Salary
💰 $170,000 - $193,000 per year
Tech Stack
AWSCloudDNSDockerGoogle Cloud PlatformJavaScriptKubernetesLinuxPythonTCP/IPTerraform
About the role
- Collaborate with senior engineers to define and implement security best practices across Serve’s cloud infrastructure (AWS/GCP).
- Support threat modeling, risk assessments, and architecture reviews for key components of our platform.
- Develop, maintain, and improve automation tools for secure configuration management and continuous monitoring (e.g., image scanning, IAM policy enforcement).
- Assist in implementing runtime security measures for our containerized workloads (Docker, Kubernetes).
- Design and deploy endpoint and application security controls to protect managed devices and ensure compliance across the organization.
- Participate in the triage, investigation, and resolution of security incidents.
- Contribute to internal documentation and raise security awareness across engineering teams through reviews and knowledge sharing.
- Participate in the Security team on-call rotation.
Requirements
- 5+ years of hands-on experience in security engineering, DevSecOps, or infrastructure security roles.
- Solid understanding of cloud platforms (AWS and/or GCP) and their security services.
- Strong knowledge of Linux systems and core networking protocols (TCP/IP, DNS, HTTP).
- Familiarity with infrastructure-as-code tools such as Terraform or CloudFormation.
- Experience with container security best practices and tools (Docker, Kubernetes).
- Proficiency in at least one scripting language (Python, Bash, etc.).
- Excellent communication and collaboration skills across technical and non-technical teams.
- Familiarity with secure authentication protocols (OAuth, SAML) and cryptographic key management.
- Experience with vulnerability scanning and compliance tooling.
- Exposure to security frameworks and standards (NIST, ISO27001, CIS Benchmarks).
- Programming experience in languages like C, C++, or JavaScript.
- Security certifications such as AWS Security Specialty, Google Cloud Security Professional, or CISSP.
- A strong sense of ownership and accountability in your work.
- The ability to work independently, ask questions, and drive projects forward.
- Continuous learning and a genuine interest in security across domains.
- Empathy, clear communication, and a collaborative mindset.