - Ireland, UK Category: Security Remote Job Description: Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! See yourself at Twilio Join the team as Twilio’s next Staff Enterprise Security Engineer (AI Security) About the job As a Staff Enterprise Security Engineer, you will be a technical leader within the EntSec team, responsible for the foundational security posture of our organization. You will serve as an SME on the technical strategy and engineering execution for securing the AI ecosystem in our Enterprise, moving beyond policy into building the foundational "decision infrastructure" and technical guardrails that allow the enterprise to innovate with AI at scale. You will also guide strategic direction and collaboration across enterprise security domains. You will need a background in security engineering and the cross-functional influence necessary to solve ambiguous, large-scale problems. Leveraging expertise in security assessments, threat modeling, identity and access control principles, and data protection, you will architect and build preventative guardrails and mitigate new risks introduced by first and third-party AI agents in our Enterprise. Responsibilities In this role, you’ll: - Design and implement secure reference architectures for Enterprise AI platforms that secures every Twilion’s engagement with them, ensuring data integrity, regulatory compliance, and resilience against evolving AI threats. - Establish a definitive framework for AI vetting, driving the cultural and policy shifts needed to institutionalize this strategic mindset across the organization. - Collaborate with cross functional partners to develop and set the long term roadmap for agentic AI identity and posture management, ensuring cohesive strategies for reducing risk from agentic AI use. - Maintain and improve our enterprise security posture through high-quality code (Python, Go, or similar) and automated infrastructure management via IAC. - Act as a technical mentor to junior engineers and a strategic advisor to leadership on the evolving AI landscape. Qualifications Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn't followed a traditional path, don't let that stop you from considering Twilio. We are always looking for people who will bring something new to the table! Required: - 7+ years of experience in security engineering or infrastructure security - 2+ years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment. - Expertise in cloud security (AWS, GCP) and container security (Kubernetes). - Proven track record of designing and deploying complex security systems at scale. - Strong proficiency in programming languages such as Python, Go, or Java. Desired: - Experience in building, deploying and reviewing automation for complex security workflows, including use of both AI-driven and traditional automation tools. - Excellent communication skills with the ability to explain complex AI security risks to non-technical stakeholders. Location This role will be remote, and based in Ireland or the UK Travel We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings. What We Offer Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location. Twilio thinks big. Do you? We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That's why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts. So, if you're ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn't what you're looking for, please consider other open positions. Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 51-200H1B Sponsor

