Post job

Senior Security Engineer jobs at SoundCloud

- 216 jobs
  • Senior Cloud Security Engineer

    Vercel 4.1company rating

    Remote

    Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, and Under Armour build for the AI-native web. Our mission is to enable the world to ship the best products. That starts with creating a place where everyone can do their best work. Whether you're building on our platform, supporting our customers, or shaping our story: You can just ship things. About the role: We are looking for a Senior Cloud Security Engineer to join our Security Engineering team. You'll lead hands on efforts to harden our platform and ensure that infrastructure security is foundational to how we build and scale. Your work will strengthen the security posture of our core systems while enabling fast, secure growth across the company. You will report to the Security Operations Manager and can be located remotely. What you will do: Design and implement scalable security controls across our cloud-native platform. Harden infrastructure components using infrastructure-as-code, policy enforcement, and service isolation. Build secure by default infrastructure and code CI/CD pipelines. Collaborate with platform and infrastructure teams to integrate security best practices into architecture and workflows. Stay ahead of cloud security trends and adopt cutting-edge technologies to enhance platform resilience. Conduct threat modeling, risk analysis, and mitigation planning for critical systems. Drive improvements in monitoring, detection, and incident response at the platform level. Build, deploy and maintain relevant tooling. About you: 8+ years of experience in infrastructure or platform security roles. Deep understanding of secure cloud infrastructure (AWS/GCP), identity and access management, and system hardening. Proficient with tools like Terraform, CDK, Kubernetes, and CI/CD security. Skilled at balancing engineering realities with principled security practices. Proven track record of shipping secure, resilient systems at scale. Bonus if you: Have built or scaled security automation pipelines. Contributed to open-source security projects or tools. Hold certifications such as GCP Security Engineer, AWS certifications, CISSP, or OSCP. Hold a bachelors or masters degree in Cybersecurity or similar disciplines. Benefits: Competitive compensation package, including equity. Inclusive Healthcare Package. Learn and Grow - we provide mentorship and send you to events that help you build your network and skills. Flexible Time Off. We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed. The San Francisco, CA base pay range for this role is [$196,000.00 - $294,000.00]. This salary range is an estimate. Actual salary will be based on job related skills, experience and location. Pay ranges outside San Francisco may be adjusted based on employee location. The total compensation package also includes benefits and equity-based compensation. Your recruiter can share more about the specific pay range for your location during the hiring process.
    $196k-294k yearly Auto-Apply 27d ago
  • Senior Engineer, App Security

    Healthie 4.1company rating

    Remote

    Our Mission We're building infrastructure for modern healthcare delivery Traditional healthcare is plagued with outdated, monolithic EHRs designed to maximize billing outcomes. Patient outcomes and provider experiences have been afterthoughts, as these systems have bolted on non-API-first solutions. None of this is built for how clinically excellent healthcare is actually delivered-longitudinally and collaboratively, with the patient at the center. Healthie is the world's leading API-first, ONC-Certified EHR for healthcare delivery outside of the hospital. We provide the powerful infrastructure every scaling organization needs-EHR, scheduling, patient engagement, billing, and more-all accessible via modern APIs and a white-labeled UI. Our platform makes it simple for organizations of any size to launch, customize, and scale their care delivery models without reinventing the wheel. Today, over 1 billion API calls are made to Healthie every month, as thousands of organizations-working with more than 13 million patients in total-rely on Healthie to deliver care across a spectrum of specialties, from preventative health and wellness to complex chronic care management. We believe in the power of technology to improve access to healthcare-and we're building the rails that make this a reality. We work fast and with quality because we provide business-critical, healthcare-critical software that clinicians and patients need for a better healthcare system. We're customer-obsessed, operate with lightning-fast processes and responses, make our product roadmap public so customers can see what we're building, and remain relentlessly focused on how care gets delivered. Healthie is backed by leading investors, and while we've $42M raised to date, more importantly, we operate with fiscal responsibility and have been profitable for more than half of our time as a company. Learn more at **************************** About the role We are hiring a Senior Application Security Engineer to join our Platform Engineering team at Healthie! In this role, you will serve as a security and technical contributor, responsible for safeguarding our application layer and driving security best practices across the engineering organization. You'll partner closely with platform, infrastructure and core engineering teams to design secure-by-default systems, embed security into our SDLC, and proactively identify and remediate vulnerabilities in our code and cloud infrastructure. This is a hands-on role, ideal for someone who is excited to contribute to security programs in a fast-moving startup environment and help shape the future of security at Healthie. As our first dedicated AppSec hire, you'll have the opportunity to continue to refine our secure development lifecycle, influence architectural decisions, and champion a culture of security awareness across the company. If you're passionate about building impactful systems, driving innovation, and making a difference in healthcare - we'd love to hear from you. Details, details This is a full-time, remote position located in the United States The base salary for this role is $180,000 - $200,000 per year plus equity & company bonus, benefits U.S. work authorization is required and Healthie does not provide sponsorship. What You'll Do Design and implement secure coding standards and tooling for application-layer security Conduct threat modeling and secure design reviews; manage ethical hacker program and third-party vulnerability reports Lead regular code reviews, internal audits, and dynamic/static analysis efforts Proficient at performing internal pentests Contribute to the definition and design of Healthie's secure development lifecycle (S-SDLC), including integration of security into CI/CD workflows Administer, configure, and maintain Semgrep and other static and dynamic application security testing (SAST/DAST) tools to ensure continuous and effective code security Partner with Engineering and Product teams to triage and remediate vulnerabilities quickly and safely Build incident response playbooks for application-layer threats and support security investigations Help build and promote a security champions program Help ensure Healthie remains compliant with relevant standards (e.g., HIPAA, SOC 2, GDPR) from a software security perspective About You 5+ years of experience in application or product security roles, preferably in high-growth, cloud-native environments Deep understanding of web application security, secure architecture patterns, and common vulnerabilities (e.g., OWASP Top 10, CIS controls, SANS Secure Coding Practices, etc.) Strong background in secure software development practices, particularly in GraphQL, Ruby on Rails, React, or similar web frameworks Experience with DevSecOps practices and security tooling Experience building or maturing application-layer security programs, policies, or guidelines Comfortable working across cross-functional teams and influencing security decisions without formal authority You are mission-driven, passionate about healthcare, and motivated to build systems that improve patient safety and data integrity Bonus: Experience with healthcare-specific security practices and compliance audits (e.g., SOC 2, HIPAA) Interview Process Quick chat with Katie, Director of Talent or Aaron, Senior Technical Recruiter (20 minutes) Interview with Cavan, CTO + cofounder (20 minutes) Take Home Assessment - completed asynchronously Technical Interview with Chris and Andrew, Engineers for Platform (1 hour) Leadership Interviews: Interview with John N, VP Security & Compliance (30 minutes) Interview with John B, Distinguished Engineer (30 minutes) Reference checks To learn more about Working at Healthie & our benefits, click here . Healthie participates in e-verify Healthie is committed to equal employment opportunity. All qualified applicants will receive consideration for employment without regard to and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category. We're proud to be building a diverse and inclusive environment that encourages collaboration, creativity, and growth. Whatever your background, please apply if this is a role that would make you excited to come into work every day.
    $180k-200k yearly 28d ago
  • Senior Security Operations Engineer

    Brex 3.9company rating

    New York, NY jobs

    Why join us Brex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from startups to enterprises - including DoorDash, Flexport, and Compass - use Brex to proactively control spend, reduce costs, and increase efficiency on a global scale. Working at Brex allows you to push your limits, challenge the status quo, and collaborate with some of the brightest minds in the industry. We're committed to building a diverse team and inclusive culture and believe your potential should only be limited by how big you can dream. We make this a reality by empowering you with the tools, resources, and support you need to grow your career. Engineering at Brex Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level - from architecture to deployment. It's an environment where engineering is a craft, and builders become leaders. What you'll do As a Security Operations Engineer at Brex, you will focus on preventing, detecting and responding to security threats across Brex's corporate and cloud environments. You will use existing systems and develop tools to improve our security capabilities. Our team is responsible for functions across corporate security, detection & response and infrastructure security domains; and we perform systems engineering and automation to support those functions. Security Operations is part of our wider Trust & IT organization which means you will have the opportunity to work closely with Application Security, Corporate Engineering, GRC and IT and to improve security configurations, drive positive employee behaviors and generally work to prevent events from becoming incidents. You will also help build and maintain our team's open source project Substation and have the opportunity to contribute to the Brex Tech Blog. You'll be part of a team that actively contributes to the wider security community and has a commitment to mentorship and engineering excellence. We're looking for individuals with a strong background and interest in detecting, responding to, and resolving security incidents and security challenges. You should be comfortable dealing with lots of moving pieces, changing priorities, and new technologies, while having a keen eye for detail. Most importantly, you should be enthusiastic about working with a variety of backgrounds, roles, and people across Brex. Building a world-class financial service requires world-class security. Where you'll work This role will be based in our New York office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of three coordinated days in the office per week, Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work! Responsibilities Work on a highly cross-functional team to prevent, detect and respond to security threats across Brex's corporate and cloud environments Perform security incident response, investigation, remediation, and documentation, participate in periodic threat hunting and security exercises Leading, scoping and building features, participate in designing, and maintaining tools and systems which support the team's domains - corporate security, detection & response and infrastructure security Collaborating and partnering with engineering and operations teams to drive remediation of security issues, while balancing prioritization of those security issues within SLA and teams' respective backlogs Caring about secure system design, valuing building things correctly, an understanding of a MVP approach and an empathetic mindset when working with others Requirements Bachelor's degree in Computer Science, Engineering or related field OR equivalent training / fellowship OR 5+ years work experience Experience working in a corporate security, detection & response or infrastructure security role with responsibilities for security alert triage and security incident response Familiarity with CI/CD systems and DevOps workflows (e.g. Buildkite, Flux, Git, Terraform) in cloud environments (e.g. AWS, Azure, GCP) Experience with deploying and maintaining some of the security services and tools owned by the team (e.g. - SIEM, data pipelines, SOAR, domain monitoring, endpoint tooling, email protection tooling, cloud security tools) While not primarily a development role, the team develops and maintains tools written in Go and Python, so experience with coding is required You thrive in a collaborative environment filled with a diverse group of people with different expertise and backgrounds. We currently have around 30 nationalities represented with more than ½ the company working in a country different from the one they grew up in. Bonus points Proficiency with Go and other programming languages Experience with securing distributed systems in AWS, cloud and Kubernetes environments Contributions to the wider technical community (open source, public research, mentorship, community organizing, blogging, presentations, etc) Compensation The expected salary range for this role is $192,000 - $240,000. However, the starting base pay will depend on a number of factors including the candidate's location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package. Please be aware, job-seekers may be at risk of targeting by malicious actors looking for personal data. Brex recruiters will only reach out via LinkedIn or email with a brex.com domain. Any outreach claiming to be from Brex via other sources should be ignored.
    $192k-240k yearly Auto-Apply 3d ago
  • Senior Security Operations Engineer

