Job Closed
This listing is no longer active.
GoDaddy is a web services platform that helps individuals and businesses worldwide start, grow, and manage their online presence. GoDaddy employs team members a
Product Security Engineer
Location
India
Posted
11 days ago
Salary
0
Seniority
Mid Level
Job Description
Product Security Engineer
GoDaddy
Role Description We are seeking a skilled and motivated Application Security Engineer to join our Product Security team. In this role, you will play a critical part in strengthening our application security posture across multiple products and platforms. The ideal candidate will support and lead key security initiatives, including: - Threat modeling - Secure design validation - DevSecOps integration You will contribute to securing modern architectures across cloud-native and distributed environments, while also helping drive AI-driven innovation in security automation and analysis. This role offers an opportunity to independently lead security efforts, influence engineering practices, and build scalable security solutions that protect against evolving threats! What you'll get to do: - Drive threat modeling sessions across applications and services, identifying risks early and ensuring secure-by-design principles are embedded throughout the SDLC - Evaluate system architectures and cloud environments (primarily AWS) to ensure alignment with security best practices and organizational standards - Build, enhance, and optimize security tools and automation pipelines to scale security across development workflows - Leverage AI/ML and agentic approaches to improve threat analysis, automation, and overall security operations efficiency - Partner with engineering, DevOps, cloud, and platform teams to embed security into design, development, and deployment processes - Independently own and drive application security initiatives, delivering measurable improvements in secure development practices - Develop and refine security standards, playbooks, and best practices to continuously improve the organization’s security posture - Stay up to date with emerging threats, technologies, and trends, while sharing knowledge and mentoring team members where applicable Qualifications - 4+ years of experience across application security domains, including a combination of threat modeling, architecture reviews, and security tooling development / DevSecOps practices - Proven expertise in architecture review and cloud security - Ability to work with and apply AI/ML concepts or AI agents to security use cases, including automation and workflow optimization Requirements - Strong background in secure code review (manual and automated) across modern programming languages Benefits - Paid time off - Retirement savings (e.g., 401k, pension schemes) - Bonus/incentive eligibility - Equity grants - Participation in our employee stock purchase plan - Competitive health benefits - Family-friendly benefits including parental leave
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Project Manager - Cyber Security
Huntington National BankSine 1866, Huntington National Bank has served midwestern communities with banking and financial services for consumers and businesses of all sizes. The regiona
Title: Senior Project Manager- Cyber Security Locations: Dallas, TX Columbus, OH Work Type: Hybrid Job ID: R0072446 Job Description: We are seeking a Senior Project Manager with a strong cybersecurity background to lead the AI‑enabled modernization of core security capabilities. This role is central to advancing the organization's Secure Software The ideal candidate has a proven track record of delivering large‑scale, cross‑functional cybersecurity initiatives in highly regulated environments. They will translate cybersecurity strategy into clear, executable delivery plans, drive disciplined execution across multiple workstreams, and deliver measurable security and process‑maturity improvements through the practical application of emerging technologies and AI. Key Responsibilities - Lead complex, enterprise‑wide AI Cybersecurity Projects with significant cross‑functional dependencies, ensuring disciplined execution across teams, platforms, and delivery models. - Translate cybersecurity strategy, AI cybersecurity roadmaps, regulatory drivers, and risk priorities into clear, executable project plans aligned to business objectives, regulatory expectations, and delivery commitments. AI‑Driven Security Transformation - Lead AI‑enabled security modernization initiatives, advancing Secure SDLC, Vulnerability Management, and Configuration Management and Resiliency capabilities through automation and data‑driven solutions. - Partner with architecture, data, and analytics teams to integrate AI capabilities responsibly, ensuring adherence to governance, model‑risk management, and control requirements. - Drive rigorous risk and issue management, including proactive identification, analysis, escalation, and mitigation of delivery, dependency, control, and model‑risk concerns-ensuring timely resolution and executive visibility. - Communicate effectively with senior leadership, providing clear, concise, and executive‑ready status updates, risk summaries, decision points, and recommended actions to support informed governance and timely decision‑making. - Establish and maintain high standards for documentation, ensuring program artifacts, plans, RAID logs, decision records, and governance materials are accurate, detailed, audit‑ready, and consistently maintained. - Partner closely with Cybersecurity, Technology, Risk, Compliance, and Audit stakeholders to ensure coordinated execution, effective governance, and alignment with regulatory, control, and model‑risk expectations. Basic Qualifications: - Bachelor's degree in information technology, Computer Science, Cybersecurity, or a related field. - 7+ years experience leading projects within technology and cybersecurity organizations, preferably in financial services or similarly regulated enterprises. - 7+ years of experience delivering large‑scale cybersecurity and/or enterprise technology projects or programs in regulated environments. Preferred