Title: Information System Security Officer (ISSO) Location: Remote, MD Job Description: Job Type Full-time Description Position Details: Job Title: Information System Security Officer (ISSO) Job Type: Full-time Location: Remote, MD - occasional in-person in the DC Metro Area as necessary Dynanet Corporation Overview: Dynanet started with a focus on IT infrastructure and operations, helping organizations enhance their networks and overcome the limitations of 1990s technology. From strengthening communication channels to introducing innovative ways to collaborate and share information, Dynanet played a crucial role in shaping the early stages of digital transformation. The company’s efforts helped organizations build the very fabric of connectivity that now powers our modern world. Over the last three decades, Dynanet has grown into a trusted partner for organizations looking to innovate boldly and transform seamlessly. While technology continues to evolve and unlock new opportunities, for nearly 30 years, Dynanet remains committed to delivering cutting-edge solutions that drive lasting change for its customers. Through agility, foresight, and an unwavering dedication to excellence, Dynanet continues to empower organizations to thrive in a rapidly changing digital landscape. Our story is more than just a story of technology – it’s a story of vision, growth, and transformation that has shaped the past and continues to pave the way for the future. About the Role: Serve as a hands-on Information System Security Officer (ISSO) supporting the modernization and accreditation of applications across the Agency's evolving cloud and on-prem ecosystem. This role is focused on technical execution, not policy-only oversight. The ISSO will drive SSP creation, automated ATO workflows, continuous monitoring integration, secure baseline enforcement for the Landing Zone Architecture (LZA), and the adoption of an OTEL-first monitoring and logging platform. By enabling evidence automation, compliance-as-code, and integrated security telemetry, the ISSO will strengthen application readiness, accelerate ATO timelines, and ensure continuous compliance across hybrid environments. - Leads hands-on SSP creation, ATO automation, and continuous monitoring integration. - Defines and implements secure baselines, compliance-as-code, and OTEL-driven monitoring patterns. Roles & Responsibilities: - Create full Security System Plans (SSPs) for new applications, including system boundaries, control implementation statements, architecture mapping, and inheritance models. Support, update, and maintain SSPs for existing applications through the full ATO lifecycle. - Develop and implement automated ATO pipelines, including evidence generation, validation tasks, and CI/CD gating aligned to RMF requirements. - Integrate continuous monitoring strategies, telemetry sources, alerting thresholds, and control-health scoring. - Automate evidence collection through scripts, scheduling logic, secure repositories, and structured control mappings. - Define, maintain, and enforce secure baselines for the Landing Zone Architecture (LZA) across cloud and on-prem environments. - Implement and scale compliance-as-code, translating NIST and agency controls into machine-testable rules and automated evaluations. - Establish and manage an OTEL-first platform for organization-wide logging, metrics, tracing, APM, and compliance telemetry. - Enable OTEL-driven continuous compliance through real-time signals tied to control effectiveness and evidence requirements. - Collaborate with engineering, cloud, security, and application teams to provide hands-on control remediation, configuration updates, and automation support. - Partner with assessors and AOs to ensure high-quality artifacts, timely responses, and successful accreditation reviews. Required Professional Skills: - 5–10+ years of experience in ISSO, security engineering, or RMF/FISMA compliance roles (hands on technical focus). - Strong experience creating SSPs, implementing controls, and driving ATOs for cloud or hybrid systems. - Hands on background with AWS, Azure, and on prem environments, including inheritance models and shared-responsibility controls. - Experience implementing continuous monitoring, SIEM integrations, telemetry pipelines, and automated control health reporting. - Proficiency with scripting (Python, PowerShell, Bash) to automate evidence collection, configuration checks, and compliance tasks. - Experience with IaC tools (Terraform, Bicep, CloudFormation) and building automated compliance checks within CI/CD. - Working knowledge of cloud networking, identity (Entra IAM/IAM), endpoint telemetry, containerized environments, and security baseline enforcement. - Strong understanding of NIST RMF, FISMA, FedRAMP, vulnerability management, and POA&M remediation processes. Preferred Professional Skills: - Experience implementing OpenTelemetry collectors, instrumentation, and pipelines for traces, logs, and metrics. - Experience with compliance as code frameworks (OPA/Conftest, Regula, or custom rulesets). - Security certifications such as CISSP, CAP, Security+, CCSK, CCSP, or cloud security certifications. - Experience automating ATO processes, evidence generation, and continuous monitoring dashboards. - Background supporting Zero Trust principles, secure baseline patterns, and telemetry driven security operations. Dynanet Team Requirements and Expectations: - Possess Strong written and verbal communication skills. - Highly organized with the ability to prioritize, balance, and effectively advance multiple competing priorities in a high-volume, fast-paced environment. - Ability to interact in a professional and collaborative manner with fellow Dynanet Teammates and the clients, and business partners that we work with. - Ability and desire to challenge and educate yourself to support and advance IT services delivery in the Federal agencies we serve. - Excellent judgment and creative problem-solving skills. - Respond to team member and client requests via email, MS teams, or other communication means during core business hours. - Active listening skills to understand clients' needs, and collaboration skills to work with other developers and designers. Employee Benefits Overview: · Industry Competitive Compensation · Medical and Dental Insurance · Paid Time Off/Holidays · 401(k) Retirement Plans with Matching · Remote Work* · Paid Training · Employee Referral Program · Employee Development Program

Maryland

Senior Cyber Security Engineer

ASRC Federal

ASRC Federal, a wholly owned subsidiary of Alaska’s largest Alaskan-owned and operated company, the Arctic Slope Regional Corporation (ASRC), is a leading provider of mission-cri

