Vultr logo
Vultr

Vultr is on a mission to make high-performance cloud computing easy to use, affordable, and locally accessible.

Senior Security Engineering Architect

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 201-500Since 2014H1B No SponsorCompany SiteLinkedIn

Location

Alabama + 32 moreAll locations: Alabama | Arizona | Colorado | Connecticut | Florida | Idaho | Illinois | Iowa | Kentucky | Louisiana | Montana | Nebraska | Nevada | New Jersey | New Mexico | New York | North Carolina | Ohio | Oklahoma | Maryland | Massachusetts | Michigan | Minnesota | Missouri | Pennsylvania | Rhode Island | South Carolina | Tennessee | Texas | Utah | Vermont | Virginia | Wisconsin

Posted

3 days ago

Salary

$130K - $145K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglishKubernetesLinux

Job Description

Senior Security Engineering Architect

Vultr

• Own and maintain the organization's baseline security standards for Linux hardening, VM image governance, container and Kubernetes security, and CI/CD pipeline security controls, ensuring standards are practical, well-documented, and easy for engineering teams to adopt • Act as the primary bridge between Security, Compliance, and Engineering, translating regulatory and policy requirements into concrete, implementable guidance without blocking delivery velocity • Engage engineering squads in a consultant capacity, embedding into team workflows to assess current security posture, identify gaps, and deliver actionable remediation plans across bare metal, virtual, and container environments • Partner closely with the DevSecOps Engineer to identify security controls that can be codified, ensuring hardening standards, compliance checks, and policy enforcement are built into images, configuration management pipelines, and CI/CD workflows rather than left as manual processes • Champion secure-by-default practices by making security requirements visible early in the design and architecture phase, before engineering teams build • Own the security review process for infrastructure architecture changes, partnering with SecOps on tooling and third-party integration reviews to ensure engineering context and requirements are represented • Develop and maintain accessible runbooks, playbooks, and onboarding materials that enable engineering teams to self-serve security best practices across bare metal, virtual, and container environments • Build and maintain cross-functional relationships to surface emerging risks early, synthesizing findings from engineering teams into prioritized remediation work that can be automated and scaled • Represent engineering's security needs in compliance and risk discussions, ensuring security strategy stays grounded in operational realities • Measure program effectiveness through adoption metrics, policy compliance rates, and mean-time-to-remediate trends, using data to continuously improve both the standards themselves and how they are communicated

Job Requirements

  • 5+ years of experience in security engineering, DevSecOps, or a related discipline with direct experience working alongside infrastructure and platform engineering teams
  • Deep understanding of Linux hardening, container security, and Kubernetes security standards and their practical implementation
  • Experience translating compliance frameworks (SOC 2, ISO 27001, PCI-DSS, or similar) into actionable engineering requirements
  • Strong technical writing skills with the ability to produce clear, adoption-focused documentation, runbooks, and onboarding materials
  • Experience acting in a consultant or embedded capacity with engineering teams, balancing security requirements with delivery velocity
  • Familiarity with security scanning tools and CI/CD pipeline security controls
  • Experience measuring and reporting on security program effectiveness using data-driven metrics
  • Excellent communication skills with a proven ability to build cross-functional relationships and influence without authority
  • Background in infrastructure security across bare metal, virtual, and container environments

Benefits

  • 100% company-paid insurance premiums for employee medical, dental and vision plans.
  • 401(k) plan that matches 100% up to 4%, with immediate vesting
  • Professional Development Reimbursement of $2,500 each year
  • 11 Holidays + Paid Time Off Accrual + Rollover Plan
  • Commitment matters to Vultr! Increased PTO at 3 year and 10 year anniversary + 1 month paid sabbatical every 5 years + Anniversary Bonus each year
  • $500 stipend for remote office setup in first year + $400 each following year
  • Internet reimbursement up to $75 per month
  • Gym membership reimbursement up to $50 per month
  • Company paid Wellable subscription

Related Categories

Related Job Pages

More Security Engineer Jobs

Semgrep logo

Senior/Staff Security Researcher

Semgrep

Semgrep is a code scanning platform for finding first and third-party security vulnerabilities in your code base.

Full TimeRemoteTeam 51-200Since 2017H1B No Sponsor

• Build detection at scale. Design and ship security workflows that combine deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk, and beyond) across many languages and frameworks. • Make LLMs viable for security-critical work. Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy: atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and which models see sensitive code. • Push on hard problems in automated triage and validation. Help close the gap between 'a finding exists' and 'this finding is real and worth a developer’s time,' so we can run workflows broadly and validate results at scale rather than by weeks of manual review. • Build and defend quality with evals. Design benchmarks and evaluation loops grounded in real customer codebases, not just synthetic datasets, so we actually know when a workflow is good. • Encode security judgment into tooling. Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems. • Learn new territory fast. Dive into unfamiliar languages, frameworks, and technologies, figure out how vulnerabilities manifest there, and turn that understanding into detection. • Prototype new products. Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user. • Share your work. Publish blog posts, give talks, produce cheat sheets and workshops, and represent Semgrep’s research to the wider community. • Lead and plan research with impact. Set the direction for research based on industry trends, emerging threats, and where the field is heading, and turn that into work that moves our products and the broader security community forward.

Arizona + 20 moreAll locations: Arizona | California | Colorado | Connecticut | District Of Columbia | Florida | Illinois | Nebraska | New Jersey | New York | North Carolina | Oregon | Maryland | Massachusetts | Michigan | Missouri | Tennessee | Texas | Virginia | Washington | Wisconsin
$190K - $319K / year

IAM Specialist

NATIONMIND LLC

NationMind LLC is a technology consulting firm focused on Technical Engineering, software development, technicians, QA testing and services. We help clients build reliable, scalable applications with a strong emphasis on automation, performance, and quality. Our team works across industries, delivering solutions that drive innovation and operational efficiency.

