Verified current Job

Security Engineer

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineer based in United States.

Job Remote Full source details
Jobgether Source published Sep 30, 2026 Verified 1 hour ago
✓ 100% verification score · Source: jobgether (lever) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull-time
Work modeRemote / location-flexible

Overview

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineer based in United States.

Full job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineer based in United States. As a Security Engineer, you will take a hands-on role in protecting cloud infrastructure, applications, and customer data across a modern technology environment. You will identify and remediate vulnerabilities directly in application repositories and infrastructure code rather than simply documenting security findings. The role combines vulnerability management, detection engineering, cloud security, application security, and incident response. You will build and tune SIEM detections, strengthen AWS security controls, and respond directly to security incidents from investigation through remediation. Working within a small, senior, globally distributed security team, you will collaborate with engineering and business stakeholders across the organization. This remote U.S. opportunity is designed for an engineer who enjoys automation, solving complex security problems, and turning findings into measurable improvements.

Identify and remediate vulnerabilities across applications, infrastructure, and cloud environments by contributing directly to application repositories and Terraform code and driving fixes through deployment. Build, maintain, and tune security detections within a SIEM, reducing false positives and improving detection coverage while mapping capabilities to MITRE ATT&CK. Lead security incident response activities, including investigation, containment, evidence handling, root-cause analysis, and tracking remediation through completion. Harden AWS environments using services and controls including IAM, GuardDuty, Security Hub, Config, CloudTrail, KMS, Secrets Manager, VPC controls, and least-privilege access. Strengthen security throughout the software delivery pipeline through code scanning, dependency management, secret scanning, container and image scanning, and Kubernetes admission controls. Automate repetitive security operations by developing workflows and scripts that support alert triage, enrichment, investigation, and remediation. Develop and maintain security runbooks, standards, detection documentation, and technical evidence supporting compliance requirements. Collaborate with engineering, sales, executive, and other cross-functional stakeholders to communicate security risks and drive practical remediation. Contribute to security programs supporting PCI DSS Level 1, GDPR, and SOC 2 requirements. Requirements: Bachelor's degree in a relevant field with 4 years of experience, or at least 6 years of practical experience in security engineering, detection engineering, or incident response. Strong programming skills and the ability to investigate unfamiliar application code, understand vulnerabilities, and implement fixes through pull requests. Deep hands-on AWS security experience, including IAM and least-privilege design, GuardDuty, CloudTrail, KMS, VPC controls, and securing containerized and serverless workloads. Practical experience with security detection engineering in a SIEM, including writing detection rules, tuning alerts, managing false positives, and evaluating detection coverage. Proven cloud incident response experience covering investigation, containment, evidence handling, root-cause analysis, and post-incident documentation. Strong application security fundamentals, including the OWASP Top 10, dependency and secrets management, and CI/CD security practices such as SAST, DAST, SCA, and infrastructure-as-code scanning. Strong written and verbal communication skills, with the ability to explain technical risks clearly and influence stakeholders through evidence and sound reasoning. Experience with Datadog Cloud SIEM, CrowdStrike, Okta, or GitHub Advanced Security is a plus. Experience supporting PCI DSS Level 1 or SOC 2 audits from an engineering perspective is a plus. Experience with Kubernetes, ArgoCD, policy-as-code, Python automation, or Terraform is a plus. Must be currently authorized to work in the United States without requiring employer sponsorship for a work visa. Benefits: Annual compensation range of $120,000–$150,000 USD, with flexibility to consider packages above this range based on skills and experience. Remote-first, remote-always working environment for U.S.-based employees. PTO in accordance with local labor requirements. Fully paid parental leave. Home office stipend based on country of residency. Professional development courses through Cloudbeds University. Access to professional development opportunities, including manager training, upskilling, and knowledge-sharing programs. Opportunity to work with a globally distributed team across 40+ countries. Hands-on exposure to modern cloud security, application security, detection engineering, and incident response practices.

Tips for this job

Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v3

Original authoritative source

JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Apply through JobOpportunity →

Browse current JobOpportunity listings from jobgether (lever) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books