Verified current Job

Staff Security Engineer (Blue Team)

Olo is a leading SaaS platform accelerating digital transformation in the restaurant industry, by helping customers deliver more personalized and profitable guest experiences. As a

Job Remote Full source details
Olo NYC, NYC or Remote Source published Sep 20, 2026 Verified 14 hours ago
✓ 100% verification score · Source: Olo (lever) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull-Time
Work modeRemote / location-flexible

Overview

Olo is a leading SaaS platform accelerating digital transformation in the restaurant industry, by helping customers deliver more personalized and profitable guest experiences. As a

Full job description

Olo is a leading SaaS platform accelerating digital transformation in the restaurant industry, by helping customers deliver more personalized and profitable guest experiences. As a result, our digital ordering, payment, and guest engagement solutions enable brands to do more with less and make every guest feel like a regular.

Reporting to the Security Engineering Director, the Staff Security Engineer will act as technical lead of the Olo Security Blue Team and work on security defences that allow our systems to keep running while protecting the data of our clients and their customers.

Additionally, you will help in the identification and prioritization of future project initiatives based on risk and execute on cross-functional projects with a high degree of ownership and excellence, all while actively mentoring other team members and elevating the collective team’s capabilities and skill sets. If you are passionate about reducing risk while supporting innovation we encourage you to apply!

You can work remotely from anywhere in the U.S. or at Olo's headquarters in NYC.

Guide and coach Olo’s Blue Team on Information Protection, Incident Detection and Response and Service Delivery.

You will provide strategic and technical oversight to the team and the program.

Technically lead a team of security engineers and analysts who hunt, detect, and respond to internal and external threats.

Collaborate with customers and partners to strengthen their security posture.

Drive ongoing optimizations by implementing new technologies, replacing technologies, addressing evolving threats, scaling practices and automating security activities.

Ultimately you will keep team member and customers data safe by identifying and mitigating vulnerabilities and risks by providing actionable guidance to product teams.

Lead Olo’s Information Protection program including the selection, testing, implementation and maintenance of security tools and services, security awareness, service provider management and the ongoing testing of those controls.

Oversee Vulnerability Management program including vulnerability assessments, risk scoring and vulnerability resolution.

Oversee Threat Hunting program to detect and mitigate advanced threats.

Manage non-event driven security reviews, including concept reviews, design reviews, patching, firewall rules and system configuration checks.

Apply Web application and API security principles and techniques, such as zero trust, RBAC, authentication, authorization, auditing, rate limiting, challenges, etc., to protect our cloud-based services from unauthorized access and abuse.

Oversee Incident Detection and Response program including ownership of incident response processes, tools and services and the ongoing continuous improvement of those controls.

Coordinate the detection and response to attacks through all incident phases.

Ensure incident reports are accurate, detailed and relevant.

Monitor, detect, and remediate misconfigurations and security risks across our cloud environments.

Participate in a 24/7 on-call rotation.

Oversee Security Services program including security support requests, risk assessments, vendor assessments, PCI and SOC audit support and service provider management.

5+ years of Security Engineering, Security Operations or Security Architecture experience.

CISSP, GCIH or similar certification preferred.

Experience acting as technical lead to distributed teams consisting largely of remote engineers.

Experience complying with PCI-DSS and other compliance and regulatory standards.

Experience with attacker tactics, techniques and procedures.

Knowledge of information technology, evolving threats, attack patterns, incident response and cyber security standards.

Experience developing and leading incident response, remediation and mitigation activities, and providing status updates and reports.

Experience analyzing security events to discern events that qualify as a legitimate security incident as opposed to non-incidents (ie. incident investigation, implementing countermeasures, and conducting incident response).

Deep understanding of operating system, networking and application concepts.

Experience hardening Windows, MacOS, Linux Containers and Kubernetes.

Familiarity with AWS security best practices and Infrastructure-as-Code.

Experience deploying and maintaining security technologies. (e.g. Access Proxies, API Gateway, Anti-Malware, Application Control, Cloud Security Posture, Data Leak Prevention, Data Mapping, Endpoint Detection & Response, Intrusion Detection System, File Integrity Monitoring, Firewalls, Mobile Device Management, Multi Factor Authentication, SIEM, Static Inspection, Vulnerability Assessment, Web Proxies, WAF and Zero Trust).

Adept at working with internal Product & Engineering, Legal, People & Culture, Finance and GTM teams and external partners, auditors and customers.

Ability to work during critical incidents or to support coverage requirements.

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v2

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Olo (lever) ↗

Browse current Job and Scholarship listings from Olo (lever) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books