    Brex 3.9company rating

    San Francisco, CA jobs

    Why join us Brex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from startups to enterprises - including DoorDash, Flexport, and Compass - use Brex to proactively control spend, reduce costs, and increase efficiency on a global scale. Working at Brex allows you to push your limits, challenge the status quo, and collaborate with some of the brightest minds in the industry. We're committed to building a diverse team and inclusive culture and believe your potential should only be limited by how big you can dream. We make this a reality by empowering you with the tools, resources, and support you need to grow your career. Engineering at Brex Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level - from architecture to deployment. It's an environment where engineering is a craft, and builders become leaders. What you'll do As a Security Operations Engineer at Brex, you will focus on preventing, detecting and responding to security threats across Brex's corporate and cloud environments. You will use existing systems and develop tools to improve our security capabilities. Our team is responsible for functions across corporate security, detection & response and infrastructure security domains; and we perform systems engineering and automation to support those functions. Security Operations is part of our wider Trust & IT organization which means you will have the opportunity to work closely with Application Security, Corporate Engineering, GRC and IT and to improve security configurations, drive positive employee behaviors and generally work to prevent events from becoming incidents. You will also help build and maintain our team's open source project Substation and have the opportunity to contribute to the Brex Tech Blog. You'll be part of a team that actively contributes to the wider security community and has a commitment to mentorship and engineering excellence. We're looking for individuals with a strong background and interest in detecting, responding to, and resolving security incidents and security challenges. You should be comfortable dealing with lots of moving pieces, changing priorities, and new technologies, while having a keen eye for detail. Most importantly, you should be enthusiastic about working with a variety of backgrounds, roles, and people across Brex. Building a world-class financial service requires world-class security. Where you'll work This role will be based in our San Francisco office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of three coordinated days in the office per week, Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work! Responsibilities Work on a highly cross-functional team to prevent, detect and respond to security threats across Brex's corporate and cloud environments Perform security incident response, investigation, remediation, and documentation, participate in periodic threat hunting and security exercises Leading, scoping and building features, participate in designing, and maintaining tools and systems which support the team's domains - corporate security, detection & response and infrastructure security Collaborating and partnering with engineering and operations teams to drive remediation of security issues, while balancing prioritization of those security issues within SLA and teams' respective backlogs Caring about secure system design, valuing building things correctly, an understanding of a MVP approach and an empathetic mindset when working with others Requirements Bachelor's degree in Computer Science, Engineering or related field OR equivalent training / fellowship OR 5+ years work experience Experience working in a corporate security, detection & response or infrastructure security role with responsibilities for security alert triage and security incident response Familiarity with CI/CD systems and DevOps workflows (e.g. Buildkite, Flux, Git, Terraform) in cloud environments (e.g. AWS, Azure, GCP) Experience with deploying and maintaining some of the security services and tools owned by the team (e.g. - SIEM, data pipelines, SOAR, domain monitoring, endpoint tooling, email protection tooling, cloud security tools) While not primarily a development role, the team develops and maintains tools written in Go and Python, so experience with coding is required You thrive in a collaborative environment filled with a diverse group of people with different expertise and backgrounds. We currently have around 30 nationalities represented with more than ½ the company working in a country different from the one they grew up in. Bonus points Proficiency with Go and other programming languages Experience with securing distributed systems in AWS, cloud and Kubernetes environments Contributions to the wider technical community (open source, public research, mentorship, community organizing, blogging, presentations, etc) Compensation The expected salary range for this role is $192,000 - $240,000. However, the starting base pay will depend on a number of factors including the candidate's location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package. Please be aware, job-seekers may be at risk of targeting by malicious actors looking for personal data. Brex recruiters will only reach out via LinkedIn or email with a brex.com domain. Any outreach claiming to be from Brex via other sources should be ignored.
    $192k-240k yearly Auto-Apply 3d ago
  • Senior Security Engineer (Remote)

    Lightning Labs 3.9company rating

    Remote

    Lightning Labs is seeking to hire a Security Engineer for the ongoing scaling of our growing engineering organization. This is a hands-on role that consists of devising and implementing policies and procedures around best practices in systems security. The ideal candidate has experience in securing web, Bitcoin, and other public-facing network services, penetration testing, and both automated and manual source code security reviews. Due to the domain in which we work, experience with Bitcoin and the Lightning Network is extremely desirable as is knowledge of the cryptographic aspects involved in this area. As we are an international organization, experience and comfort working with highly distributed teams is a must. In addition, the ideal candidate should have a passion for our mission of bringing financial freedom to the world, as well as for Bitcoin as a whole. Although a part of the engineering organization, candidates in this position will work across functional team boundaries to ensure all aspects of the business are appropriately considered and covered by security best practices. Responsibilities may include but are not limited to: Designing and deploying active fuzzing, black+white box testing and penetration testing infrastructure for open source and production systems Performing security audits and review of both internal production systems as well as open source software which interacts with Bitcoin+Lightning in a security critical manner Provide mentorship and guidance to level up your teammates Creating global security policy, standards, guidelines, and procedures to ensure ongoing maintenance of security Overseeing security aspects of software release processes and infrastructure Determining security team requirements for future growth Developing and ensuring responsiveness of security incident management processes Performing risk management assessments Preferred experience: At least 5 years prior experience in in systems security An ability to work with a high impact, fast-moving startup team Extensive knowledge of operating system and computer architecture internals Strong understanding of cryptography, protocol design and adversarial analysis Experience in reverse engineering and exploiting of cryptographic protocol (cryptocurrencies like Bitcoin) systems Extensive expertise with professional software development experience in Go, Rust, C/C++, and/or Java Experience in security incident response Experience in security code review and vulnerability triaging Prior experience running an open source facing bug bounty program 2+ years management experience or experience as a senior decision maker Experience working with remote teams Experience working with Kubernetes and AWS infrastructure Working knowledge of fundamental Bitcoin and Lightning design principles Candidates with additional experience are welcome to apply as we are open to adjusting the role accordingly
    $112k-157k yearly est. Auto-Apply 60d+ ago
  • Senior Security Engineer I/II