Role Description We are seeking an experienced Identity and Access Management (IAM) Specialist to support user access administration in an ITAR-regulated environment. The ideal candidate will have strong experience with Microsoft Entra ID (Azure AD), Identity Governance & Administration (IGA), RBAC, Active Directory, and access governance while ensuring compliance with regulatory requirements. Qualifications - 3–5 years of experience in Identity and Access Management (IAM) / User Access Management - Experience managing user access in regulated ITAR environments - Strong understanding of Role-Based Access Control (RBAC) - Strong understanding of Identity Governance - Strong understanding of Access Certification processes - Hands-on experience with Active Directory - Hands-on experience with LDAP - Hands-on experience with UNIX - Hands-on experience with Mainframe - Hands-on experience with Microsoft Exchange Administration - Experience with Microsoft Entra ID - Experience with Identity Governance & Administration (IGA) - Experience with Single Sign-On (SSO) - Experience with Multi-Factor Authentication (MFA) - Experience with Conditional Access - Experience with user provisioning, deprovisioning, and access review processes - Strong analytical, audit, and documentation skills Requirements - Experience supporting ITAR-regulated environments - Strong understanding of access governance and compliance controls - Experience conducting User Access Reviews - Experience conducting Entitlement Reviews - Experience conducting Access Certification - Experience implementing and managing Role-Based Access Control (RBAC) - Ability to manage access requests and approvals - Hands-on experience with Microsoft Entra ID - Hands-on experience with IGA - Hands-on experience with SSO - Hands-on experience with MFA - Hands-on experience with Conditional Access - Excellent stakeholder communication skills Good-to-Have Skills - Knowledge of SOX and other regulatory compliance frameworks - Experience with ServiceNow workflows - Automation and scripting experience - Experience supporting Aerospace, Defense, or Manufacturing organizations Key Responsibilities - Manage user access requests across ITAR and non-ITAR systems. - Perform provisioning and deprovisioning activities in compliance with regulatory requirements. - Conduct user access reviews, certifications, and audit support activities. - Enforce Role-Based Access Control (RBAC) and least-privilege access principles. - Investigate and resolve user access-related issues. - Maintain IAM documentation, SOPs, and compliance evidence. - Coordinate with Security, Audit, and Business teams to ensure ITAR compliance.

United States
$40 - $45 / hour
Full TimeRemoteTeam 51-200Since 1934H1B No Sponsor

• Develop and lead the enterprise cybersecurity strategy, roadmap, policies, and governance structure in alignment with the credit union’s risk appetite and business objectives. • Oversee information security risk management, including risk assessments, control maturity, issue remediation tracking, and alignment to regulatory expectations. • Establish and oversee an enterprise cybersecurity assessment and assurance program, including periodic internal security assessments, independent third-party assessments, penetration testing, vulnerability assessments, and security maturity reviews. • Lead security-related regulatory, audit, and board reporting, including updates on cybersecurity posture, incidents, third-party exposure, and emerging threats. • Establish and oversee the credit union’s third-party cybersecurity risk program, including due diligence standards, control reviews, contract security provisions, and ongoing monitoring. • Provide executive oversight for IAM, cloud, and security architecture standards. • Own cybersecurity incident response leadership at the executive level, including escalation management, tabletop exercises, post-incident reporting, and lessons learned. • Lead Business Continuity, Disaster Recovery, and Cyber Resilience planning. • Lead AI and data governance efforts related to cybersecurity, including secure use of AI tools, model oversight coordination, data protection controls, and governance expectations. • Partner with Digital Delivery, Infrastructure, Risk, Compliance, Internal Audit, Legal, and business leaders while maintaining independent cybersecurity oversight. • Supervise the Security Operations Manager and ensure effective day-to-day execution of operational security activities.

Montana + 2 moreAll locations: Montana | Nebraska | Rhode Island
$225K - $275K / year

Role Description - Design and define comprehensive red-teaming workflows and adversarial scenarios targeting SaaS and cloud-based environments. - Conduct hands-on penetration testing and adversarial threat modeling across platforms such as Microsoft 365, Google Workspace, Slack, GitHub, and Snowflake. - Act as a senior reviewer, critically evaluating the quality and depth of red-teaming exercises and deliverables. - Identify and document potential vectors for misuse or manipulation of AI agents, including prompt injection, privilege escalation, data exfiltration, and destructive actions. - Contribute practical insights for developing and vetting security controls, policies, and detection strategies relevant to real-world SaaS environments. - Collaborate with other cybersecurity professionals, providing detailed written and verbal feedback on findings and improvements. - Support benchmarking initiatives by creating adversarial scenarios that reflect contemporary threats and attack methodologies. Qualifications - Extensive hands-on experience in security domains such as red teaming, penetration testing, application/cloud security, or security engineering. - Deep understanding of enterprise SaaS security concepts including identity, RBAC/permissions, and data governance. - Direct familiarity with Microsoft 365, Google Workspace, Slack, GitHub, and Snowflake from a security evaluation perspective. - Demonstrated ability to think adversarially about how AI and SaaS platforms could be exploited or compromised. - Strong written and verbal communication skills, enabling clear articulation of complex security issues and recommended remediations. - Proven track record of practical, real-world impact in security projects—beyond simply listing experience on a resume. - Bonus: Prior experience in AI/LLM security or adversarial testing of agent-based systems.

United States
$60 - $100 / hour