Remote job
Security Engineer
Job details
About this role
Role overview A fully remote security engineering role focused on hardening cloud and SaaS environments against evolving threats. The position blends hands-on technical security, vulnerability management, and advisory work across an AWS-heavy stack, with opportunities to explore emerging AI-driven security patterns. It suits someone who enjoys tying together networking, scripting, and cloud-native tooling to lift an organization's overall security posture.
Responsibilities - Run regular vulnerability assessments on cloud-based and mobile workloads using both automated and manual techniques, and design scans to surface weaknesses across applications and infrastructure. - Monitor and audit security implementations, develop or tune automated tests, and respond to alerts from AWS-native tools such as Inspector, CloudTrail, CloudWatch, GuardDuty, Lambda, and Security Hub. - Review and approve technical security requirements, architecture, and control implementations while advising project teams on current and projected risks and mitigation strategies. - Identify, build, and integrate new and existing security tooling, including cloud-native services, and research standards for hardening containerized and Kubernetes workloads at scale. - Partner with security governance to author and interpret standards, then build self-service capabilities that validate application security and compliance against those standards. - Mentor junior team members and deliver developer-focused training; participate in an on-call SecOps rotation for incident response.
Requirements - Bachelor's degree or equivalent, with 2-4 years in IT or security roles and 3+ years working with AWS or another public cloud. - Security+ or comparable security certification, plus an AWS Security Specialty or Professional-level credential (and ideally an AI-platform certification). - Hands-on experience with infrastructure-as-code languages such as YAML, Terraform, or CDK, and scripting in Bash or PowerShell. - Proficiency in a modern programming language (Python or Node.js preferred) and familiarity with one or more additional languages such as TypeScript, Go, Java, C#, or Rust. - Experience partnering with software teams across the full SDLC, using code-defined infrastructure, configuration management, and CI/CD pipelines. - Working knowledge of frameworks such as RMF, FedRAMP, DoD CC SRG, NIST 800-53, and NIST 800-171, plus prior consultative client-facing experience.
Nice to have - Demonstrated use of AI to transform a workload or process. - Prior training delivery on RMF or cyber security concepts. - Familiarity with Datadog and prior on-call rotation experience.
Benefits and work setup - 100% remote with pay in USD, generous holidays plus flexible PTO, and competitive phantom equity. - Paid exams and certifications, peer bonus awards, modern laptop and tooling, plus an equipment and office stipend. - Individual professional development plan with an annual learning stipend; candidates must already hold legal authorization to work in the country of hire.