    Spothero 4.2company rating

    Chicago, IL jobs

    Who we are: At SpotHero, we work as a team to empower people to get everywhere, easier! We're rapidly growing with the mission of bringing the parking industry into the future through technology. Drivers across the nation use the SpotHero mobile app and website to reserve convenient, affordable parking in advance, on-the-go or through their connected cars, and parking companies rely on us to help them reach new customers while optimizing their business. We connect the dots with cutting-edge technology, delivering value to both sides of this exciting, evolving marketplace. We've been quite busy, take a peek at some of our recent announcements. Senior Security Engineer I/II at SpotHero: SpotHero is looking for a Senior Security Engineer I to build and lead our Application Security Program. This role involves close collaboration with engineering teams and product managers to integrate security throughout the entire product development lifecycle. What you'll do Conduct security-focused architecture, design, and code reviews. Direct threat modeling and penetration testing exercises. Lead the Security Champions program, empowering developers across teams to act as security advocates and fostering a culture of security awareness and best practices within the organization. Document security guidance and secure coding best practices and provide training to the engineering organization. Collaborate with customers, external security researchers, and developers to understand, document and assist in remediating reported vulnerabilities. Contribute to the Vulnerability Management Program through the deployment and operationalization of security analysis tools. Assist in responding to security incidents. What we're looking for 5+ years of experience as a security engineer, demonstrating in-depth knowledge of application security principles, secure coding practices, and vulnerability management. Proven ability to manage and prioritize security projects effectively. Proficiency in developing and debugging in at least one programming language. Experience conducting or participating in threat modeling and web/mobile application penetration testing. Excellent communication skills, with the ability to effectively communicate complex security concepts to technical and non-technical audiences and collaborate with cross-functional teams. Familiarity with cloud security controls and best practices. Experience with Amazon Web Services (AWS) is preferred but not required. Nice to have Security certifications such as Offensive Security Certified Professional (OSCP), Certified Secure Software Lifecycle Professional (CSSLP), or similar. Tech you'll work with Security analysis tools such as Semgrep or Docker Scout Languages: Python/Django, Go, Kotlin, Java, React/Redux Infrastructure: AWS, Kubernetes, Terraform Why SpotHero? We're a marketplace making parking easier for drivers and more efficient for garage operators. You'll join a team that values curiosity, ownership, and continuous learning and a culture that emphasizes impact, relationships, and adaptability. Seeking Candidates in: Illinois | Colorado | Washington D.C. | Florida | Indiana | Maryland | Michigan | New York | Pennsylvania | Texas | Washington | Wisconsin 100% remote What we are offering: Career game changer - A truly unique experience to work for a fast-growing startup in a role with unlimited growth potential. Excellent benefits We cover a generous portion of Medical Premiums, 50% of Dental and Vision Premiums, company-sponsored Life Insurance, a 401(k) with match and immediate vesting, and comprehensive leave policies to meet your needs in creating space for life" Canada: We offer Medical (prescription drug and paramedical coverage), Dental, Vision, Life Insurance, STD and LTD. Flexible PTO policy and outstanding work/life balance - We value and support each individual team member. Grubhub weekly lunch stipend for in office days (SkipTheDishes for Canada) Udemy and Personal Learning Budget - We support the professional and personal growth of our people by providing everyone with learning resources and development opportunities. Annual parking stipend - Duh. We help people park! The opportunity to collaborate with fun, innovative, and passionate people in a casual yet highly productive atmosphere. Our commitment to allyship has been a central driver of how we Respect Fellow Drivers. You'll have the opportunity to be part of Employee Resource Groups, access allyship learning resources, and actively contribute to our ongoing effort of making SpotHero inclusive for all. Employee programs to grow and support our people such as Discovery Days for Product and Engineering, Gearing up for Aspiring Leaders, and Mentorship Program. A workplace recognized as CityLights award winner by 1871, 2025 Best Places To Work by BuiltIn, Most Loved Workplace Certified by the Best Practice Institute, and recipient of multiple Comparably awards, including Best Company Culture, Best Company for Women, and Best Company for Diversity. Compensation: Depending on your skillset and experience, you can expect your base salary to be between $104,000 - $150,000 as well as a discretionary bonus and leading total rewards package including stock options. At SpotHero, we Respect Fellow Drivers by providing an inclusive interview experience for everyone, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process. Please let our team know of your need when you apply or as you begin interviewing with our team. SpotHero is an equal opportunity employer. We know that a diverse workforce is the strongest workforce, and are committed to building and supporting an inclusive environment for all. Additionally, because we want to Remember to Signal, if you choose to provide us personal information in connection with a job application, please review our Applicant Privacy Notice which provides details about what information we collect and process about you in order to consider your candidacy. PLEASE NOTE: This position is ineligible for visa sponsorship. To be considered for this role, you must be legally authorized to work in the US or Canada and not require sponsorship for employment now or in the future.
    $104k-150k yearly Auto-Apply 60d+ ago
  • Senior Offensive Security Engineer

    Astranis 3.9company rating

    San Francisco, CA jobs

    Astranis builds advanced satellites for high orbits, expanding humanity's reach into the solar system. Today, Astranis satellites provide dedicated, secure networks to highly-sophisticated customers across the globe- large enterprises, sovereign governments, and the US military. With five satellites on orbit and many more set to launch soon, the company is servicing a backlog of more than $1 billion of commercial contracts. Astranis is the preferred satellite communications partner for buyers with stringent requirements for uptime, data security, network visibility, and customization.Astranis has raised over $750 million from some of the world's best investors, from Andreessen Horowitz to Blackrock and Fidelity, and employs a team of 450 engineers and entrepreneurs. Astranis designs, builds, and operates its satellites out of its 153,000 sq. ft. headquarters in Northern California, USA. Senior Offensive Security Engineer As a Senior Offensive Security Engineer, you will lead penetration testing and adversarial simulation efforts targeting our applications, cloud infrastructure, and corporate networks. You will emulate real-world attackers to identify weaknesses across the software and IT stack, and work closely with engineering and IT teams to improve our defenses. Your focus is offensive testing of application and enterprise systems. Role: Offensive & Penetration Testing (Primary) Perform penetration tests of web apps, APIs, backend services, cloud infrastructure, and corporate networks. Conduct threat emulation exercises, red-team scenarios, and targeted attack simulations. Assess CI/CD pipelines, IAM configurations, and internal services for exploitable weaknesses. Lead offensive security initiatives and serve as the organization's primary expert for AppSec and enterprise pentesting. Security Research & Adversarial Analysis Track emerging threats, techniques, and vulnerabilities relevant to cloud and enterprise environments. Develop custom exploits or proof-of-concepts as needed to validate findings. Collaboration & Remediation Support Work with development, infra, and IT teams to validate controls and guide effective remediation. Provide actionable risk assessments from an attacker's perspective. Contribute offensive insights to secure system design guidance. General Product Security Support (Secondary) Assist with code review and threat modeling for software components when offensive insights are needed. Requirements: 5+ years of hands-on offensive security experience (AppSec, cloud, or enterprise penetration testing). Demonstrated experience leading complex penetration tests for web apps, APIs, and cloud platforms. Strong proficiency in offensive tooling (Burp Suite, Nmap, Metasploit, proxy tools, etc.) and manual testing techniques. Familiarity with cloud-native attack vectors (AWS/Azure/GCP). Proficiency in at least one scripting or exploitation-oriented language (Python, Go, JavaScript, etc.). Strong analytical and problem-solving skills with an attacker's mindset. Ability to explain complex technical vulnerabilities to a range of audiences. What we offer: All our positions offer a compensation package that includes equity and robust benefits. Base pay is a single component of Astranis's total rewards package, which may also include equity in the form of incentive stock options, high quality company-subsidized healthcare, disability and life insurance benefits, flexible PTO, 401(K) retirement, and free on-site catered meals. Astranis pay ranges are informed and defined through professional-grade salary surveys and compensation data sources. The actual base salary offered to a successful candidate will additionally be influenced by a variety of factors including experience, credentials & certifications, educational attainment, skill level requirements, and the level and scope of the position. Base Salary$160,000-$240,000 USDU.S. Citizenship, Lawful Permanent Residency, or Refugee/Asylee Status Required (To comply with U.S. Government space technology export regulations, applicant must be a U.S. citizen, lawful permanent resident of the United States, or other protected individual as defined by 8 U.S.C. 1324b(a)(3)) Our mission and our products are meant to connect the world and everyone in it, regardless of gender, race, creed, or any other distinction. We believe in a diverse and inclusive workplace, and we encourage all people to join our team and bring their unique perspective to help make us stronger.
    $160k-240k yearly Auto-Apply 3d ago
  • Product Security Engineer

    Airtable 4.2company rating

    Remote

    Airtable is the no-code app platform that empowers people closest to the work to accelerate their most critical business processes. More than 500,000 organizations, including 80% of the Fortune 100, rely on Airtable to transform how work gets done. Join Airtable as a Product Security Engineer and play a pivotal role in shaping the security of our rapidly evolving platform. You will partner closely with product teams to ensure our products are secure by design, drive impactful security programs, and build production-ready code that safeguards our users. This is a unique opportunity to influence application security at scale as we expand our AI and LLM-powered offerings. What you'll do Partner with product teams to review product plans, designs, and code for security considerations Lead and implement programs that raise the bar for application and product security across the organization Build and ship frameworks that make it easy for product engineers to ship secure code Triage and drive remediation for findings from external penetration testers Research emerging threats and evolving best practices, especially in AI and LLM safety, and educate the rest of Engineering about your findings. Work with our advisors and third party vendors on penetration tests, security reports and compliance projects. Contribute to roadmaps, metrics and and strategic planning for the product security team Who you are 2+ years experience in product security and application security, with some experience shipping production code Skilled at conducting in-depth security reviews and collaborating with engineering teams Proficient in writing clean, maintainable code Hands-on experience with AI product security for LLM-powered products Strong communicator and collaborator, able to drive security initiatives and foster trust with partner teams You excel at communicating analyses of technical issues and recommendations for addressing them. Comfortable making systems as well as breaking them; you enjoy both building controls and finding gaps Familiar with JavaScript or TypeScript, Node, Linux, and AWS or comparable technologies, and can reason about the security implications of systems built on them Comfortable working in a fast-paced environment and contributing to long-term security strategy Airtable is an equal opportunity employer. We embrace diversity and strive to create a workplace where everyone has an equal opportunity to thrive. We welcome people of different backgrounds, experiences, abilities, and perspectives. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status or any characteristic protected by applicable federal and state laws, regulations and ordinances. Learn more about your EEO rights as an applicant. VEVRAA-Federal Contractor If you have a medical condition, disability, or religious belief/practice which inhibits your ability to participate in any part of the application or interview process, please complete our Accommodations Request Form and let us know how we may assist you. Airtable is committed to participating in the interactive process and providing reasonable accommodations to qualified applicants. Compensation awarded to successful candidates will vary based on their work location, relevant skills, and experience. Our total compensation package also includes the opportunity to receive benefits, restricted stock units, and may include incentive compensation. To learn more about our comprehensive benefit offerings, please check out Life at Airtable. For work locations in the San Francisco Bay Area, Seattle, New York City, and Los Angeles, the base salary range for this role is:$170,000-$277,000 USD Please see our Privacy Notice for details regarding Airtable's collection and use of personal information relating to the application and recruitment process by clicking here. 🔒 Stay Safe from Job Scams All official Airtable communication will come from an @airtable.com email address. We will never ask you to share sensitive information or purchase equipment during the hiring process. If in doubt, contact us at ***************. Learn more about avoiding job scams here.
    $170k-277k yearly Auto-Apply 20d ago
  • Senior Security Engineer, Application Security

