Senior Security Engineer

🔥 12 hours ago

🇺🇸 United States – Remote

💵 $133k - $199k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 1%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Guidewire Software

Guidewire Software

1001 - 5000 employees

Founded 2001

🛡️ Insurance

💰 $750k Series C on 2008-03

Software • Insurance • Cloud Computing

Guidewire Software is a leading provider of software solutions for the property and casualty (P&C) insurance industry. The company offers a comprehensive platform that includes core applications such as PolicyCenter, ClaimCenter, and BillingCenter, as well as advanced analytics and a robust cloud platform. Guidewire focuses on delivering digital transformations, improving operational efficiencies, and enhancing customer service for insurers globally. Through collaborations and partnerships, Guidewire supports a wide range of insurance products and services, including usage-based and embedded insurance. With its commitment to innovation and customer success, Guidewire continues to empower insurers to meet the evolving demands of the industry.

📋 Description

• Lead complex infrastructure security initiatives involving multiple teams, systems, and dependencies, focusing on AWS cloud environments and CI/CD pipelines • Design, implement, and operate security controls across AWS and applicable cloud platforms • Build secure-by-default solutions using infrastructure as code, policy as code, CI/CD, and automation • Improve cloud governance, security posture, and operational resilience • Define and maintain security baselines for cloud accounts, operating systems, containers, AMIs, Kubernetes, networks, and supporting infrastructure • Support cloud account onboarding, offboarding, inventory, configuration drift management, exception handling, and control validation • Design and improve cloud and infrastructure network security, including segmentation, traffic visibility, ingress and egress control, DNS, firewalls, routing, private connectivity, monitoring, and enforcement • Secure CI/CD and software supply chains, including build and deployment workflows, dependencies, artifacts, containers, registries, third-party actions, secrets, and runner environments • Support asset and identity governance for applications, infrastructure, containers, service accounts, workload identities, API keys, AI agents, and MCP tools • Participate in AI security initiatives involving AI models, agents, and tool integrations, including threat modeling, prompt injection defenses, data egress protection, guardrails, human-in-the-loop controls, and monitoring • Apply risk-based security analysis using reachability, attack paths, asset criticality, exploitability, and business impact • Validate scanning-tool and AI-generated findings, establish ownership and remediation expectations, and improve finding-quality feedback loops • Represent Security in architecture, change management, design review, and operational forums • Communicate risks, trade-offs, assumptions, dependencies, and business impact to technical and non-technical audiences • Create standards, runbooks, architecture decision records, dashboards, documentation, and enablement materials • Mentor engineers and help partner teams adopt secure patterns without direct management responsibility • Participate in on-call rotations and incident response support for cloud and infrastructure security incidents • Monitor emerging threats and translate relevant developments into improvements to Guidewire’s security controls

🎯 Requirements

• Typically 5+ years of experience in security engineering, cloud security, infrastructure security, DevSecOps, or equivalent practical experience • Hands-on experience designing and operating secure AWS environments is required • Experience with Google Cloud Platform (GCP) is strongly preferred; experience with other cloud platforms is a plus • Experience with cloud governance, access management integration, policy enforcement, logging and monitoring, data protection, network security, configuration management, and cloud account lifecycle controls • Hands-on experience with infrastructure-as-code using Terraform, CloudFormation, or comparable technologies • Hands-on experience building, securing, testing, and operating CI/CD pipelines, preferably using GitHub Actions or comparable platforms • Experience with pipeline automation, secrets management, artifact handling, and runner security • Hands-on scripting or programming experience using Python, Go, or another appropriate language • Practical knowledge of cloud and infrastructure networking, including segmentation, routing, DNS, firewalls, ingress and egress controls, private connectivity, and network telemetry • Experience securing containers and Kubernetes platforms, preferably EKS or an equivalent platform • Knowledge of threat modeling, secure design, vulnerability management, security testing, risk assessment, monitoring, and incident response • Ability to evaluate security-control effectiveness using evidence, operational feedback, exceptions, findings, and relevant metrics • Demonstrated experience building, operating, or contributing to security measurement and analysis capabilities • Working knowledge of identity and access-control concepts, including authentication, authorization, privileged access management, identity governance, zero-standing privilege, workload and non-human identities, and secrets management • Working knowledge of software supply-chain security concepts, including SBOMs, artifact signing, provenance, dependency management, secure registries, and CI/CD runner hardening • Working knowledge of foundational AI security concepts, including LLM risks and prompt safety • Ability to own complex work, manage ambiguity, make trade-offs, identify risks, and deliver outcomes across multiple teams • Strong written and verbal communication skills • Preferred: hands-on experience or deep knowledge of AI-security risks and controls, including LLMs, AI agents, MCP, AI gateways, prompt injection defense, sensitive-data leakage, and advanced AI models/tools • Preferred: familiarity with NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, ISO/IEC 42001, or comparable frameworks • Preferred: certifications such as AWS Security Specialty, CISSP, GIAC, or equivalent practical expertise

🏖️ Benefits

• Health insurance • Dental insurance • Vision insurance • Paid time off • Company sponsored retirement plan • Some roles may be eligible for the annual company bonus plan • Some roles may be eligible for commissions • Some roles may be eligible for long term incentive awards • Disability accommodations throughout the hiring process • Appeals process for denied accommodations or non-selection decisions

Apply Now

Similar Jobs

🔥 14 hours ago

Defense Unicorns

51 - 200

💼 Consulting

📦 Logistics

🎖️ Defense

Senior engineer implementing secure identity, endpoint, cloud, and network systems for Defense Unicorns’ federal and enterprise customers. Supporting compliance-ready software delivery and cybersecurity operations.

🔥 14 hours ago

Defense Unicorns

51 - 200

💼 Consulting

📦 Logistics

🎖️ Defense

IT Systems & Security Engineer implementing and securing customer IT environments for Defense Unicorns. Configuring identity, endpoints, networks, compliance controls, and automation.

🔥 15 hours ago

Aledade, Inc.

501 - 1000

🏥 Healthcare

⚕️ Healthcare Insurance

🏢 Enterprise

Senior Security Engineer II securing Aledade’s independent-primary-care technology infrastructure. Automating IAM, cloud security, and incident response through Security-as-Code.

🔥 15 hours ago

GEICO

10,000+ employees

🚘 Automotive

💼 Consulting

🏥 Healthcare

Senior Internal Security Investigator conducting non-field fraud investigations for GEICO, a major U.S. auto insurer. Evaluating evidence, interviewing witnesses, and supporting claims departments.

🔥 15 hours ago

Interra Health

51 - 200

🏥 Healthcare

☁️ SaaS

🔌 API

AI Security Engineer securing Interra Health’s AI/ML models, data pipelines, and applications. Building guardrails and responding to AI security risks in healthcare technology.