Remote job
Senior Security Engineer
Job details
About this role
Role overview A senior security engineer is needed to independently safeguard infrastructure, data, and personnel across endpoints, networks, cloud environments, and identity systems. The position combines hands-on technical security work with compliance ownership for frameworks like NIST 800-171 and ITAR/EAR controls. It is a hybrid role based out of a San Jose, CA office (three days onsite) or fully remote from an approved U.S. location.
Responsibilities - Design, deploy, and tune endpoint detection and response tooling across macOS and Windows fleets, including alert triage and incident handling. - Architect and operate network security controls such as firewalls, IDS/IPS, segmentation, and VPN infrastructure. - Run the vulnerability management lifecycle: scanning, prioritization, remediation coordination with engineering, and closure tracking. - Administer and harden IAM platforms (Okta, AWS IAM) including SSO, conditional access, privileged access reviews, and lifecycle automation. - Build SIEM detections, response playbooks, and ongoing monitoring for security-relevant signals. - Conduct security reviews of new tools, vendors, and architectural changes prior to deployment. - Manage cloud security posture across AWS, including IAM policy hygiene, S3 protections, security group reviews, and CloudTrail/GuardDuty oversight. - Maintain documentation, support audits, and contribute to security policy development as the environment evolves.
Requirements - 5+ years in information security or security engineering roles. - Hands-on experience with EDR/XDR platforms such as CrowdStrike or SentinelOne. - Practical experience operating enterprise vulnerability scanners (Tenable, Qualys, Rapid7, or comparable). - Working knowledge of Okta or Azure AD administration and IAM principles. - Cloud security proficiency in AWS, including IAM, VPC, security groups, CloudTrail, GuardDuty, and Config. - Familiarity with SIEM platforms (Splunk, Sentinel, Elastic, etc.) for log analysis and detection engineering. - Solid networking fundamentals spanning firewalls, proxies, DNS security, segmentation, and packet analysis. - Working knowledge of compliance frameworks such as NIST 800-171, CMMC, SOC 2, or ISO 27001. - Strong written and verbal communication skills with both engineers and leadership audiences.
Nice to have - Relevant certifications such as CISSP, GIAC, CEH, or AWS Security Specialty. - Infrastructure-as-code and CI/CD pipeline security experience using Terraform or CloudFormation. - Background supporting environments subject to ITAR/EAR export control requirements.
Benefits and work setup - Salary range: $193,000–$218,000 plus a competitive equity grant and comprehensive benefits. - Hybrid schedule (three days onsite in San Jose) or fully remote from approved U.S. states. - Medical, dental, and vision insurance, 401(k), short- and long-term disability, and life insurance. - Three weeks of paid vacation for new hires, 12 paid holidays, unlimited sick time, and paid parental leave.