Salary
💰 $185,000 - $230,000 per year
Tech Stack
AWSAzureCloudGoGoogle Cloud PlatformJenkinsKubernetesPythonTerraform
About the role
- Lead and manage the Security Engineering team, setting the technical vision and driving execution of a security strategy that scales.
- Protect infrastructure, products, and customer data through proactive engineering and automation.
- Detect and manage threats and risks across the entire stack and development lifecycle.
- Build and own a high-performing security function and foster a culture of shared responsibility with engineering teams.
- Develop and execute technical security roadmaps, including threat modeling, security architecture reviews, and vulnerability management.
- Lead major security incidents from detection and containment to post-mortem analysis and remediation.
- Partner with senior engineering leaders and multiple teams to drive security initiatives across the organization.
- Mentor and grow security engineers, setting high standards and coaching for performance and development.
Requirements
- 8+ years of experience in hands-on security engineering, with a significant portion spent in cloud-native environments (AWS, GCP, or Azure).
- 3+ years of direct people management experience leading and mentoring a high-performing team of security engineers.
- Proven track record of developing and executing a technical security roadmap, including threat modeling, security architecture review, and vulnerability management at scale.
- Experience leading major security incidents, from detection and containment to post-mortem analysis and remediation.
- Demonstrated ability to partner effectively with senior engineering leaders and drive security initiatives across multiple teams and departments.
- Cloud Security Expertise: Deep understanding of security principles and services in AWS or GCP, including IAM, VPC, security groups, and cloud-native security tooling.
- Infrastructure as Code (IaC): Proficiency with tools like Terraform or CloudFormation and experience securing IaC pipelines.
- CI/CD & DevSecOps: Strong experience integrating security controls (SAST, DAST, SCA) into CI/CD pipelines (e.g., Jenkins, GitLab CI, GitHub Actions).
- Container & Orchestration Security: Hands-on experience securing containerized workloads and orchestration platforms, particularly Kubernetes.
- Scripting & Automation: Strong proficiency in a scripting language such as Python or Go for the purpose of building security automation and tooling.
- Core Security Domains: Expertise in network security, cryptography, application security (AppSec), and modern authentication/authorization protocols.
- Organizer and Roadmapper: craft a vision around organizational needs and industry best practices, set ambitious targets and efficient paths.
- Collaborative Partner: view role as an enabler, not a gatekeeper; build trust and influence with engineering teams.
- Pragmatic & Risk-Based: prioritize effectively and make pragmatic decisions that balance security with business velocity.
- Proactive & Threat-Focused: think about potential attack vectors and proactively mitigate them.
- Automator: desire for durable solutions that eliminate manual toil through technology.
- Leader by example with a strong work ethic and high standards; committed coach that fosters team growth while driving performance.