    Postman 4.0company rating

    San Francisco, CA jobs

    Who Are We? Postman is the world's leading API platform, used by more than 40 million developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration-enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. What You'll Do Mentor junior security engineers and security champions on security best practices and techniques. Improve our security tooling and processes. Conduct security talks and training sessions. Identify critical flaws and weaknesses in our web applications, services and our cloud infrastructure then design and implement strategic solutions to remediate them. Write and review technical proposals, architectural diagrams, application code and IaC. Use automated and manual testing techniques to gain a better understanding of the environment and reduce false negatives. Reduce manual security review efforts by improving our tooling and processes. Improve the scope of our assessments by adding new techniques and new categories of vulnerability assessments. Consolidate and track vulnerabilities across our organization and our supply chain to assist in identifying areas to focus our security uplift efforts. Review and define requirements for developing and deploying secure products; create guidelines and standards to meet these requirements. Work closely with the team to build systems that protect against and eradicate entire classes of vulnerabilities. About You Experience working as a Senior Security Engineer with deep involvement in securing modern web Applications and APIs. Experience conducting threat modeling, security reviews and risk assessments. Solid project management experience leading initiatives that have measurably improved the security of organizations. Proficient in one or more high-level programming languages. Proficient with common developer tools and processes such as Github, CI/CD, containers and orchestration, IaaS/PaaS, APIs, Websockets, Databases, Front-End and Back-End systems. Experience securing Data to meet various privacy framework and regulation requirements. Deep understanding and experience in securing AWS environments. Experience in deploying AppSec tools (e.g., SAST, SCA, WAF etc) throughout the stages of the SDLC to ensure the most relevant vulnerabilities are surfaced and false positives are kept to a minimum. Understanding of web security mechanisms (such as SOP, CORS, CSP, Subresource Integrity, and same-site cookies). Strong understanding of various authentication/authorization protocols e.g. OAuth, SAML and JWT The reasonably estimated base salary for this role ranges from $210,000 to 240,000, plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. What Else? In addition to Postman's pay-on-performance philosophy, and a flexible schedule working with a fun, collaborative team, Postman offers a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Along with that, our wellness programs will help you stay in the best of your physical and mental health. Our frequent and fascinating team-building events will keep you connected, while our donation-matching program can support the causes you care about. We're building a long-term company with an inclusive culture where everyone can be the best version of themselves. At Postman, we embrace a hybrid work model. For all roles based out of San Francisco Bay Area, Boston, Bangalore, Hyderabad, and New York, employees are expected to come into the office 3-days a week. We were thoughtful in our approach which is based on balancing flexibility and collaboration and grounded in feedback from our workforce, leadership team, and peers. The benefits of our hybrid office model will be shared knowledge, brainstorming sessions, communication, and building trust in-person that cannot be replicated via zoom. Our Values At Postman, we create with the same curiosity that we see in our users. We value transparency and honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can. Equal opportunity Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.
    $210k-240k yearly Auto-Apply 39d ago
  • Senior Security Engineer - AppSec

    Pave 4.5company rating

    San Francisco, CA jobs

    Who We Are At Pave, we're building the industry's leading compensation platform, combining the world's largest real-time compensation dataset with deep expertise in AI and machine learning. Our platform is perfecting the art and science of pay to give 8,500+ companies unparalleled confidence in every compensation decision. Top tier companies like OpenAI, McDonald's, Instacart, Atlassian, Synopsys, Stripe, Databricks, and Waymo use Pave, transforming every pay decision into a competitive advantage. $190+ billion in total compensation spend is managed in our workflows, and 70% of Forbes AI 50 use Pave to benchmark compensation. The future of pay is real-time & predictive, and we're making it happen right now. We've raised $160M in funding from leading investors like Andreessen Horowitz, Index Ventures, Y Combinator, Bessemer Venture Partners, and Craft Ventures. The Research & Development Org Pave's R&D pillar includes our data science, engineering, information technology, product design, product management, and security teams. This organization builds, maintains, and secures a platform used by more than 8,500+ client organizations. Compensation strategy is broken down into 3 pillars - compensation bands, planning workflows, and total rewards communication. We build products that make these processes seamless for customers. Over the next year, our roadmap is focused on enhancing the entire compensation lifecycle: from philosophy definition to market trend analysis, band adjustments, merit cycles, and employee communication. We're seeking passionate engineers who are excited about building robust, data-rich systems that simplify complex compensation processes at scale. Learn more about our engineering principles here! Security Team @ Pave Security is part of everything we do at Pave. With amazing growth comes amazing engineering and security challenges. This is an opportunity to have a huge impact and run programs at a company that doesn't need to be convinced why security is important. Our customers count on us to secure some of their most sensitive data, and that trust is central to Pave. It's the only way we can unlock a labor market built on trust, and change the world of compensation. What You'll Bring 5+ years of application security experience as part of a blue team Expert knowledge of OWASP Top 10 and application security Security design review experience Experience in running bug bounty programs and pentesting Outstanding communication and partnership skills with software engineers Ideally, experience in Google Cloud Security best practices Our stack includes: TypeScript, Node.js, MySQL, Prisma, and React, hosted on GCP Compensation, It's What We Do. Salary is just one component of Pave's total compensation package for employees. Your total rewards package at Pave will include equity, top-notch medical, dental, and vision coverage, an unlimited PTO policy, and many other region-specific benefits. Your level is based on our assessment of your interview performance and experience, which you can always ask the hiring manager about to understand in more detail. This salary range may include multiple levels. The targeted cash compensation for this position is (level depends on experience and performance in the interview process): P4: $205,700 - $278,300 Life @ Pave Since being founded in 2019, Pave has established a robust global footprint. Headquartered in San Francisco's Financial District, we operate strategic regional hubs across New York City's Flatiron District, Salt Lake City, and the United Kingdom. We cultivate a vibrant, collaborative workplace culture through our hybrid model, bringing teams together in-person on Mondays, Tuesdays, Thursdays, and Fridays to foster innovation and strengthen professional relationships Benefits @ Pave At Pave, career advancement drives everything-roles expand, responsibilities deepen, and compensation rises alongside your professional growth. What we provide Complete Health Coverage: Comprehensive Medical, Dental and Vision coverage for you and your family, with plenty of options to suit your needs Time off & Flexibility: Flexible PTO and the ability to work from anywhere in the world for a month Meals & Snacks: Lunch & dinner stipends as well as fully stocked kitchens to fuel you Professional Development: Quarterly education stipend to continuously grow Family Support: Robust parental leave to bond with your new family Commuter Assistance: A commuter stipend to help you collaborate in person Vision - Our vision is to unlock a labor market built on trust Mission - Our team's mission is to build confidence in every compensation decision Are you ready to help our customers make smarter, more effective compensation decisions?
    $205.7k-278.3k yearly Auto-Apply 45d ago
  • Senior Security Engineer

    Qualified.com, Inc. 3.8company rating

    San Francisco, CA jobs

    Qualified is the Agentic Marketing Platform for B2B companies. With Piper the AI SDR Agent, Qualified offers a whole new way to grow inbound pipeline. Piper operates across both the website and email, working to engage website visitors, capture leads, and convert buyers into pipeline around the clock. Hundreds of the world's leading brands-including Crunchbase, Asana, Box, and Grubhub-choose Qualified to increase lead conversions, generate more meetings, and improve efficiency within their inbound pipeline motion. Overview We're looking for a deeply experienced Senior Security Engineer to establish and lead our security engineering function as our first dedicated security engineer hire. You'll serve as the security champion for our 50+ person engineering organization, partnering closely with our platform, infrastructure, and engineering leadership teams to mature and enhance our existing security posture. This is a foundational role where you'll have the opportunity to evolve our security strategy, strengthen existing security controls, and establish advanced security practices across our entire technology stack. You'll drive initiatives that protect our AI-powered platform, customer data, and business operations while enabling safe, high-velocity development. If you're passionate about building robust security programs, love solving complex security challenges, and enjoy elevating security awareness across engineering teams, this role is for you. What You'll Do 1. Evolve and Mature Security Practices: Build upon our existing security foundation by designing and implementing advanced security controls, policies, and practices that scale with our growth and align with industry best practices. 2. Drive Proactive Security Assessments: Systematically identify security vulnerabilities and weak points across our systems through threat modeling, security reviews, and risk assessments. Develop and execute comprehensive remediation roadmaps. 3. Partner with Corporate Security: Collaborate closely with our corporate security team to align technical security initiatives with broader organizational security policies, compliance requirements, and risk management objectives. 4. Secure the Platform & Infrastructure: Work hand-in-hand with our platform and infrastructure teams to harden cloud environments, implement security automation, and build security into our CI/CD pipelines and deployment workflows. 5. Implement Security Tooling & Monitoring: Deploy and manage security tools including SAST/DAST scanners, vulnerability management systems, security monitoring, and incident response capabilities. 6. Incident Response & Forensics: Lead security incident response efforts, conduct post-incident analysis, and continuously improve our security incident handling capabilities. What We're Looking For * 6+ years of software engineering experience with 3+ years in security engineering, application security, or infrastructure security roles, with proven experience building security programs at high-growth technology companies. * Deep cloud security expertise with AWS, Kubernetes, and cloud-native security tools. * Experience securing containerized environments. * Strong application security background including secure code review, vulnerability assessment, penetration testing, and familiarity with OWASP Top 10 and common attack vectors. * Infrastructure security experience with network security, identity and access management (IAM), secrets management, and security automation using infrastructure-as-code. * Strong communication and collaboration skills; able to translate complex security risks into business impact and work effectively with engineering teams to drive security improvements. * Regulatory and compliance knowledge with frameworks like SOC 2, ISO 27001, GDPR, and experience implementing technical controls to meet compliance requirements. Why Join Qualified Foundational Impact: As our first security hire, you'll mature our security program and directly shape how we approach advanced security practices across all aspects of our business. High-Growth Environment: Join us at a pivotal stage where you can establish security best practices that will scale with our rapid growth and expansion. Cutting-Edge AI Security: Work on unique security challenges related to AI driven products and help define security standards for B2B AI applications. Close Leadership Collaboration: Partner with leadership to ensure security is integrated into our strategic decision-making. Career Growth: Lead and grow the security function as we scale, with opportunities to build and manage a security team as the company expands. If you're ready to take on a high-impact role where you'll establish the security foundation for a fast-growing AI company and drive critical security initiatives from day one, we'd love to hear from you. About Qualified Qualified is the Agentic Marketing platform for B2B companies around the world. Headquartered in San Francisco, Qualified delivers pipeline generation at scale with Piper the AI SDR for thousands of customers like Crunchbase, Demandbase, Greenhouse, Plaid, and Suse. Led by former Salesforce CMO Kraig Swensrud and former Salesforce Product SVP Sean Whiteley, Qualified boasts 1100+ 5-star reviews on G2 and is ranked #1 on the Salesforce AppExchange. Qualified is funded by Sapphire, Tiger Global, Norwest Venture Partners, Redpoint Ventures, and Salesforce Ventures. Visit qualified.com to learn more. One Team We're all in this together with a shared goal: grow the business and each other. Work as a team, win as a team. Collaborate and strategize across departments to deliver A+ work. We are bold thought leaders that value creating a sense of belonging for all and celebrating our wins, big or small. Customer Obsessed Prioritize the customer above everything else. Build a product that our customers love. Establish ourselves as their trusted advisor and do "Whatever it takes" to make them successful. Prove the ROI. Only when our customers win do we win. Think Big & Move Fast We're defining a new category and we have fierce competition. Fast-paced innovation is the name of the game. We look forward. We reimagine. We throw out new ideas. We test things. We move quickly. We challenge the norm. We don't settle for status quo. On the heels of their Series C financing, Qualified is looking to grow the team so that they can do even more, even faster; they're focused on delivering our customers more innovation, additional services, an expanded product portfolio, and even deeper ties into the Salesforce CRM platform. Qualified is looking for folks that are fired up about joining a fast-paced, fast-growing company that is doing big things. Diversity & Inclusion Qualified is committed to bringing together individuals from different backgrounds and perspectives. We strive to create an inclusive environment where everyone can thrive, feel a sense of belonging, and do great work together. We are proud to be an equal opportunity employer open to all qualified applicants regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, Veteran status, or any other legally protected status.
    $140k-190k yearly est. 60d+ ago
  • Sr. Security Engineer, AppSec (AI/ML Security)

    6Sense 4.1company rating

    California jobs

    Our Mission: 6sense is on a mission to revolutionize how B2B organizations create revenue by predicting customers most likely to buy and recommending the best course of action to engage anonymous buying teams. 6sense Revenue AI is the only sales and marketing platform to unlock the ability to create, manage and convert high-quality pipeline to revenue. Our People: People are the heart and soul of 6sense. We serve with passion and purpose. We live by our Being 6sense values of Accountability, Growth Mindset, Integrity, Fun and One Team. Every 6sensor plays a part in defining the future of our industry-leading technology. 6sense is a place where difference-makers roll up their sleeves, take risks, act with integrity, and measure success by the value we create for our customers. We want 6sense to be the best chapter of your career. Senior Security Engineer - Application Security (AI Security Focus) Location: Bengalaru, India // Pune, India Reporting To: Manager, Security Engineering Function/Dept: Business Technology / Security About the Role You will drive platform security initiatives with a primary focus on securing AI/ML systems and models. You'll partner with engineering, product, and data science teams to ensure robust security for AI-powered features and infrastructure, while maintaining coverage for traditional AppSec domains. Responsibilities & Accountabilities * AI Security Leadership: Lead the design and implementation of security controls for AI/ML models, pipelines, and data flows. * Vulnerability Management: Ensure coverage of AI/ML and application vulnerabilities using SAST, DAST, dependency scanning, and specialized AI security tools. * Threat Modeling & Red Teaming: Conduct comprehensive threat modeling and AI/ML red teaming exercises, including prompt injection, jailbreaking, adversarial attack simulations, and vulnerability assessments for AI systems. Assess risks such as adversarial attacks, model theft, data poisoning, privacy risks, and other emerging threats to AI/ML models and pipelines. * Automation & Tooling: Build and maintain automation pipelines for AI/ML security testing and monitoring. * Cross-Functional Collaboration: Partner with Engineering, Product, and Data Science to embed security into AI/ML development lifecycles. * Incident Response: Support detection, triage, and remediation of AI/ML-specific security incidents. * Training & Advocacy: Facilitate secure development training focused on AI/ML risks and best practices. * Metrics & Reporting: Track and report status of vulnerabilities, including AI/ML-specific metrics (e.g., model robustness, data integrity). * Program Ownership: Design and execute quarterly OKRs for AI/ML security initiatives. Performance Measurement * Demonstrates deep understanding of AI/ML security risks and mitigations. * Leads identification, triage, and management of AI/ML and application security issues. * Establishes routines for updating documentation, runbooks, and dashboards with AI/ML security content. * Effectively communicates complex AI/ML security topics to technical and non-technical stakeholders. Educational and Experience Requirements * 5+ years in information security, with significant experience in application security and AI/ML security. * Hands-on experience securing AI/ML models, pipelines, and data within the AI/ML SDLC. · Familiarity with common AI/ML security threats (adversarial attacks, model inversion, data poisoning). * Experience with security tools for AI/ML (e.g., Adversarial Robustness Toolbox, MLFlow security plugins). * Development or scripting experience (Python preferred; experience with AI/ML frameworks a plus). * Excellent communication skills. Preferred Qualifications * Bachelor's degree in a related field. * Relevant certifications (e.g., AIRTP+, CAISF, Microsoft AI Security Fundamentals, AWS Certified Security - Specialty, GIAC, CISSP, CEH are highly desirable). * Experience working directly with software developers and data scientists to improve code/model security. Competencies and Behaviors * Establishes credibility among Engineering and Data Science counterparts. * Advocates for AI/ML security best practices. * Drives tasks to completion and maintains accuracy of information. * Effective prioritization and escalation to management. Our Benefits: Full-time employees can take advantage of health coverage, paid parental leave, generous paid time-off and holidays, quarterly self-care days off, and stock options. We'll make sure you have the equipment and support you need to work and connect with your teams, at home or in one of our offices. We have a growth mindset culture that is represented in all that we do, from onboarding through to numerous learning and development initiatives including access to our LinkedIn Learning platform. Employee well-being is also top of mind for us. We host quarterly wellness education sessions to encourage self care and personal growth. From wellness days to ERG-hosted events, we celebrate and energize all 6sense employees and their backgrounds. Equal Opportunity Employer: 6sense is an Equal Employment Opportunity and Affirmative Action Employers. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to ***************. We are aware of recruiting impersonation attempts that are not affiliated with 6sense in any way. All email communications from 6sense will originate from the @6sense.com domain. We will not initially contact you via text message and will never request payments. If you are uncertain whether you have been contacted by an official 6sense employee, reach out to ***************
    $132k-179k yearly est. Auto-Apply 60d+ ago
  • Senior Security Engineer, GRC (Governance, Risk and Compliance)

    6Sense 4.1company rating

    California jobs

    Our Mission: 6sense is on a mission to revolutionize how B2B organizations create revenue by predicting customers most likely to buy and recommending the best course of action to engage anonymous buying teams. 6sense Revenue AI is the only sales and marketing platform to unlock the ability to create, manage and convert high-quality pipeline to revenue. Our People: People are the heart and soul of 6sense. We serve with passion and purpose. We live by our Being 6sense values of Accountability, Growth Mindset, Integrity, Fun and One Team. Every 6sensor plays a part in defining the future of our industry-leading technology. 6sense is a place where difference-makers roll up their sleeves, take risks, act with integrity, and measure success by the value we create for our customers. We want 6sense to be the best chapter of your career. As members of 6sense's Security department, the Governance, Risk and Compliance (GRC) team aligns Security with business objectives while managing risks and meeting industry standards, regulations, and contractual obligations. GRC enforces governance, implements risk management strategies, and ensures compliance through operating as the second line of defense. Responsibilities & Accountabilities * All responsibilities of GRC Security Engineer III, and; * Execute on milestones for end-to-end GRC initiatives in accordance with the Security roadmap * Lead internal and external audit engagements * Oversee and execute complex control tests, third-party and operational security risk assessments, and communicate results across multiple audiences with varying levels of sensitivity * Develop issue and risk treatment plans with owners and test remediation for closure * Design high-quality test plans and improve security control test activities through peer reviews that provide feedback and guidance to other GRC Engineers * Provide GRC technology administration to include user training * Mature security governance, training, and awareness programs * Improve GRC handbook pages, procedures, and playbooks and maintain security program controlled documents * Design GRC control automation and implement security GRC-related automation tasks * Execute on quarterly individual Key Results that support team Objectives (OKRs) Performance Measurement * Maintains up-to-date knowledge of 6sense's product, environment, systems, and architecture * Actively prepares for weekly 1:1s with Manager and monthly skip levels * Drives remediation of security risks and threats * Adheres to strict deadlines and SLAs * Participates in creation of milestones associated with major security projects * Executes on milestones associated with major security projects * Develops and maintains up-to-date handbook pages, runbooks, workflows, and dashboards * Provides project status updates on a weekly basis * Administers GRC technology Educational and Experience Requirements * 5+ years of experience being part of a GRC or similar team * 1+ years of experience developing automation * Experience with security tools and cloud environments (e.g., GRC, Vulnerability Scanners, SIEM, SOAR, AWS) * Experience with industry frameworks, regulations, and standards, such as: ISO 27001, SOC 2, GDPR, PCI, SOX, NIST, etc. Preferred Qualifications * Big 4 (KPMG, Deloitte, PwC, EY) or similar experience * Bachelor's degree in a related field * Relevant industry certifications, such as CISSP, CISM, or GIAC, are highly desirable Competencies and Behaviors * Evangelizes security best practices * Works independently to maintain and improve overall company security posture * Collaborates with cross-functional teams * Translates technical requirements into actionable and timebound requests * Drives projects and tasks to completion by following up on questions, deadlines, and requests for input * Maintains accuracy of information * Proactive prioritization and escalation to management * Strong communication skills, including verbal, written, and presentation skills Our Benefits: Full-time employees can take advantage of health coverage, paid parental leave, generous paid time-off and holidays, quarterly self-care days off, and stock options. We'll make sure you have the equipment and support you need to work and connect with your teams, at home or in one of our offices. We have a growth mindset culture that is represented in all that we do, from onboarding through to numerous learning and development initiatives including access to our LinkedIn Learning platform. Employee well-being is also top of mind for us. We host quarterly wellness education sessions to encourage self care and personal growth. From wellness days to ERG-hosted events, we celebrate and energize all 6sense employees and their backgrounds. Equal Opportunity Employer: 6sense is an Equal Employment Opportunity and Affirmative Action Employers. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to ***************. We are aware of recruiting impersonation attempts that are not affiliated with 6sense in any way. All email communications from 6sense will originate from the @6sense.com domain. We will not initially contact you via text message and will never request payments. If you are uncertain whether you have been contacted by an official 6sense employee, reach out to ***************
    $132k-179k yearly est. Auto-Apply 40d ago
  • Senior Security Engineer, GRC (Governance, Risk and Compliance)

    6Sense 4.1company rating

    Indio, CA jobs

    Our Mission: 6sense is on a mission to revolutionize how B2B organizations create revenue by predicting customers most likely to buy and recommending the best course of action to engage anonymous buying teams. 6sense Revenue AI is the only sales and marketing platform to unlock the ability to create, manage and convert high-quality pipeline to revenue. Our People: People are the heart and soul of 6sense. We serve with passion and purpose. We live by our Being 6sense values of Accountability, Growth Mindset, Integrity, Fun and One Team. Every 6sensor plays a part in defining the future of our industry-leading technology. 6sense is a place where difference-makers roll up their sleeves, take risks, act with integrity, and measure success by the value we create for our customers. We want 6sense to be the best chapter of your career. As members of 6sense's Security department, the Governance, Risk and Compliance (GRC) team aligns Security with business objectives while managing risks and meeting industry standards, regulations, and contractual obligations. GRC enforces governance, implements risk management strategies, and ensures compliance through operating as the second line of defense. Responsibilities & Accountabilities * Execute on milestones for end-to-end GRC initiatives in accordance with the Security roadmap * Lead internal and external audit engagements * Oversee and execute complex control tests, third-party and operational security risk assessments, and communicate results across multiple audiences with varying levels of sensitivity * Develop issue and risk treatment plans with owners and test remediation for closure * Design high-quality test plans and improve security control test activities through peer reviews that provide feedback and guidance to other GRC Engineers * Provide GRC technology administration to include user training * Mature security governance, training, and awareness programs * Improve GRC handbook pages, procedures, and playbooks and maintain security program controlled documents * Design GRC control automation and implement security GRC-related automation tasks * Execute on quarterly individual Key Results that support team Objectives (OKRs) Performance Measurement * Maintains up-to-date knowledge of 6sense's product, environment, systems, and architecture * Actively prepares for weekly 1:1s with Manager and monthly skip levels * Drives remediation of security risks and threats * Adheres to strict deadlines and SLAs * Participates in creation of milestones associated with major security projects * Executes on milestones associated with major security projects * Develops and maintains up-to-date handbook pages, runbooks, workflows, and dashboards * Provides project status updates on a weekly basis * Administers GRC technology Educational and Experience Requirements * 5+ years of experience being part of a GRC or similar team * 1+ years of experience developing automation * Experience with security tools and cloud environments (e.g., GRC, Vulnerability Scanners, SIEM, SOAR, AWS) * Experience with industry frameworks, regulations, and standards, such as: ISO 27001, SOC 2, GDPR, PCI, SOX, NIST, etc. Preferred Qualifications * Big 4 (KPMG, Deloitte, PwC, EY) or similar experience * Bachelor's degree in a related field * Relevant industry certifications, such as CISSP, CISM, or GIAC, are highly desirable Competencies and Behaviors * Evangelizes security best practices * Works independently to maintain and improve overall company security posture * Collaborates with cross-functional teams * Translates technical requirements into actionable and timebound requests * Drives projects and tasks to completion by following up on questions, deadlines, and requests for input * Maintains accuracy of information * Proactive prioritization and escalation to management * Strong communication skills, including verbal, written, and presentation skills Our Benefits: Full-time employees can take advantage of health coverage, paid parental leave, generous paid time-off and holidays, quarterly self-care days off, and stock options. We'll make sure you have the equipment and support you need to work and connect with your teams, at home or in one of our offices. We have a growth mindset culture that is represented in all that we do, from onboarding through to numerous learning and development initiatives including access to our LinkedIn Learning platform. Employee well-being is also top of mind for us. We host quarterly wellness education sessions to encourage self care and personal growth. From wellness days to ERG-hosted events, we celebrate and energize all 6sense employees and their backgrounds. Equal Opportunity Employer: 6sense is an Equal Employment Opportunity and Affirmative Action Employers. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to ***************. We are aware of recruiting impersonation attempts that are not affiliated with 6sense in any way. All email communications from 6sense will originate from the @6sense.com domain. We will not initially contact you via text message and will never request payments. If you are uncertain whether you have been contacted by an official 6sense employee, reach out to ***************
    $128k-174k yearly est. Auto-Apply 40d ago
  • Senior Security Engineer, Cloud Infrastructure

    Klaviyo 4.2company rating

    San Francisco, CA jobs

    At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements. If you're a close but not exact match with the description, we hope you'll still consider applying. Want to learn more about life at Klaviyo? Visit careers.klaviyo.com to see how we empower creators to own their own destiny. As a Senior Security Engineer, you'll be a vital part of the Infrastructure Security Team, focusing on strengthening the security posture across Klaviyo's entire technology environment. Unlike roles with a narrowly defined specialty, this position offers the opportunity to demonstrate your unique expertise-whether that's in cloud security, identity and access management, data protection, secure systems design, or other security domains. Your work will involve evaluating and hardening our infrastructure, collaborating with cross-functional teams, and leveraging AI to build scalable solutions to address emerging threats. We are looking for someone who is excited to bring their specialized skills to the team, shaping Klaviyo's security practices and helping us continue to raise the bar. How You Will Make a Difference Secure Klaviyo's infrastructure by designing, implementing, and maintaining scalable security controls across cloud, on-prem, and hybrid environments Evaluate and improve security configurations and policies across a range of technologies, using your domain expertise to reduce risk and enable secure-by-default architectures Collaborate with engineering and IT teams to embed security practices across the development and deployment lifecycle Lead threat modeling, risk assessments, and architecture reviews in areas aligned with your specialty Develop automated solutions and infrastructure-as-code to drive consistent and reproducible security outcomes Stay ahead of the latest threats and advocate for innovative security solutions aligned with business needs Help define security standards and best practices at Klaviyo, championing their adoption across teams Who You Are Have 3+ years of experience in infrastructure or security engineering roles, with deep knowledge in one or more security focus areas (e.g., cloud security, IAM, endpoint security, data protection, detection engineering, compliance) Comfortable navigating ambiguity and defining priorities in a broad-scoped role Experienced working in modern cloud environments such as AWS, GCP, or Azure Familiar with infrastructure-as-code tools such as Terraform, CloudFormation, or Pulumi Proficient in secure systems design, threat modeling, and vulnerability management AI Agentic development and prompt engineering, MCP (AWS Bedrock, OpenAI, Anthropic) Able to clearly articulate complex security topics to technical and non-technical stakeholders Passionate about security, eager to learn from others and share your expertise Nice to have - certifications (e.g., CISSP, CKS, GCP/AWS Security certs) or equivalent practical experience We use Covey as part of our hiring and / or promotional process. For jobs or candidates in NYC, certain features may qualify it as an AEDT. As part of the evaluation process we provide Covey with job requirements and candidate submitted applications. We began using Covey Scout for Inbound on April 3, 2025. Please see the independent bias audit report covering our use of Covey here Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. Our salary range reflects the cost of labor across various U.S. geographic markets. The range displayed below reflects the minimum and maximum target salaries for the position across all our US locations. The base salary offered for this position is determined by several factors, including the applicant's job-related skills, relevant experience, education or training, and work location. In addition to base salary, our total compensation package may include participation in the company's annual cash bonus plan, variable compensation (OTE) for sales and customer success roles, equity, sign-on payments, and a comprehensive range of health, welfare, and wellbeing benefits based on eligibility. Your recruiter can provide more details about the specific salary/OTE range for your preferred location during the hiring process. Base Pay Range For US Locations:$152,000-$228,000 USD Get to Know Klaviyo We're Klaviyo (pronounced clay-vee-oh). We empower creators to own their destiny by making first-party data accessible and actionable like never before. We see limitless potential for the technology we're developing to nurture personalized experiences in ecommerce and beyond. To reach our goals, we need our own crew of remarkable creators-ambitious and collaborative teammates who stay focused on our north star: delighting our customers. If you're ready to do the best work of your career, where you'll be welcomed as your whole self from day one and supported with generous benefits, we hope you'll join us. AI fluency at Klaviyo includes responsible use of AI (including privacy, security, bias awareness, and human-in-the-loop). We provide accommodations as needed. By participating in Klaviyo's interview process, you acknowledge that you have read, understood, and will adhere to our Guidelines for using AI in the Klaviyo interview Process. For more information about how we process your personal data, see our Job Applicant Privacy Notice. Klaviyo is committed to a policy of equal opportunity and non-discrimination. We do not discriminate on the basis of race, ethnicity, citizenship, national origin, color, religion or religious creed, age, sex (including pregnancy), gender identity, sexual orientation, physical or mental disability, veteran or active military status, marital status, criminal record, genetics, retaliation, sexual harassment or any other characteristic protected by applicable law. IMPORTANT NOTICE: Our company takes the security and privacy of job applicants very seriously. We will never ask for payment, bank details, or personal financial information as part of the application process. All our legitimate job postings can be found on our official career site. Please be cautious of job offers that come from non-company email addresses (@klaviyo.com), instant messaging platforms, or unsolicited calls. By clicking "Submit Application" you consent to Klaviyo processing your Personal Data in accordance with our Job Applicant Privacy Notice. If you do not wish for Klaviyo to process your Personal Data, please do not submit an application. You can find our Job Applicant Privacy Notice here and here (FR).
    $152k-228k yearly Auto-Apply 3d ago
  • Growth Hacker

    Osaro 4.2company rating

    Remote

    Who We Are: At OSARO, we're on a mission to empower industries with cutting-edge automation solutions that redefine the possibilities of supply chain and fulfillment operations. By harnessing the power of AI and advanced robotic vision systems, we help businesses streamline operations and achieve unprecedented efficiency. Join us as we create a world where technology not only drives productivity but also enhances the human experience in the workplace. About the Role: Are you a dynamic, socially savvy individual who thrives on building relationships and creating lasting connections? Do you have a knack for turning online interactions into meaningful conversations that drive business? If so, we want you to be our Social Intelligence Strategist! In this role, you'll pivot away from traditional cold outreach and focus on leveraging social media platforms like LinkedIn and X (formerly Twitter) to engage with decision-makers at our target accounts. You'll be given a curated list of 20-25 ideal customer profiles (ICPs) to concentrate on, ensuring your efforts are focused and impactful.In this role, you will: Engage: Connect, follow, and interact with key decision-makers within your target accounts through social media. Strategize: Develop innovative strategies to showcase OSARO's automation solutions, tailoring approaches that resonate with potential clients' unique needs. Educate: Share insights and content that highlight the value of our solutions, driving interest and engagement within your network. Analyze: Track and analyze engagement metrics to refine your outreach strategies, ensuring continuous improvement. Collaborate: Work closely with our sales and marketing teams to synchronize efforts and share best practices. Key Responsibilities: Achieving a target of 3-5 meaningful interactions per week with decision-makers. Generating weekly engagement reports to gauge activity metrics and adjust strategies accordingly. Utilizing tools like LinkedIn Sales Navigator and other analytics platforms to monitor and engage with leads strategically. What makes the ideal candidate: Connections & Network: ~5000+ LinkedIn Connections Experience: You have 3-5 years of experience in enterprise and social selling, with a proven ability to engage prospects through digital channels. Knowledge: Familiarity with the MEDDICC qualification framework is a plus, as is experience with automation technologies. Relationship Builder: Your skills in social dynamics allow you to establish and nurture meaningful relationships that lead to new business opportunities. Data-Driven: You have an analytical mindset and enjoy using data to inform your strategies and improve performance. Creative Problem Solver: You're an out-of-the-box thinker with the ability to develop engaging content that attracts the right audience. Ideal candidate will be in the Bay Area of California Perks of Joining OSARO: A collaborative company culture that promotes innovation and teamwork. Opportunity to work with cutting-edge technology and industry-leading experts. Comprehensive onboarding and continuous professional development programs to ensure your success in the role. Clear paths for career advancement within OSARO. Competitive salary with performance bonuses and equity options. Comprehensive health, dental, and vision insurance. Flexible time-off policy - take the time you need to recharge. Join Us: At OSARO, we value diversity and the unique perspectives every team member brings to the table. If you are excited about the opportunity to help redefine how industries use automation and drive change through innovative sales strategies, we want to hear from you! Apply Now! Let's revolutionize the future of automation together. If you're ready to take the next step in your career and make a real impact, we'd love to see your application :) OSARO is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. More About OSAROOSARO is a San Francisco-based startup company building machine learning software for industrial automation, to power robots in logistics and material handling centers. Our vision is to develop a solution that enables industrial robots to perform diverse tasks in a wide range of environments. We are excited and driven to see the results of our efforts operating in the fast-growing field of autonomous material handling. We implement state-of-the-art techniques but constantly strive to build the simplest possible solution. OSARO is technique agnostic and always focused on the goal. We regularly review academic literature for novel strategies while steering clear of the hype. We're focused on delighting our customers with systems that work like magic. Our markets are global. That's why OSARO employs a diverse team of experts in various fields from more than 15 countries, attracting talent from both innovative companies and the research labs of top-ranked engineering universities. We are naturally curious, love healthy debate, and respect varying points of view. At OSARO, we strive to be champions for equality. We believe we can serve as a model for diversity in the tech industry by emphasizing policies of nondiscrimination and inclusion at every step. We are an equal opportunity employer who offers Health, dental, vision, and commuter benefits Generous, flexible vacation time Excellent paid parental leave policy with the option for additional reduced and unpaid leave The chance to work with robots! The above full-time position is available immediately.
    $71k-110k yearly est. Auto-Apply 60d+ ago
  • Head of Growth Hacking

    Remote 4.1company rating

    Remote

    About Remote Remote is solving modern organizations' biggest challenge - navigating global employment compliantly with ease. We make it possible for businesses of all sizes to recruit, pay, and manage international teams. With our core values at heart and future focused work culture, our team works tirelessly on ambitious problems, asynchronously, around the world. You can find Remoters working from 6 different continents (Antarctica left to go!) and all of our positions are fully remote. We encourage every member of the Remote team to bring their talents, experiences and culture to the table to help us build the best-in-class HR platform. If you are energetic, curious, motivated and ambitious, be part of our world. Apply now and define the future of work!The position As Head of Growth Hacking you will own unconventional, high‑leverage growth, design and run guerrilla growth programs that create awareness, demand, and activation for the suite of Remote HR products. This role is for you if you enjoy hands-on, scrappy building and will use your deep network in startup ecosystems to drive revenue growth and find new commercial avenues. What you bring High agency Ex‑founder or first‑growth hire who has shipped scrappy plays from idea to measurable impact and revenue. Have public presence in founder communities or creator economy. Have a network among founders, operators, and investors Move fast with low dependency. Comfortable running multiple experiments in parallel. Actively defaults to using AI Fluent in written and spoken English. Key responsibilities Identify and prioritise opportunities for building brand awareness, especially across founder and startup communities and events. Develop and deliver both online and offline marketing campaigns to optimise growth and generate revenue. Drive efficiency and productivity across marketing channels. Launch scrappy, high‑signal experiments: such as community hijacks, product‑led virality and other non-traditional marketing campaigns. Measure and analyze outcome of strategies to help shape future GTM strategy. Nurture a close network of partners Own market research and competitive analysis. Practicals You'll report to: President Team: President Location: SF / Bay Area Start date: As soon as possible Remote Compensation Philosophy Remote's Total Rewards philosophy is to ensure fair, unbiased compensation and fair equity pay along with competitive benefits in all locations in which we operate. We do not agree to or encourage cheap-labor practices and therefore we ensure to pay above in-location rates. We hope to inspire other companies to support global talent-hiring and bring local wealth to developing countries. At Remote we have international operations and a globally distributed workforce. We use geo ranges to consider geographic pay differentials as part of our global compensation strategy to remain competitive in various markets while we hiring globally. Our salary ranges are determined by role, level and location, and our job titles may span more than one career level. The actual base pay for the successful candidate in this role is dependent upon many factors such as location, transferable or job-related skills, work experience, relevant training, business needs, and market demands. The base salary range may be subject to change. At Remote, we foster internal mobility as a key element of our culture of employee growth and development, supported by a compensation philosophy that guarantees pay equity and fairness. Therefore, all compensation changes associated with an internal move will be reviewed by the Total Rewards & People Enablement team on a case by case basis. Application process (async) Profile review Interview with the Recruiter Interview with Hiring Manager Interview with team members (async) Offer Benefits Our full benefits & perks are explained in our handbook at remote.com/r/benefits. As a global company, each country works differently, but some benefits/perks are for all Remoters: work from anywhere flexible paid time off flexible working hours (we are async) 16 weeks paid parental leave mental health support services stock options learning budget home office budget & IT equipment budget for local in-person social events or co-working spaces How you'll plan your day (and life) We work async at Remote which means you can plan your schedule around your life (and not around meetings). Read more at remote.com/async. You will be empowered to take ownership and be proactive. When in doubt you will default to action instead of waiting. Your life-work balance is important and you will be encouraged to put yourself and your family first, and fit work around your needs. If that sounds like something you want, apply now! How to apply Please fill out the form below and upload your CV with a PDF format. We kindly ask you to submit your application and CV in English, as this is the standardised language we use here at Remote. If you don't have an up to date CV but you are still interested in talking to us, please feel free to add a copy of your LinkedIn profile instead. Not only do we encourage folks from all ethnic groups, genders, sexuality, age, abilities, disability status and any other under-represented group to apply, but we prioritize a sense of belonging. We have 4 ERGs (Women, Disability, Queer, Minorities in Tech) who meet regularly with the People team. During your interviews and beyond, we ask & encourage anybody who needs an accommodation to request one from their recruiter. We will ask you to voluntarily tell us your pronouns at interview stage, and you will have the option to answer our anonymous demographic questionnaire when you apply below. As an equal employment opportunity employer it's important to us that our workforce reflects people of all backgrounds, identities, and experiences and this data will help us to stay accountable. We thank you for providing this data, if you chose to. At Remote, we embrace AI as a valuable tool while prioritizing human creativity and authenticity. We look forward to meeting candidates who balance innovation with genuine expertise and experience. To learn more about Remote's AI guidelines check see here. Please note we accept applications on an ongoing basis.
    $72k-111k yearly est. Auto-Apply 26d ago
  • Senior Physical Security System Engineer

