Remote job
Senior Security Engineer
Job details
About this role
Role overview
A fast-growing SaaS company in the construction and roofing software space is hiring a Senior Security Engineer to elevate its security posture as the platform scales. Reporting to the VP of Engineering, this role partners closely with engineering, DevOps, and executive leadership to own detection, response, cloud hardening, and compliance programs end to end. The position suits a hands-on builder who is equally comfortable writing detection logic, running incident command, and translating risk into language the leadership team can act on.
Responsibilities
- Design and harden security infrastructure across cloud environments, covering network segmentation, firewalls, IDS/IPS, VPNs, WAF, and endpoint detection and response tooling. - Lead the full vulnerability management lifecycle, including authenticated scans, exploitability-based prioritization, blast-radius analysis, and remediation SLAs with engineering teams. - Build and tune SIEM/SOAR detection content and alerting logic mapped to real-world attack techniques rather than default vendor signatures. - Serve as incident commander during security events, handling containment, eradication, forensics, and post-incident review writeups. - Threat-model new features and infrastructure changes before release to surface design-level risk early. - Own cloud security posture and IAM hygiene, including least-privilege access, secrets management, and network boundaries across production accounts. - Operate the compliance program end to end, mapping controls to NIST CSF 2.0, SOC 2, and CCPA/CPRA, running audits, closing gaps, and keeping evidence current. - Run tabletop exercises and playbook drills, and embed secure-by-design practices into SDLC workflows.
Requirements
- 5-8+ years in security engineering, incident response, or related infrastructure roles, with firsthand experience as a primary or senior responder on real incidents. - Bachelor's degree in computer science, IT, cybersecurity, or equivalent hands-on experience. - Deep network security fundamentals, including firewalls, VPNs, routing and segmentation, TLS, DNS, and common attacker abuse patterns. - Hands-on AWS cloud security experience, including IAM policy design, VPC architecture, KMS and secrets management, and tools like CloudTrail or GuardDuty. - Working knowledge of SIEM/SOAR tooling, detection logic in Python or Bash, and a willingness to build custom tooling when off-the-shelf options fall short. - Strong software engineering ability, comfortable reading and writing production application code to investigate issues directly. - Confidence operating as the sole security voice in decision-making rooms and the judgment to own those calls.
Nice to have
- Professional certifications such as CISSP, OSCP, GCIH, or CEH. - Prior experience scaling security programs at a high-growth SaaS or startup environment.
Benefits and work setup
- Remote-first culture with a home office setup stipend, plus internet and phone allowance. - Flexible paid time off, with one mandatory first week, a monthly Friday off, and a company-wide shutdown between Christmas and New Year. - Employer-supported health benefits (around 80% covered in the U.S., with full premium coverage for extended healthcare and dental in Canada), RRSP/401k matching, and a generous parental leave policy. - Weekly paydays, annual company retreat, and ongoing learning and development opportunities.