Remote job
Security Engineer
Job details
About this role
Role overview A security engineering role on a small Trust team responsible for protecting a real-time, large-scale infrastructure platform that handles audio, video, and data traffic at massive volume. The position owns meaningful pieces of the security program from day one, with two focus areas available depending on background: infrastructure security posture, or vulnerability management and security operations.
Responsibilities - Map the security posture of cloud and production infrastructure, identify gaps that could lead to data loss or compromise, and drive prioritized remediation. - Operationalize scanning tooling across cloud, containers, hosts, and dependencies, and run the full vulnerability management lifecycle from triage through SLA tracking and reporting. - Harden identity, secrets, and network boundaries, with attention to environment separation and credential hygiene. - Build automation that eliminates manual security work and scales with engineering growth. - Partner with engineering teams to make secure workflows the easy, default path for triaging and fixing issues. - Automate collection of technical evidence supporting PCI-DSS and ISO 27001 programs, working alongside the compliance team. - Participate in incident response and a shared security escalation rotation.
Requirements - 5+ years in security engineering, infrastructure engineering, or SRE, with a substantial share directly in security. - For the infrastructure track: hands-on experience securing a major cloud provider (AWS, GCP, or Azure) and containerized workloads including Kubernetes, plus a track record of owning infrastructure security for a production platform. - For the vulnerability management track: hands-on experience building or running vulnerability management or software security tooling, with an engineering-first triage approach. - Strong scripting and automation skills in Go or Python, plus fluency with infrastructure-as-code tools such as Terraform. - Pragmatic risk judgment, with the ability to explain why a finding matters to the business and how quickly it must be fixed.
Nice to have - Experience with real-time media, networking, or WebRTC systems. - Background in AI security, such as securing LLM applications or agent infrastructure. - Incident response or application security experience. - Prior experience supporting compliance audits.
Benefits and work setup - Competitive salary and equity package, health, dental, and vision benefits, flexible vacation policy, and opportunity to contribute to open source.