Remote job
Security Engineer II (Remote)
Job details
About this role
Role overview
A U.S.-based web hosting and managed services employer is hiring a remote Security Engineer II to protect a large, multi-tenant Linux hosting environment where untrusted code runs by design. This is a hands-on engineering role investigating live compromises, building detections, reviewing internal and third-party code, and driving down long-standing risk across shared hosting, VPS, managed WordPress, dedicated servers, cloud, and email infrastructure.
Responsibilities
- Lead complex security incident investigations across shared, virtualized, and dedicated Linux hosts, including containment, evidence preservation, and clear write-ups. - Build and tune detection engineering capabilities such as malware and webshell signatures and log-based detections that scale across a large fleet. - Conduct application security reviews of in-house control planes, customer panels, internal tooling, and the third-party and open-source code in use. - Modernize secrets management by moving static credentials into Vault or equivalent, adopting dynamic credentials, and removing plaintext secrets from code, logs, and CI. - Manage vulnerability remediation and patch velocity across a heterogeneous fleet, including end-of-life OS and runtime upgrades. - Automate recurring work, partner with Systems, Development, Abuse, and Support to land security controls, and review AI and agent tooling for safe internal adoption.
Requirements
- 3 to 6 years in security engineering, incident response, application security, offensive security, or systems administration with a track record of resolving complex problems independently. - Depth in at least one of application security, incident response and detection engineering, or offensive security and penetration testing, plus working competence in the other two. - Strong hands-on Linux experience (Debian or Ubuntu preferred) including processes, namespaces, capabilities, filesystems, and kernel-level troubleshooting. - Experience operating long-lived production systems that cannot simply be rebuilt, including in-place repair under load. - Background in multi-tenant or customer-facing environments where users are untrusted. - Scripting and automation in production using Python, Go, Bash, Perl, or similar languages. - Log analysis at scale and comfort with intrusion detection and web application firewalls such as mod_security. - Working knowledge of cloud platform security on AWS, GCP, Azure, or OpenStack, and familiarity with secrets management and CI/CD security.
Nice to have
- Prompt injection, tool-permission scoping, or data-boundary work related to AI and agents. - Familiarity with PCI DSS, SOC 2, or ISO 27001 as context rather than as a primary focus. - Open source contributions.
Benefits and work setup
- Yearly salary range of $125,000 to $145,000. - Full health, vision, and dental coverage for the entire family at zero cost to the employee. - 3% Safe Harbor 401(k) contribution plus up to 1% employer match, profit sharing, and bonus opportunities. - Generous paid time off starting at 15 vacation days, 11 paid holidays, and 80 hours of accrued paid sick leave. - Tuition reimbursement, pet insurance, a monthly wellness allowance, Udemy access, disability insurance, generous parental leave, discounted travel, and free web hosting.