Security Engineer

Vaga não está no LinkedIn

🕒 Junho 24

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $160.000 - $210.000 / ano

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

👻 Score fantasma 33%

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of Flox

Flox

11 - 50 funcionários

☁️ SaaS

⚡ Produtividade

Software • SaaS • Productivity

A Flox é uma plataforma de software integrada projetada para que equipes gerenciem de forma eficaz o software e suas dependências durante todo o ciclo de vida do software. Ela simplifica o processo de integração para novos projetos, permitindo que desenvolvedores configurem rapidamente seus ambientes com complexidade mínima. Os ambientes da Flox são flexíveis e podem ser facilmente compostos, sincronizados e compartilhados, garantindo desempenho consistente em várias arquiteturas e sistemas operacionais. A ferramenta visa resolver problemas comuns no desenvolvimento, como o famoso problema de 'funciona na minha máquina', oferecendo uma solução confiável e eficiente para gerenciar ambientes de desenvolvimento de software.

Descrição

• Help evaluate whether to stand up an internal SIEM or work with an outsourced SOC provider—then implement whichever path makes sense for where we are as a company. • Build incident response runbooks and triage workflows—then actually test them (e.g. test backups in case needed for ransomware recovery) • Be the person who sees something and does something about it • Scan and harden our AWS posture hands-on: IAM policies, SCPs, security group hygiene, GuardDuty, Security Hub, and automated compliance guardrails need to be evaluated and maintained • Own Cloudflare configuration across WAF rules, DDoS protection, bot management, Zero Trust access, and DLP policies—keeping rules current and tuned as the product evolves • Implement IaC security scanning (Checkov, tfsec, or similar) directly into CI/CD pipelines • Deploy and manage endpoint protection across developer systems and production endpoints—covering EDR, device posture, behavior monitoring (including dynamic scans), DLP, and threat detection • Ensure developer machines (Mac-heavy environment typical of engineering teams) meet baseline security standards while minimizing friction that slows people down. • Define and enforce endpoint compliance policies, including disk encryption, patch posture, and application controls • Secure our build and release pipelines • Consider SLSA framework adoption and supply chain integrity attestations for our catalog and environments • Stand up dependency vulnerability scanning and own the remediation workflow end-to-end for third-party services, libraries, middleware, operating systems, and SaaS • Integrate SAST and SCA tooling (Semgrep, Snyk, GitHub Advanced Security) into developer workflows • Participate in security design reviews and threat modeling for new features • Work shoulder-to-shoulder with developers to find and fix vulnerabilities using a risk-based model instead of just vulnerability aging reports • Audit and rationalize IAM across AWS, Cloudflare, SaaS applications, and internal tooling; implement the fixes, not just the findings • Drive SSO consolidation, enforce MFA universally, and implement least-privilege access in practice, not just policy • Build a lightweight, repeatable access review process—something that actually runs on a cadence and produces real decisions • Own joiner/mover/leaver processes so that entitlements stay clean as the team grows • Evaluate and implement an appropriate identity governance solution for our stage—not an enterprise IGA platform, but something that gives us control and auditability

🎯 Requisitos

• 3–5 years of hands-on security engineering experience, ideally at a software company or cloud-native environment • A demonstrable track record of implementing security tools and controls, not just scoping or recommending them • Solid working knowledge of AWS security services: IAM, SCPs, GuardDuty, Security Hub, CloudTrail, and related tooling • Hands-on experience with Cloudflare—WAF rule management, Zero Trust, DLP, or similar; comfort learning what you haven’t used yet • Experience deploying and managing endpoint protection (EDR/MDM) across a mixed developer and production environment • Familiarity with software supply chain concepts: SBOMs, dependency management, artifact signing, SLSA • Experience integrating SAST, SCA, or DAST tools into CI/CD pipelines • Comfort with scripting or light automation (Python, Bash, or similar) to build repeatable processes • Ability to work independently, ruthlessly prioritize, and operate without a playbook • The kind of person who is bothered when something is insecure and doesn’t wait for someone else to fix it.

🏖️ Benefícios

• Competitive salary • Meaningful equity in a well-funded company • Flexible hybrid environment

Candidatar-se

Vagas Similares

🕒 Junho 24

Recurrent Energy

501 - 1000

🏗️ Construção

🏭 Manufatura

⚡ Energia

Cybersecurity Architect at Recurrent Energy focusing on OT cybersecurity strategies and compliance. Implementing solutions to protect critical infrastructure in energy and renewables.

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 24

Etched

11 - 50

🏭 Manufatura

🤖 Inteligência Artificial

🔧 Hardware

Security Engineer at Etched managing security for AI hardware infrastructure. Responsible for monitoring, detection, and response to safeguard critical systems and data.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $150.000 - $250.000 / ano

💰 $5.400.000 Seed Round em 2023-05

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🦅 Patrocina Visto H1B

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 24

Apollo Information Systems

51 - 200

💼 Consultoria

🏥 Saúde

📦 Logística

Technical Assessor at Apollo Information Systems conducting cybersecurity assessments. Leading assessment efforts and providing actionable guidance to enhance clients' security posture.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $80.000 - $120.000 / ano

💰 $5.000.000 Seed Round - Apollo Information Systems em 2025-02

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 23

VerTALENTS

11 - 50

🎯 Recrutamento

🔒 Cibersegurança

Cloud Security Engineer securing cloud environments through automation and vulnerability assessments. Collaborating with engineering teams to develop security controls across AWS, Azure, and GCP.

🇺🇸 Estados Unidos – Remoto (EUA)

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 23

VerTALENTS

11 - 50

🎯 Recrutamento

🔒 Cibersegurança

Sr. Offensive Security Consultant leading complex security assessments across enterprise environments. Focusing on penetration testing and application security engagements with client risk communication.

🇺🇸 Estados Unidos – Remoto (EUA)

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório