Job Closed
This listing is no longer active.
Senior Security Engineer
Location
United States
Posted
103 days ago
Salary
$0 - $300K / year
Seniority
Senior
Job Description
Senior Security Engineer
Loancrate
• Lead and drive Loancrate’s security posture across application security, cloud security, identity, and compliance • Perform regular threat modeling, vulnerability assessments, and penetration testing • Build and maintain security tooling and automation: SAST/DAST, dependency scanning, container scanning, SBOM management, and secret detection • Harden our AWS environment: IAM, VPC boundaries, secrets management, audit logging, GuardDuty, Security Hub, KMS key management, and DDoS protection • Own our SOC 2 Type II program • Lead or coordinate incident response for security events • Establish and maintain a secure SDLC • Maintain a risk register • Partner with Operations on endpoint and device security • Manage third-party and vendor security risk • Own identity and access infrastructure • Contribute to security documentation, internal runbooks, and team education
Job Requirements
- 5+ years of experience in security engineering or related field
- Deep application security experience: threat modeling, OWASP Top 10 (and beyond), secure code review, SAST/DAST tooling
- Strong AWS security experience across IAM, VPC, GuardDuty, Security Hub, CloudTrail, KMS, Secrets Manager, and WAF
- Terraform and/or Pulumi proficiency
- Hands-on SOC 2 experience
- CI/CD security experience
- Fintech or regulated industry experience
- Collaborative mindset
- Identity and access experience
- Familiarity with data security for sensitive personal and financial data
- Strong written communication
- Scripting and automation skills (Python, Bash, or similar)
Benefits
- Health insurance
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Lead People Business Partner, Security
VantaVanta is the leading trust management platform that helps simplify & centralize security for organizations of all sizes.
• Serve as a trusted thought partner, consultant and coach to CISO and senior leaders across the CTS organization • Be the primary point of contact on all people-related matters for CTS org at all levels • Provide support, guidance and thought leadership on areas such as performance management, change management, employee relations, workforce and talent planning, career development, manager development, etc. • Collect and analyze data to deliver insights and drive recommendations that support the business • Assess organizational health and effectiveness on a regular basis and identify opportunities to drive improvements and efficiencies • Drive the project management and execution of critical People programs such as performance reviews, compensation planning, talent reviews, and engagement surveys • In partnership with cross-functional stakeholders and the broader People team, build and implement top-tier, scalable programs and policies to attract, retain and grow outstanding talent at Vanta.
Lead Security DevOps Engineer
Zoom Video CommunicationsZoom Video Communications was founded in 2011 to revolutionize the way teams communicate with its software-based conference room solution. Across all devices an
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description As a DevOps Engineer, you will deploy and operate data center and cloud software infrastructure. This senior role within the Security DevOps team oversees critical production systems, including: - Secrets management - Deployment pipelines - PKI Responsibilities include: - Defining and implementing projects to enable features, improve system safety, enhance security, and reduce costs - Driving projects that modernize secrets management infrastructure and/or deliver automation - Working across teams to complete projects while making significant hands-on contributions - Driving improvements to the security posture across Zoom - Influencing the direction of developer teams that own security infrastructure components - Producing designs and leading junior team members through implementation and deployment to production at scale, using modern best practices (e.g., IaC) - Communicating with stakeholders including security teams and senior managers Qualifications - Bachelors or Masters in Computer Science or similar - 8+ years of SRE or DevOps experience - Experience with at least one programming language, in addition to scripting languages - Experience with logging and monitoring tools (e.g. ELK stack, Prometheus, Grafana) - Experience with cloud providers (e.g. AWS, OCI) and cloud infrastructure technologies (e.g. Terraform, Kubernetes) - Experience with security from a DevOps perspective (e.g. running Vault) - Able to participate in on-call shifts, incident response, and work after hours/weekends for application releases/deployments - Experience with DevOps practices, CI/CD pipelines, and version control systems (e.g., Git) - Experience with system design and distributed computing at scale Requirements - Proficiency in explaining complex concepts to engineers, leaders, and security experts - Strategic thinking, balancing trade-offs, and adapting plans to achieve key objectives for stakeholders effectively Benefits - Comprehensive benefits program to help employees maintain their physical, mental, emotional, and financial health - Support for work-life balance - Opportunities to contribute to the community in meaningful ways Salary Range or On Target Earnings - Minimum: $124,000.00 - Maximum: $271,200.00 In addition to the base salary and/or OTE listed, Zoom has a Total Direct Compensation philosophy that takes into consideration base salary, bonus, and equity value. Note: Starting pay will be based on a number of factors and commensurate with qualifications & experience. We also have a location-based compensation structure; there may be a different range for candidates in this and other locations. Ways of Working Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting. Anticipated Position Close Date 04/30/26
Senior Research Director, Analyst – Cybersecurity Strategy
GartnerWe deliver actionable, objective insight that drives smarter decisions and stronger performance.