Role Description ASRC Federal is looking for an experienced Senior Cyber Security Analyst (Incident Response & Threat Operations) to join our team in a government contracting (GovCon) environment. This is a full-time remote position with occasional on-site support (Beltsville, MD or Reston, VA). The Senior Cyber Security Analyst is responsible for advanced incident response, threat detection, and Tier II/Tier III Security Operations Center (SOC) support within an enterprise environment. This role focuses on: - Investigating security events - Identifying malicious activity - Responding to cyber incidents - Improving detection capabilities across the organization The ideal candidate has strong hands-on experience in: - Intrusion detection - Threat hunting - Phishing investigations - Endpoint and network analysis - Operational cybersecurity support Key Responsibilities - Serve as a Tier II/Tier III escalation point for complex SOC investigations and cybersecurity incidents. - Investigate and respond to security alerts involving phishing, malicious URLs, malware activity, credential compromise, suspicious authentication activity, and endpoint threats. - Conduct proactive threat hunting activities using SIEM, EDR/XDR, firewall, DNS, email security, and network telemetry data. - Monitor security tools, logs, alerts, and reports to identify suspicious or malicious activity and coordinate appropriate response and remediation actions. - Identify, analyze, and mitigate cybersecurity threats, vulnerabilities, and system weaknesses to reduce organizational risk exposure. - Analyze security events and logs to identify indicators of compromise, attack patterns, and unauthorized activity. - Perform incident response activities including triage, containment, eradication, recovery, and root cause analysis for security incidents. - Support and enhance enterprise security monitoring and detection capabilities across SIEM, EDR/XDR, IDS/IPS, email security, and firewall platforms. - Develop and tune detection rules, alerting logic, and threat detection use cases to improve SOC effectiveness and reduce false positives. - Create scripts and automation solutions using PowerShell, Python, or similar tools to streamline investigations and response activities. - Collaborate with infrastructure, networking, cloud, and endpoint teams during investigations and remediation efforts. - Evaluate emerging threats, vulnerabilities, attack techniques, and security technologies to strengthen enterprise detection and response capabilities. - Provide technical guidance and support for escalated cybersecurity investigations and operational issues. - Document investigative findings, incident timelines, and remediation recommendations. - Participate in on-call incident response support as required. Qualifications - Must be a U.S. Citizen or Permanent Resident (Green Card Holder). - Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent professional experience. - 7+ years of hands-on experience in cybersecurity operations, incident response, or SOC environments. - Experience supporting Tier II/Tier III SOC investigations and incident handling. - Strong experience with: - SIEM platforms - EDR/XDR technologies - IDS/IPS systems - Email security platforms - Firewall and network security tools - Experience investigating phishing attacks, URL click alerts, malware infections, and account compromise activity. - Strong understanding of TCP/IP, DNS, HTTP/S, VPNs, Active Directory, and enterprise networking concepts. - Experience supporting Windows and Linux environments. - Proficiency in PowerShell, Python, or similar scripting languages. - Strong analytical, troubleshooting, and communication skills. - Ability to work independently in a fast-paced operational environment. Preferred Qualifications - Certifications such as CISSP, GCIH, GCIA, CEH, Security+, or equivalent (at least one is required). - Experience with MITRE ATT&CK, threat intelligence platforms, or SOAR technologies. - Familiarity with cloud security monitoring and enterprise-scale security operations. Benefits - Competitive pay and benefits packages. - Health care, dental, vision, life insurance. - 401(k) plan. - Education assistance. - Paid time off including PTO, holidays, and any other paid leave required by law. Additional Information - Reports to: Cybersecurity Governance, Risk & Compliance Leadership. - Travel: None. - Clearance: Secret clearance preferred but not required; may be required based on project needs. EEO Statement ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