Qualifications: - Exceptional executive communication, documentation, and stakeholder leadership skills, with demonstrated ability to produce clear, detailed, and audit‑ready artifacts. - Strong understanding of core project management disciplines, with experience applying Agile frameworks and structured delivery practices. - Demonstrated experience delivering cybersecurity initiatives in large‑scale enterprise environments, with direct accountability for scope, schedule, dependencies, and outcomes. - Proven hands‑on delivery leadership across complex programs, including managing cross‑team dependencies, driving issue resolution, and sustaining delivery momentum under competing priorities. - Experience in Banking or Financial Services - Experience utilizing a variety portfolio project management tool and creating and tracking project schedules in MS Excel or MS Project - Strong understanding of project lifecycle methodologies (e.g., Waterfall, Iterative, Agile/Scrum) and project management processes and standards - Strong aptitude in both business and technology - Excellent verbal and written communications skills; ability to explain project risks and issues, and IT related concepts clearly and concisely to multiple layers of peers and leadership - High motivated with strong organizational, analytical, decision making, and problem solving skills - Ability to work in a fast-paced environment and to handle multiple priorities and effectively prioritize them - Ability to provide strong program and project leadership during periods of uncertainty, ambiguity, and change - Willingness and drive to learn and understand detailed software solutions - High level of professionalism and confidence with the ability to build credibility with leadership, team members, and business partners and establish effective working relationships - Ability to initiate and facilitate change, whether indicated by corporate needs, market or regulatory requirements - Experience leading large, cross-functional information technology programs and projects Exempt Status: (Yes = not eligible for overtime pay) (No = eligible for overtime pay) Yes Workplace Type: Office Our Approach to Office Workplace Type Certain positions outside our branch network may be eligible for a flexible work arrangement. We're combining the best of both worlds: in-office and work from home. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. Remote roles will also have the opportunity to come together in our offices for moments that matter. Specific work arrangements will be provided by the hiring team.
Title: Staff Enterprise Security Engineer, AI Security Location: - Ireland, UK Category: Security Remote Job Description: Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! See yourself at Twilio Join the team as Twilio’s next Staff Enterprise Security Engineer (AI Security) About the job As a Staff Enterprise Security Engineer, you will be a technical leader within the EntSec team, responsible for the foundational security posture of our organization. You will serve as an SME on the technical strategy and engineering execution for securing the AI ecosystem in our Enterprise, moving beyond policy into building the foundational "decision infrastructure" and technical guardrails that allow the enterprise to innovate with AI at scale. You will also guide strategic direction and collaboration across enterprise security domains. You will need a background in security engineering and the cross-functional influence necessary to solve ambiguous, large-scale problems. Leveraging expertise in security assessments, threat modeling, identity and access control principles, and data protection, you will architect and build preventative guardrails and mitigate new risks introduced by first and third-party AI agents in our Enterprise. Responsibilities In this role, you’ll: - Design and implement secure reference architectures for Enterprise AI platforms that secures every Twilion’s engagement with them, ensuring data integrity, regulatory compliance, and resilience against evolving AI threats. - Establish a definitive framework for AI vetting, driving the cultural and policy shifts needed to institutionalize this strategic mindset across the organization. - Collaborate with cross functional partners to develop and set the long term roadmap for agentic AI identity and posture management, ensuring cohesive strategies for reducing risk from agentic AI use. - Maintain and improve our enterprise security posture through high-quality code (Python, Go, or similar) and automated infrastructure management via IAC. - Act as a technical mentor to junior engineers and a strategic advisor to leadership on the evolving AI landscape. Qualifications Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn't followed a traditional path, don't let that stop you from considering Twilio. We are always looking for people who will bring something new to the table! Required: - 7+ years of experience in security engineering or infrastructure security - 2+ years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment. - Expertise in cloud security (AWS, GCP) and container security (Kubernetes). - Proven track record of designing and deploying complex security systems at scale. - Strong proficiency in programming languages such as Python, Go, or Java. Desired: - Experience in building, deploying and reviewing automation for complex security workflows, including use of both AI-driven and traditional automation tools. - Excellent communication skills with the ability to explain complex AI security risks to non-technical stakeholders. Location This role will be remote, and based in Ireland or the UK Travel We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings. What We Offer Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location. Twilio thinks big. Do you? We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That's why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts. So, if you're ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn't what you're looking for, please consider other open positions. Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.