• Serve as an authority on cybersecurity strategy for CIOs in high-risk industries • Deliver research and recommendations on cybersecurity governance, risk management frameworks, and advanced cybersecurity technologies • Analyze industry trends, threat intelligence, and technology disruptions to forecast future risks • Present cybersecurity research and thought leadership in 1-to-1 conversations and at Gartner events • Support clients in evaluating and selecting cybersecurity vendors and solutions • Collaborate with other Gartner Analysts to develop comprehensive, actionable research on cybersecurity priorities
Director - Product Security
LivaNovaImproving Quality of Life Through Innovation. Every Patient, Every Day
As a global medtech company, we are driven by our Vision of changing the trajectory of lives for a new day and our Mission to create ingenious solutions that ignite patient turnarounds. Our relentless commitment to patients and strong legacy of innovation in healthcare are the foundation of our future. If you're looking for a new chance, a new beginning, a new trajectory, LivaNova is where your talent can truly thrive. Join our talented team members worldwide to become a pioneer of tomorrow—because at LivaNova, we don’t just treat conditions — we aspire to alter the course of lives. Job Summary: The Director of Product Security is a key leadership role responsible for the strategic vision, execution, and oversight of the company's product security program. This executive will lead a dedicated team to manage the cybersecurity posture of our medical device portfolio throughout its entire lifecycle, from design and development through post-market surveillance. The role is a direct response to a complex and evolving regulatory environment, including new requirements from the FDA, and is critical to ensuring patient safety, maintaining market access, and protecting the company's reputation and long-term business growth. The ideal candidate is a hands-on, visionary leader with deep technical knowledge, a strong understanding of medical device regulations, and exceptional communication skills to drive change across the organization and engage with external stakeholders. Houston, TX is the ideal location for this role, but this is open to Remote opportunities for well-qualified individuals. Key Responsibilities: - Strategic Leadership & Program Management: - Define and execute a comprehensive product security strategy that aligns with business priorities, FDA/MDR/524B expectations, and Quality Management System (QMS) requirements. - Build, lead, and mentor a high-performing team of product security professionals, fostering their technical and leadership skills. - Manage and allocate human and financial resources to achieve strategic objectives. - Secure Product Development Lifecycle (SDLC): - Drive a "shift-left" security strategy, integrating security controls and best practices into all stages of the product lifecycle. - Oversee a rigorous threat modeling program and lead cybersecurity risk assessments for all new and existing products. - Champion DevSecOps principles and automate security controls and testing within CI/CD pipelines. - Provide architectural guidance on secure design, including implementing security controls such as secure boot, firmware signing, and encryption. - Regulatory Compliance & Governance: - Ensure all required cybersecurity documentation, including risk assessments and SBOMs, is prepared and submitted for premarket applications (510(k), PMA). - Manage the generation and maintenance of SBOMs and VEX (Vulnerability Exploitability eXchange) documents to ensure transparency and enable targeted, actionable risk management for regulators and customers. - Act as the senior product security subject matter expert, representing the company during FDA and other international regulatory inspections. - Post-Market Surveillance & Incident Response: - Oversee the post-market surveillance program to continuously monitor field devices for emerging threats and vulnerabilities. - Lead and manage the security incident response process, including coordinated vulnerability disclosure, containment, root cause analysis, and remediation. - Develop and execute plans for communicating security updates and patches to customers and stakeholders. - Cross-Functional Collaboration & Stakeholder Engagement: - Partner with R&D, Engineering, Quality, Regulatory Affairs, and Legal teams to embed security practices and ensure a comprehensive approach to product safety. - Serve as the primary security consultant to the organization, articulating technical challenges and mitigation plans to senior management and external stakeholders in a clear, non-technical manner. - Engage with customers, hospital IT/IS staff, and industry partners to translate technical requirements into business and clinical impact and build trust in the company’s products. - Oversee external communications regarding program and product vulnerabilities - Develop and execute strategies for external presence and participation in industry groups, conferences and thought leadership activities Required Skills & Qualifications: - Education: Bachelor's degree in Computer Science, Cybersecurity, or a related engineering discipline, with 15 or more years of technical experience in the medical device industry. - Experience: A minimum of 10 years of progressive experience in cybersecurity, with at least 5 years in a leadership or director-level role. At least 3 years of experience integrating security into embedded systems or connected medical devices in a regulated product development environment is essential. - Technical Knowledge: Deep expertise in secure SDLC, threat modeling, and vulnerability management. Strong understanding of cybersecurity landscape, embedded systems security, IoT security, and cloud architectures - Certifications: Industry-recognized certifications such as CISSP, CISM, or CSSLP are highly valued. - Regulatory Acumen: Proven experience navigating cybersecurity requirements for FDA 510(k) and PMA submissions - Soft Skills: Exceptional leadership, communication, and problem-solving skills with a proven ability to drive clarity and consensus across broad organizations. Pay Transparency: A reasonable estimate of the annual base salary for this position is $185,000 - $225,000 + discretionary annual bonus. Pay ranges may vary by location. Employee benefits include: - Health benefits – Medical, Dental, Vision - Personal and Vacation Time - Retirement & Savings Plan (401K) - Employee Stock Purchase Plan - Training & Education Assistance - Bonus Referral Program - Service Awards - Employee Recognition Program - Flexible Work Schedules Welcome to impact. Welcome to innovation. Welcome to your new life.



