Manager, Security Engineering, Cloud & AppSec

🕒 vor 2 Monaten

🇺🇸 Vereinigte Staaten – Remote

💵 $149.850 - $185.000 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of Horizon3.ai

Horizon3.ai

51 - 200 Mitarbeiter

Gegründet 2019

🔒 Cybersecurity

🤖 Künstliche Intelligenz

☁️ SaaS

Cybersecurity • Artificial Intelligence • SaaS

Die NodeZero™-Plattform befähigt Ihr Unternehmen, Ihre ausnutzbare Angriffsfläche kontinuierlich zu identifizieren, zu beheben und die Wirksamkeit der Maßnahmen zu verifizieren. Reduzieren Sie Ihr Sicherheitsrisiko, indem Sie Schwachstellen in Ihrem Netzwerk autonom finden, wissen, wie Sie sie priorisieren und beheben, und umgehend verifizieren, dass Ihre Maßnahmen wirken. NodeZero liefert produktionssichere, autonome Penetrationstests sowie weitere zentrale Assessments, die über Ihre größten internen, externen, Cloud- und Hybrid-Cloud-Umgebungen skalieren. Keine Agents erforderlich, kein Code zu schreiben, keine Berater zu beauftragen.

Beschreibung

• Lead, coach, and grow the Security Engineering team, including both Cloud Security Engineers and Application Security Engineers • Set priorities and operating rhythms for the team, balancing strategic security investments, day-to-day engineering support, and incident response • Design and implement security controls across our Cloud environments, such as but not limited to: AWS, Azure, GCP, Digital Ocean, OCI, etc., including IAM, SCPs, VPC security, S3 bucket policies, security groups, key management, and logging • Continuously monitor and improve cloud posture by managing and tuning services such as GuardDuty, Security Hub, AWS WAF, CloudTrail, and Inspector • Partner with engineering teams to embed security into the SDLC, including secure design reviews, threat modeling, architecture review, and CI/CD security automation • Lead the application security program, including secure coding practices, vulnerability management, developer enablement, and product security reviews • Continuously monitor and improve application security tooling by managing and tuning services such as SonarQube, Dependency Track, ZAproxy, Trufflehog, Trivy • Build and maintain GitLab CI/CD pipelines and tooling for automated security testing and scanning of cloud resources and applications • Conduct threat modeling, architecture reviews, and risk assessments for cloud deployments, product features, and new systems • Implement security monitoring, secure systems hardening, and detective controls for malicious activity across AWS and application environments • Respond quickly to new and emerging threats and vulnerabilities; support investigations, post-mortem analysis, root cause identification, and preventive actions • Define and enforce identity and access management best practices, including least privilege, federated identity, role-based access control, and automated remediation • Develop and maintain security policies, standards, and procedures aligned to frameworks such as SOC 2, GDPR, ISO 27001, FedRAMP, NIST, CIS, and MITRE ATT&CK • Create metrics, reporting, and risk narratives that communicate security posture, trends, and priorities to business owners and leadership • Evaluate and recommend new tools, techniques, and controls to improve the security posture of our cloud and application environments

🎯 Anforderungen

• Must be proficient in AWS security services, Terraform, GitLab, and modern CI/CD security practices • Must have a deep understanding of AWS security architecture, IAM, cloud posture management, data security principles, and secure SDLC practices • Must have experience leading or closely partnering with Application Security efforts, including threat modeling, vulnerability management, and security reviews • Must be knowledgeable in compliance standards and security frameworks, including SOC 2, GDPR, ISO 27001, FedRAMP, NIST, CIS, and MITRE ATT&CK • Must have strong written and verbal communication skills, with the ability to explain technical risks and tradeoffs to both technical and non-technical stakeholders • Must be able to work independently and as part of a team, with a strong sense of ownership and accountability • Must have experience developing metrics and reporting that communicate risk and security posture to leadership • Must have familiarity with DLP concepts, including data classification, identification, and protection • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience • 5+ years of experience in cybersecurity • 5+ years of experience securing AWS environments • 5+ years of experience securing cloud-native systems and modern software delivery pipelines • Prior experience leading security engineers or serving as a technical lead in a security engineering function

🏖️ Vorteile

• Health insurance • Vision insurance • Dental insurance • Flexible vacation policy • Generous parental leave • Equity package in the form of stock options • Career development opportunities • Collaborative environment that encourages creativity

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 2 Monaten

RAPIDFORT

51 - 200

💼 Beratung

🎖️ Verteidigung

🏥 Gesundheitswesen

Senior OS Engineer at RapidFort designing and maintaining secure Linux-based operating systems. Focused on CVE remediation, container image security, and automation for efficient build pipelines.

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 2 Monaten

TEECOM

51 - 200

💼 Beratung

🏥 Gesundheitswesen

🏗️ Bauwesen

Associate Principal managing multi-discipline engineering projects for TEECOM. Leading client relationships and mentoring engineering teams while ensuring quality deliverables.

🇺🇸 Vereinigte Staaten – Remote

💵 $125.000 - $160.000 / Jahr

⏰ Vollzeit

🟢 Junior

🟡 Mittelstufe

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 2 Monaten

Sargent & Lundy

1001 - 5000

🏗️ Bauwesen

🎖️ Verteidigung

⚡ Energie

Lead Cyber Security Engineer specialized in nuclear power cybersecurity. Focus on critical digital asset assessments and cybersecurity controls implementation in nuclear facilities.

🇺🇸 Vereinigte Staaten – Remote

💵 $118.023 - $180.313 / Jahr

⏰ Vollzeit

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cyber Security

🕒 vor 2 Monaten

NVIDIA

10.000+ Mitarbeiter

🏥 Gesundheitswesen

🏭 Fertigung

🤖 Künstliche Intelligenz

Senior Security Architect designing and implementing security systems for NVIDIA's AI computing infrastructure. Collaborating with various teams to protect critical infrastructure and intellectual property.

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cyber Security

Docker

Firewalls

Kubernetes

Linux

NFS

Realm

Rust

🕒 vor 2 Monaten

Akamai Technologies

5001 - 10000

🔒 Cybersecurity

🏢 Unternehmen

📱 Medien

Enterprise Architect in Akamai's Application & API Security team designing and implementing security solutions. Partnering with engineers and architects to ensure cloud-native security architectures are executed effectively.

🇺🇸 Vereinigte Staaten – Remote

💵 $119.600 - $215.400 / Jahr

⏰ Vollzeit

🟠 Senior

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich