Sift logo
Sift

We’re the leader in Digital Trust & Safety, empowering companies of all sizes to unlock revenue without risk.

Senior Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 201-500Since 2011H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

8 days ago

Salary

$145K - $200K / year

Seniority

Senior

Job Description

Senior Security Engineer

Sift

Role Description The Security Engineering team is responsible for protecting Sift’s products, infrastructure, and data while enabling our engineering organization to ship quickly and safely. As a Senior Security Engineer, you’ll be a key technical contributor and subject-matter expert, working on projects that materially reduce risk and strengthen Sift’s security posture. In this role, you will: - Design, implement, and operate security controls and tooling across Sift’s stack. - Work closely with Engineers, SREs, IT, and Legal/Compliance to secure our systems end-to-end—from application code and CI/CD pipelines to cloud infrastructure and identity. - Help define our standards, mentor other engineers on secure practices, and contribute directly to audits and compliance efforts. What you’ll do: - Design and implement security controls and tooling across Sift’s infrastructure and applications (e.g., IAM policies, network controls, secrets management, endpoint protections, container and workload security). - Embed with product and platform teams to perform security design reviews, threat modeling, and code or configuration reviews for new features and services. - Improve the secure SDLC by integrating AI-powered scanning tools, security scanning (SAST/DAST, dependency and container scanning) into CI/CD, and by developing guardrails, templates, and best practices for engineers. - Own or co-own vulnerability management workflows, from discovery and triage through remediation, including defining SLAs, coordinating with service owners, and tracking closure. - Develop automation (scripts, services, integrations) to detect misconfigurations, anomalous activity, or policy violations, and to reduce manual operational work for the security team. - Participate in security incident response (on-call rotation or escalation), including investigation, containment, root cause analysis, and long-term fixes. - Contribute to security documentation and standards, ensuring we have clear, actionable guidance for engineers on topics like authentication, authorization, data encryption, and key management. - Support audits and assessments (e.g., SOC 2, customer security questionnaires) by providing technical details and evidence of control design and effectiveness. - Mentor other engineers on secure design and implementation practices through pairing, reviews, training sessions, and written guidance. Qualifications - 5+ years of experience in security engineering, infrastructure engineering, or application security, ideally in a B2B SaaS or cloud-native environment. - Hands-on experience with at least one major public cloud platform (e.g., GCP, AWS), including IAM, networking, logging/monitoring, and security services. - Strong proficiency in at least one programming or scripting language (e.g., Python, Go, Java, or similar) and experience using code to automate security controls or detection. - Direct experience with AI/LLM-specific security risks (prompt injection, model supply chain, etc.). - Demonstrated knowledge of secure application and system design, including topics like authentication/authorization, encryption in transit and at rest, least-privilege access, and secrets management. - Experience with security tooling such as vulnerability scanners, SAST/DAST tools, SIEM/centralized logging, endpoint protection, or cloud security posture management. - Solid understanding of common vulnerabilities and attack patterns (e.g., OWASP Top 10, misconfigurations, supply-chain risks) and how to mitigate them in practice. - Ability to work cross-functionally with engineering, IT, and compliance/legal teams, and to translate security requirements into practical implementation details. - Clear written and verbal communication skills, including the ability to document designs and decisions and to educate others on security best practices. - A collaborative, pragmatic approach: you’re comfortable making risk-based decisions, proposing options, and supporting teams in implementing secure, scalable solutions. Benefits - Intentionally building a diverse, equitable, and inclusive workplace. - Empowerment and authenticity to build trust and create a safer Internet.