United States
$135K - $170K / year

Role Description We are seeking a Senior Cryptographer with deep experience in modern cryptographic design, PQC evaluation, and secure-system implementation. The ideal candidate has supported or participated in national-security cryptographic programs (NSA, CYBERCOM, CIA DS&T, MITRE, APL, Sandia, Los Alamos, NIST). Work Locations in Virginia / Maryland / DC / Remote (with CONUS travel). You will be a senior technical advisor working alongside Vibrint's cleared engineering teams and QED's cryptography leadership, advising federal customers and evaluating cryptography modernization roadmaps. Key Responsibilities - Conduct cryptographic audits for CNSA 2.0 + NIST PQC compliance - Evaluate algorithm implementations (Kyber, Dilithium, SPHINCS+, McEliece) - Assess hardware crypto modules (HSMs, TPM, FPGA, ASIC security blocks) - Develop crypto migration recommendations for federal clients - Review Type-1 / high-assurance system architectures - Support prototyping of QED-Vibrint proprietary PQC hardware modules (QRNG + PQC-enabled chipset) - Engage with NIST/IETF/PQC working groups (optional but preferred) - Contribute to customer briefings, white papers, and cryptographic risk assessments Required Experience - Lattice-based crypto (Kyber, Dilithium) - Code-based (Classic McEliece) - Hash-based (SPHINCS+) - Hardware crypto modules, HSM, FPGA, chip-level key management Benefits - Competitive salary - Annual merit-based salary increases and discretionary bonus program - 401(k) plan with a company contribution - 11 paid federal holidays - 160 hours of paid time off - Medical, dental, vision, life and short- & long-term disability insurance - Employee assistance program - Generous professional development allowance Equal Opportunity Employer All applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, citizenship, family structure, marital status, disability, veteran or military status, or any other characteristic protected by law in all phases of the employment process and in compliance with applicable federal, state, and local laws and regulations. An equal opportunity employer/disability/vet. Please apply for immediate consideration.

United States

Role Description A fantastic opportunity for a CyberSecurity Operations Engineer to join a fast-growing, technology-led security company delivering managed security and managed IT services to a global client base. This role sits firmly within the Operations and Service Delivery function, working closely with clients post-sale to support, implement and improve their security and IT environments. This is a hands-on, client-facing operational role focused on technical support, troubleshooting, account ownership and project delivery. Location: Fully remote, anywhere in the US Salary: $80,000 – $120,000 per annum (lower end for a recent Graduate) Qualifications - Outstanding academic background with a minimum GPA of 3.6 - Bachelor’s degree in Computer Science, Cyber Security, Engineering, Mathematics or Physics - Degree obtained from a highly ranked academic institution (typically Top 100 US universities or equivalent globally) - Hands-on technical experience through internships, commercial roles, homelabs, open-source projects or real-world environments - Strong technical understanding across operating systems, networking, security protocols, scripting and cloud infrastructure - Excellent problem-solving skills with a practical, solutions-focused mindset - Strong communication skills with the ability to explain technical issues clearly to non-technical stakeholders - A proactive, self-motivated individual who thrives in a fast-paced, high-responsibility environment - Curiosity, ambition and a genuine passion for technology and continuous learning - Exposure to SOC or offensive security is beneficial but not required Requirements - Deliver 1st and 2nd line technical support across security and IT environments - Take ownership of client issues from detection through to resolution - Act as a key technical point of contact for clients, managing ongoing relationships - Conduct regular client catch-ups and service reviews, discussing security and IT challenges - Guide clients through security and IT roadmaps, advising on best practice and improvements - Troubleshoot and support security software, agents and bespoke security controls - Triage and respond to security incidents raised by internal monitoring teams, advising on remediation - Design, implement and manage IT and cloud infrastructure across SaaS, PaaS and IaaS environments - Support device provisioning, hardening, monitoring and IT asset procurement - Assist with firewall management, compliance activities, reporting and documentation - Support pre-sales activity including demos and proof-of-concepts when required - Deliver and manage ad hoc security and IT projects involving multiple internal and external stakeholders - Support and mentor more junior team members as you progress within the team Benefits - A highly varied operations role spanning security, IT support, projects and client delivery - Rapid technical development through real-world exposure to security and IT challenges - Clear progression into senior operations, account ownership or specialist technical roles - Structured training and support towards professional certifications - Opportunities to present internally and externally as your expertise develops - A collaborative, high-calibre team with strong technical standards - Fully remote working anywhere in the US Applications If you would like to apply for this CyberSecurity Operations Engineer role, please submit an up-to-date CV via the relevant link. For your application to be progressed, academic results must be clearly listed, including GPA and university attended. Please note you will hear back within 5 working days if your application is being progressed. Due to an extremely high level of applications for this specific role we are unable to provide individual feedback. We’re committed to creating an inclusive and accessible recruitment process. If you require reasonable adjustments for your application or during the review process, please highlight this by separately emailing applications@redtech-recruit.com.

United States
$80K - $120K / year