Title: Information System Security Officer (ISSO) Location: Remote, MD Job Description: Job Type Full-time Description Position Details: Job Title: Information System Security Officer (ISSO) Job Type: Full-time Location: Remote, MD - occasional in-person in the DC Metro Area as necessary Dynanet Corporation Overview: Dynanet started with a focus on IT infrastructure and operations, helping organizations enhance their networks and overcome the limitations of 1990s technology. From strengthening communication channels to introducing innovative ways to collaborate and share information, Dynanet played a crucial role in shaping the early stages of digital transformation. The company’s efforts helped organizations build the very fabric of connectivity that now powers our modern world. Over the last three decades, Dynanet has grown into a trusted partner for organizations looking to innovate boldly and transform seamlessly. While technology continues to evolve and unlock new opportunities, for nearly 30 years, Dynanet remains committed to delivering cutting-edge solutions that drive lasting change for its customers. Through agility, foresight, and an unwavering dedication to excellence, Dynanet continues to empower organizations to thrive in a rapidly changing digital landscape. Our story is more than just a story of technology – it’s a story of vision, growth, and transformation that has shaped the past and continues to pave the way for the future. About the Role: Serve as a hands-on Information System Security Officer (ISSO) supporting the modernization and accreditation of applications across the Agency's evolving cloud and on-prem ecosystem. This role is focused on technical execution, not policy-only oversight. The ISSO will drive SSP creation, automated ATO workflows, continuous monitoring integration, secure baseline enforcement for the Landing Zone Architecture (LZA), and the adoption of an OTEL-first monitoring and logging platform. By enabling evidence automation, compliance-as-code, and integrated security telemetry, the ISSO will strengthen application readiness, accelerate ATO timelines, and ensure continuous compliance across hybrid environments. - Leads hands-on SSP creation, ATO automation, and continuous monitoring integration. - Defines and implements secure baselines, compliance-as-code, and OTEL-driven monitoring patterns. Roles & Responsibilities: - Create full Security System Plans (SSPs) for new applications, including system boundaries, control implementation statements, architecture mapping, and inheritance models. Support, update, and maintain SSPs for existing applications through the full ATO lifecycle. - Develop and implement automated ATO pipelines, including evidence generation, validation tasks, and CI/CD gating aligned to RMF requirements. - Integrate continuous monitoring strategies, telemetry sources, alerting thresholds, and control-health scoring. - Automate evidence collection through scripts, scheduling logic, secure repositories, and structured control mappings. - Define, maintain, and enforce secure baselines for the Landing Zone Architecture (LZA) across cloud and on-prem environments. - Implement and scale compliance-as-code, translating NIST and agency controls into machine-testable rules and automated evaluations. - Establish and manage an OTEL-first platform for organization-wide logging, metrics, tracing, APM, and compliance telemetry. - Enable OTEL-driven continuous compliance through real-time signals tied to control effectiveness and evidence requirements. - Collaborate with engineering, cloud, security, and application teams to provide hands-on control remediation, configuration updates, and automation support. - Partner with assessors and AOs to ensure high-quality artifacts, timely responses, and successful accreditation reviews. Required Professional Skills: - 5–10+ years of experience in ISSO, security engineering, or RMF/FISMA compliance roles (hands on technical focus). - Strong experience creating SSPs, implementing controls, and driving ATOs for cloud or hybrid systems. - Hands on background with AWS, Azure, and on prem environments, including inheritance models and shared-responsibility controls. - Experience implementing continuous monitoring, SIEM integrations, telemetry pipelines, and automated control health reporting. - Proficiency with scripting (Python, PowerShell, Bash) to automate evidence collection, configuration checks, and compliance tasks. - Experience with IaC tools (Terraform, Bicep, CloudFormation) and building automated compliance checks within CI/CD. - Working knowledge of cloud networking, identity (Entra IAM/IAM), endpoint telemetry, containerized environments, and security baseline enforcement. - Strong understanding of NIST RMF, FISMA, FedRAMP, vulnerability management, and POA&M remediation processes. Preferred Professional Skills: - Experience implementing OpenTelemetry collectors, instrumentation, and pipelines for traces, logs, and metrics. - Experience with compliance as code frameworks (OPA/Conftest, Regula, or custom rulesets). - Security certifications such as CISSP, CAP, Security+, CCSK, CCSP, or cloud security certifications. - Experience automating ATO processes, evidence generation, and continuous monitoring dashboards. - Background supporting Zero Trust principles, secure baseline patterns, and telemetry driven security operations. Dynanet Team Requirements and Expectations: - Possess Strong written and verbal communication skills. - Highly organized with the ability to prioritize, balance, and effectively advance multiple competing priorities in a high-volume, fast-paced