Related Categories

Related Job Pages

More Security Engineer Jobs

Pliancy logo

Principal Security & Compliance Advisor, Outpost

Pliancy

People-Centric IT for Today’s Changemakers

Full TimeRemoteTeam 51-200H1B No Sponsor

• Serve as a senior security and compliance advisor for Outpost clients, with an emphasis on finance firms, including VC, PE, hedge funds, family offices, both ERAs and RIAs, and other investment firms, as well as select technology and biotech startups. • Lead consultative client conversations around governance, risk, controls, compliance readiness, secure AI adoption, security roadmaps, vendor selection, audit preparation, DDQs, cybersecurity insurance, incident preparedness, and operational workflows. • Translate client business objectives into practical security and compliance action plans that are clear, prioritized, and realistic. • Help clients understand, evaluate, and securely adopt AI tools, including usage policies, data handling expectations, vendor risk considerations, access controls, employee guidance, and practical governance models. • Help design, document, and continuously improve Outpost’s service delivery playbooks, templates, project plans, assessment methods, and client-facing deliverables. • Deliver leadership-level roadmapping and project ownership across ongoing client engagements. • Support clients working toward or maintaining compliance with frameworks and requirements such as SOC 2, ISO 27001, NIST CSF, CIS Controls, CCPA, GDPR, HIPAA-adjacent requirements, and other relevant security or privacy obligations. • Assess and improve client processes such as onboarding, offboarding, access reviews, vendor risk management, business continuity, disaster recovery, incident response, policy management, and control monitoring. • Advise on and help implement systems and tools across categories such as compliance automation, identity and access management, endpoint security, MDR, SIEM, vulnerability management, MDM, backup and recovery, AI productivity platforms, and security awareness. • Partner with Pliancy teams to connect security and compliance recommendations to the underlying IT systems, workflows, and support model required to make them stick. • Create high-quality internal and client-facing documentation that improves clarity, repeatability, and client experience. • Share market observations, client feedback, recurring pain points, and delivery lessons with Outpost leadership to help productize the offering. • Help shape future hiring, operating processes, and service standards as Outpost grows.

United States
$150K - $180K / year
Stack AV logo

Senior Cyber Security Engineer

Stack AV

Revolutionizing the Transportation of Goods

Full TimeRemoteTeam 51-200H1B No Sponsor

• Develop new cyber detections for threats and other uses cases using our SIEM and other security tooling. • Develop automated processes for triaging security incidents and incident response in general. • Assesses software and service requests from within the organization. • Deploy and develop solutions to better secure Stack AV’s infrastructure, data, and people. • Conduct and/or arrange vulnerability and other security assessments on Stack’s infrastructure. • Respond to security incidents and drive the effort to mitigate and/or remediate findings.

Pennsylvania
Simple Technology Solutions logo

Security Engineer – ISSO Support

Simple Technology Solutions

8(a) HUBZone IT consultancy w/ advanced partnerships w/ Amazon Web Services, Microsoft Azure & Google Cloud Platform

Full TimeRemoteTeam 51-200H1B No Sponsor

• serve as the primary point of contact and subject matter expert for all security assessment and authorization activities • implement and continuously maintain Zero Trust Architecture (ZTA) • ensure full compliance with FISMA, NIST 800-53, NIST 800-63 • engage with the agency's privacy and security teams • ensure all code submitted to production is free of medium- and high-level static and dynamic security vulnerabilities • manage AWS IAM role configurations and naming standards

United States
Capco logo

Técnico de Segurança do Trabalho

Capco

Capco, a Wipro company, is a management & technology consultancy dedicated to the financial services & energy industries

Full TimeRemoteTeam 1,001-5,000Since 1998H1B Sponsor

• Serviços técnicos especializados na Gestão de anomalias de segurança; • Serviços técnicos especializados de assessorias técnicas, avaliações, auditorias, e inspeções de segurança do trabalho nas instalações terrestres e marítimas; • Serviços técnicos especializados de gestão e execução de programas de treinamento de segurança do trabalho; • Serviços técnicos especializados no apoio à Gestão de Contratação de Fornecedores; • Serviços especializados de gestão de contingências; • Serviços especializados de segurança ocupacional e operacional; • Serviços especializados de gestão de indicadores e desempenho.

Brazil