    Bytedance 4.6company rating

    San Jose, CA jobs

    Team Introduction The Physical Security System and Technology Team, falls under the physical security department of the Corporate Services. Its core responsibility is to leverage technological means to guard against security risks within the workplace. In addition, the team undertakes the daily operation, maintenance, and upgrade of global physical security and prevention systems (such as Lenel, Hikvision, Avigilon, etc.), and is also responsible for the management and maintenance of physical security-related data. Responsibilities: * Provide technical support to users, document system issues reported, analyse & identify root-cause, recommend solutions, fix issues, provide status updates to users, and provide periodical incident reports & updates to management. * Experienced with SQL database open connectivity development. Able to provide guidance to the internal R&D team members on the integration between internal developed applications and security systems. * Coordinate with security system vendors to ensure outstanding issues raised by internal R&D teams are being addressed by vendors in a timely manner. Document issues and provide status updates to management on a periodical basis. * Act as the primary point of contact to the security system vendor. Attend a periodical meeting with the security system vendor as required. * Perform periodical system health checks to ensure safe, stable and efficient operation of the security system on a global basis. * Perform application & system upgrade based on recommendation by the vendor to ensure the version in used meets standard operation. Enhances existing software capabilities, and develops direct system testing and validation procedures.Minimum Qualifications: * Studied in any of these faculties: Computer Science, Information Technology, Programming & Systems Analysis, Science. * Experienced in one or more programming languages, such as scripting experience in Shell and Python, and SQL. * Experienced in designing, building, and maintaining large-scale distributed applications & systems or experience in databases, operating systems, and server management & maintenance. Preferred Qualifications: * Be highly self-motivated, able to proactively identify problems, and promote the continuous development and progress of related projects. * Lenel physical security-related applications & systems certified/trained.
    $143k-204k yearly est. 3d ago
  • Infrastructure Security Engineer

    Airtable 4.2company rating

    San Francisco, CA jobs

    Airtable is the no-code app platform that empowers people closest to the work to accelerate their most critical business processes. More than 500,000 organizations, including 80% of the Fortune 100, rely on Airtable to transform how work gets done. Join Airtable as an Infrastructure Security Engineer and play a pivotal role in shaping the security architecture of our rapidly evolving infrastructure as we scale to support millions of users and complex AI-powered workloads. You will join the team responsible for safeguarding the foundations of Airtable's platform. You will partner with infrastructure engineering teams and build paved roads, frameworks, and automated controls that make the secure path the easy path for our engineering teams. What you'll do Develop self-service security frameworks and "paved roads" that allow engineering teams to ship secure infrastructure by default. Focus on automated guardrails that prevent insecure configurations without blocking developer velocity. Design and implement security controls for our core infrastructure, including AWS, Kubernetes, and our CI/CD pipelines. Evolve our approach to identity and access management (IAM), secrets management, and machine identity to ensure least-privilege access at scale. Collaborate closely with the Compute, Storage and Traffic Engineering teams to contribute to architecture design and threat modeling for new infrastructure initiatives. Proactively harden our production environment against attacks and assist in building detection capabilities for infrastructure-level-threats. (Senior/Staff L5+): Act as a subject matter expert for infrastructure security, mentoring other engineers and helping to raise the security bar across the entire engineering organization. Who you are 4+ years of experience in security engineering or infrastructure engineering, with a strong focus on cloud security. Please note this is not an early career position. You have a strong background in computer science with a degree in CS or a related field or equivalent practical experience. You have deep familiarity with AWS (or similar cloud providers) and container orchestration technologies like Kubernetes. You understand the unique security challenges of distributed systems. You are proficient in writing and reviewing code and treat security as an engineering problem to be solved with software, not just policies. You have experience with IaC tools like Terraform and understand how to secure infrastructure delivery pipelines. You excel at communicating complex security risks to non-security stakeholders and enjoy collaborating cross-functionally to find solutions that balance security with engineering velocity. You are comfortable working in a fast-paced environment, navigating ambiguity, continuously learning about emerging threats and technologies, and contributing to long-term security strategy. Airtable is an equal opportunity employer. We embrace diversity and strive to create a workplace where everyone has an equal opportunity to thrive. We welcome people of different backgrounds, experiences, abilities, and perspectives. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status or any characteristic protected by applicable federal and state laws, regulations and ordinances. Learn more about your EEO rights as an applicant. VEVRAA-Federal Contractor If you have a medical condition, disability, or religious belief/practice which inhibits your ability to participate in any part of the application or interview process, please complete our Accommodations Request Form and let us know how we may assist you. Airtable is committed to participating in the interactive process and providing reasonable accommodations to qualified applicants. Compensation awarded to successful candidates will vary based on their work location, relevant skills, and experience. Our total compensation package also includes the opportunity to receive benefits, restricted stock units, and may include incentive compensation. To learn more about our comprehensive benefit offerings, please check out Life at Airtable. For work locations in the San Francisco Bay Area, Seattle, New York City, and Los Angeles, the base salary range for this role is:$170,000-$277,600 USD Please see our Privacy Notice for details regarding Airtable's collection and use of personal information relating to the application and recruitment process by clicking here. 🔒 Stay Safe from Job Scams All official Airtable communication will come from an @airtable.com email address. We will never ask you to share sensitive information or purchase equipment during the hiring process. If in doubt, contact us at ***************. Learn more about avoiding job scams here.
    $170k-277.6k yearly Auto-Apply 6d ago
  • Distributed Systems Engineer: Secure Sandboxes

    Magic Ai 3.9company rating

    San Francisco, CA jobs

    Magic's mission is to build safe AGI that accelerates humanity's progress on the world's most important problems. We believe the most promising path to safe AGI lies in automating research and code generation to improve models and solve alignment more reliably than humans can alone. Our approach combines frontier-scale pre-training, domain-specific RL, ultra-long context, and inference-time compute to achieve this goal. About the role As a Software Engineer on the Supercomputing Platforms and Infrastructure team, you will build the next generation systems that power large scale AI research and deployment. You will focus on sandboxed execution environments, distributed systems orchestration, and performance optimized compute workflows. You will work closely with ML and Research teams and infrastructure teams to deliver both high throughput, scale, and strong isolation guarantees in a cluster environment. What you might work on Build highly scalable, highly performant, software that facilitates arbitrary code execution with strong isolation guarantees. Design and build systems that allow our AI models to interface with machines in various modes, interactive terminal, GUI applications, etc. Provision and operate high density compute and storage nodes (NVMe, high IOPS SSDs, high bandwidth networks), and build software that performs efficient load balancing, and resource utilization across them. Instrument and optimize end to end performance including storage IO, network bandwidth, CPU, memory, and endurance constraints. Develop APIs, self service platforms, and automation and tools so researchers and engineers can deploy and monitor workloads at scale. Troubleshoot complex infrastructure issues across OS, drivers, hardware, storage systems (local NVMe, block storage, NFS), networking, namespace isolation, and cloud or hybrid environments. Produce clean, documented code and developer workflows, and collaborate with SRE and security teams to ensure safe, reliable, and self serviceable compute offerings. What we are looking for Strong software engineering background (C, C++, Go, Rust, or similar systems languages). Experience designing or operating sandboxed or isolated execution environments (namespaces, cgroups, container runtime internals), or strong interest in this area. Experience building or operating distributed systems or parallel processing frameworks (scatter aggregate processing, worker pools, multi thread and multi process coordination, shared memory, atomics, merging strategies). Solid understanding of storage and IO subsystems (NVMe, SSD endurance, write amplification), network performance, CPU and memory resource constraints in high performance compute clusters. Comfortable working on low level systems (OS, threading, memory management, synchronization) as well as higher level orchestration or automation. Experience with cloud infrastructure (GCP, AWS, Azure, etc.) including IaC tools such as OpenTofu, Terraform, Pulumi, or CDK is a plus. Intellectual curiosity, strong ownership, and the ability to make tradeoffs in ambiguous environments such as latency versus throughput and isolation versus performance. Nice to haves Prior experience with GPU scheduling, RDMA networking, or bare metal HPC clusters Contributions to open source container runtimes or sandboxing frameworks Experience with kernel internals, device drivers, or SSD and NVMe endurance modeling Familiarity with Rust for systems programming or Go for infrastructure orchestration Why join us You will work at the cutting edge of AI infrastructure including large compute clusters, advanced metrics engines, and next generation sandboxing systems for untrusted workloads. The problems you solve will be foundational, for example how to securely and efficiently run arbitrary research code across thousands of GPUs or high end SSDs. You will join a collaborative and hands-on team where you are building rather than only modeling. Excellent compensation and equity, generous benefits, and high impact. Our culture: Integrity. Words and actions should be aligned Hands-on. At Magic, everyone is building Teamwork. We move as one team, not N individuals Focus. Safely deploy AGI. Everything else is noise Quality. Magic should feel like magic Compensation and benefits (US) Annual salary range: 225,000 USD to 550,000 USD depending on seniority Significant equity component 401(k) with matching, comprehensive health, dental, and vision insurance, unlimited paid time off, visa sponsorship and relocation support Fast paced, mission driven environment focused on safely advancing AGI for humanity
    $114k-163k yearly est. Auto-Apply 28d ago

Learn more about SoundCloud jobs

Most common jobs at SoundCloud