environment. - Ability to interact in a professional and collaborative manner with fellow Dynanet Teammates and the clients, and business partners that we work with. - Ability and desire to challenge and educate yourself to support and advance IT services delivery in the Federal agencies we serve. - Excellent judgment and creative problem-solving skills. - Respond to team member and client requests via email, MS teams, or other communication means during core business hours. - Active listening skills to understand clients' needs, and collaboration skills to work with other developers and designers. Employee Benefits Overview: · Industry Competitive Compensation · Medical and Dental Insurance · Paid Time Off/Holidays · 401(k) Retirement Plans with Matching · Remote Work* · Paid Training · Employee Referral Program · Employee Development Program
Senior Cyber Security Engineer
ASRC FederalASRC Federal, a wholly owned subsidiary of Alaska’s largest Alaskan-owned and operated company, the Arctic Slope Regional Corporation (ASRC), is a leading provider of mission-cri
Role Description ASRC Federal is looking for an experienced Senior Cyber Security Analyst (Incident Response & Threat Operations) to join our team in a government contracting (GovCon) environment. This is a full-time remote position with occasional on-site support (Beltsville, MD or Reston, VA). The Senior Cyber Security Analyst is responsible for advanced incident response, threat detection, and Tier II/Tier III Security Operations Center (SOC) support within an enterprise environment. This role focuses on: - Investigating security events - Identifying malicious activity - Responding to cyber incidents - Improving detection capabilities across the organization The ideal candidate has strong hands-on experience in: - Intrusion detection - Threat hunting - Phishing investigations - Endpoint and network analysis - Operational cybersecurity support Key Responsibilities - Serve as a Tier II/Tier III escalation point for complex SOC investigations and cybersecurity incidents. - Investigate and respond to security alerts involving phishing, malicious URLs, malware activity, credential compromise, suspicious authentication activity, and endpoint threats. - Conduct proactive threat hunting activities using SIEM, EDR/XDR, firewall, DNS, email security, and network telemetry data. - Monitor security tools, logs, alerts, and reports to identify suspicious or malicious activity and coordinate appropriate response and remediation actions. - Identify, analyze, and mitigate cybersecurity threats, vulnerabilities, and system weaknesses to reduce organizational risk exposure. - Analyze security events and logs to identify indicators of compromise, attack patterns, and unauthorized activity. - Perform incident response activities including triage, containment, eradication, recovery, and root cause analysis for security incidents. - Support and enhance enterprise security monitoring and detection capabilities across SIEM, EDR/XDR, IDS/IPS, email security, and firewall platforms. - Develop and tune detection rules, alerting logic, and threat detection use cases to improve SOC effectiveness and reduce false positives. - Create scripts and automation solutions using PowerShell, Python, or similar tools to streamline investigations and response activities. - Collaborate with infrastructure, networking, cloud, and endpoint teams during investigations and remediation efforts. - Evaluate emerging threats, vulnerabilities, attack techniques, and security technologies to strengthen enterprise detection and response capabilities. - Provide technical guidance and support for escalated cybersecurity investigations and operational issues. - Document investigative findings, incident timelines, and remediation recommendations. - Participate in on-call incident response support as required. Qualifications - Must be a U.S. Citizen or Permanent Resident (Green Card Holder). - Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent professional experience. - 7+ years of hands-on experience in cybersecurity operations, incident response, or SOC environments. - Experience supporting Tier II/Tier III SOC investigations and incident handling. - Strong experience with: - SIEM platforms - EDR/XDR technologies - IDS/IPS systems - Email security platforms - Firewall and network security tools - Experience investigating phishing attacks, URL click alerts, malware infections, and account compromise activity. - Strong understanding of TCP/IP, DNS, HTTP/S, VPNs, Active Directory, and enterprise networking concepts. - Experience supporting Windows and Linux environments. - Proficiency in PowerShell, Python, or similar scripting languages. - Strong analytical, troubleshooting, and communication skills. - Ability to work independently in a fast-paced operational environment. Preferred Qualifications - Certifications such as CISSP, GCIH, GCIA, CEH, Security+, or equivalent (at least one is required). - Experience with MITRE ATT&CK, threat intelligence platforms, or SOAR technologies. - Familiarity with cloud security monitoring and enterprise-scale security operations. Benefits - Competitive pay and benefits packages. - Health care, dental, vision, life insurance. - 401(k) plan. - Education assistance. - Paid time off including PTO, holidays, and any other paid leave required by law. Additional Information - Reports to: Cybersecurity Governance, Risk & Compliance Leadership. - Travel: None. - Clearance: Secret clearance preferred but not required; may be required based on project needs. EEO Statement ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.



