Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Forward Financing

Staff Security Engineer

Forward Financing

Staff Security Engineer overseeing security technology stack architecture at Forward Financing. Owning integration and evaluating security tools within the company’s ecosystem.

Posted 7/28/2026full-timeRemote • 🇺🇸 United StatesLead💰 $160,000 - $200,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in security architecture and engineering, with a strong focus on cloud security (AWS), infrastructure-as-code, and integration of security tools within engineering ecosystems. Proficient in aligning security practices with frameworks such as CIS Controls, ISO 27001, and NIST while mentoring teams across AppSec, SecOps, and GRC.

Highest-signal resume keywords
Security Architecture OwnershipCloud Security Expertise (AWS)Infrastructure-as-Code (Terraform)Integration of Security ToolsKnowledge of Security Frameworks (CIS, ISO 27001, NIST)

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security EngineeringDetection EngineeringCloud SecurityInfrastructure Log AnalysisProgramming (Ruby, Python, Go)CI/CD IntegrationRole-Based Access ControlData Pipeline ArchitectureAutomated Security ConfigurationsSecurity Tool Evaluation
Soft Skills
Technical CommunicationMentoringCollaboration
Tools & Technologies
AWSGCPAzureSIEMTerraformCI/CD PipelinesIdentity Governance
Industry Keywords
AppSecSecOpsGRCCIS ControlsISO 27001SOC 2NIST

Tech Stack

Tools & technologies
AWSAzureCloudGoGoogle Cloud PlatformPythonRubyTerraform

About the role

Key responsibilities & impact
  • Own the end-to-end architecture of Forward’s security technology stack – the platforms, tooling, data pipelines, and integrations that power AppSec, SecOps, and GRC – and make sure it works cleanly with the broader Engineering, IT, and Infrastructure ecosystem.
  • Set the technical direction for how we evaluate, integrate, standardize, and retire security tools, defining the reference architectures and standards the department builds on.
  • Act as the shared technical foundation for all three security functions: helping developers build security testing into how software ships, giving the operations team clean and reliable data to detect and investigate threats, and giving the compliance team the evidence and reporting they need to prove that controls are working.
  • Partner with Engineering, IT, and Infrastructure to build security into shared platforms – cloud (AWS), identity, CI/CD, endpoints, and SaaS – so security is native rather than bolted on.
  • Lead the evaluation, proof-of-concept, and rollout of new security technologies; consolidate overlapping tools and reduce operational toil with defensible build-versus-buy recommendations.
  • Use infrastructure-as-code and detection-as-code to make security configurations, platform hardening, and cloud-native controls automated, versioned, and repeatable.
  • Architect our centralized logging and detection data foundation (SIEM and supporting pipelines) so a single high-quality data source serves detection, investigation, and audit needs.
  • Architect the technical underpinnings of our identity governance and role-based access control programs, plus the automation that keeps access defensible as we grow.
  • Keep the security architecture aligned to frameworks like CIS Controls, ISO 27001, SOC 2, and NIST, so it stays defensible and auditable.
  • Provide senior technical support during major incidents, and turn lessons learned into lasting architectural improvements.
  • Grow the bar for the whole department – mentoring and technically guiding engineers across AppSec, SecOps, and GRC on design quality, secure defaults, and engineering practices.

Requirements

What you’ll need
  • Typically 7 or more years in security engineering, security architecture, detection engineering, or security operations, including designing systems that span multiple security domains.
  • Demonstrated experience owning or heavily shaping the architecture of a security technology stack – how platforms, data, and controls fit together – not just operating a single tool.
  • Deep, hands-on cloud security expertise (AWS required; GCP or Azure a plus), including control plane monitoring, IAM, network architecture, and infrastructure log analysis.
  • A track record of integrating security tooling and controls into broader Engineering and IT ecosystems (CI/CD, identity, endpoints, and SaaS).
  • Fluency across at least two of the three domains this role serves – AppSec, SecOps, and GRC – with enough literacy in the third to design for it.
  • Experience with infrastructure-as-code and/or detection-as-code (e.g., Terraform and CI/CD pipelines for security configurations and detection logic).
  • Working knowledge of security frameworks such as CIS Controls, ISO 27001, SOC 2, and NIST, and how architecture maps to control and audit requirements.
  • Experience with modern programming languages such as Ruby, Python, or Go, sufficient to build automation and integrations.
  • Ability to communicate risk and technical direction crisply to engineers and executives alike.
  • Typically has a Bachelor’s Degree in Computer Science, Physics, or an equivalent technical degree, or equivalent industry experience.

Benefits

Comp & perks
  • Flexibility is a top priority: Our employees are empowered to choose where they want to work (whether that’s from home, in the office, or a combination of both) with flexible hours.